# UK data protection: UK GDPR and Data Protection Act 2018 overview

> **Key takeaway:** UK GDPR + DPA 2018. Art 5 principles; Art 6/9 lawful bases. Controller accountability; processor duties. Subject rights; breach notification. ICO enforcement. Check PECR for marketing. Verify current post-reform text.

- **Jurisdiction:** England & Wales
- **Practice area:** Commercial
- **Last reviewed:** 2026-08-04
- **Interactive page:** https://kttclegal.info/library/notes/Commercial/data-protection-uk-gdpr-overview
- **Keywords:** data protection, UK GDPR, Data Protection Act 2018, ICO, personal data, lawful basis, subject access request, controller

## What is this about?

UK data protection law centres on the UK GDPR and the Data Protection Act 2018. Controllers and processors must process personal data lawfully, fairly, and transparently, with data-subject rights and ICO enforcement. This is a high-level map for practitioners — not a full compliance manual.

## What is the core rule?

Personal data must be processed under a lawful basis (UK GDPR Art 6) and, for special category data, an Art 9 condition. Core principles include purpose limitation, data minimisation, accuracy, storage limitation, integrity/confidentiality, and accountability (Art 5). Controllers implement appropriate technical and organisational measures; processors act on documented instructions. Data subjects have rights of access, erasure, objection, and others (Arts 12–22). Personal data breaches may require ICO and data-subject notification (Arts 33–34). Transfers to third countries need appropriate safeguards.

## What are the elements or test?

1. Is there personal data / special category data / criminal offence data?
2. Who is controller vs processor?
3. Lawful basis and transparency (privacy notice)?
4. Purpose, minimisation, retention, security adequate?
5. Data-subject request handling within time limits?
6. International transfers and processors under contract?

## Which authorities matter?

- **UK GDPR (retained/assimilated EU GDPR as amended) and Data Protection Act 2018** — Primary domestic data protection framework — check current text after reforms.
- **Data Protection Act 2018 (law enforcement and intelligence parts; exemptions)** — Supplements UK GDPR with applied regimes and exemptions.
- **ICO guidance (accountability, lawful basis, SARs)** — Highly persuasive practical standards for compliance and enforcement risk.

## How does this apply in practice?

PECR e-privacy rules still govern much marketing/cookies. Employment monitoring and DSARs are frequent flashpoints. Proposed/implemented reforms may amend UK GDPR — verify current law before advising. Not a cyber-incident response playbook.

## What are common pitfalls?

- Relying on consent where another lawful basis is more appropriate
- Missing processor contracts (Art 28)
- Late or incomplete DSAR responses
- Assuming anonymised data is always out of scope without proper anonymisation

## When would a practitioner use this?

Compliance programmes, DSAR disputes, and commercial due diligence on data handling.

## Quick reference

UK GDPR + DPA 2018. Art 5 principles; Art 6/9 lawful bases. Controller accountability; processor duties. Subject rights; breach notification. ICO enforcement. Check PECR for marketing. Verify current post-reform text.

---

*Reference material from [KTTC Legal](https://kttclegal.info/), not legal advice. Work product supports instructing solicitors and barristers under their supervision. England & Wales.*
