Data Protection Act 2018
Data Protection Act 2018 (2018 c. 12)
- Data Protection Act 2018 (2018 c. 12)
- PART 1 Preliminary
- 1 Overview
- 2 Protection of personal data
- 3 Terms relating to the processing of personal data
- PART 2 General processing
- CHAPTER 1 Scope and definitions
- 4 Processing to which this Part applies
- 5 Definitions
- CHAPTER 2 The UK GDPR
- Meaning of certain terms used in the UK GDPR
- 6 Meaning of “controller”
- 7 Meaning of “public authority” and “public body”
- Lawfulness of processing
- 8 Lawfulness of processing: public interest etc
- 9 Child's consent in relation to information society services
- Relevant international law
- 9A Processing in reliance on relevant international law
- Special categories of personal data
- 10 Special categories of personal data and criminal convictions etc data
- 11 Special categories of personal data etc: supplementary
- Rights of the data subject
- 12 Limits on fees that may be charged by controllers
- 13 Obligations of credit reference agencies
- 13A Meaning of “relevant offence” for purpose of right to erasure
- 14 Automated decision-making authorised by law: safeguards
- Exemptions etc
- 15 Exemptions etc
- 16 Power to make further exemptions etc by regulations
- Certification
- 17 Accreditation of certification providers
- ...
- 17A Transfers based on adequacy regulations
- 17B Transfers based on adequacy regulations: review etc
- 17C Standard data protection clauses
- 18 Transfers of personal data to third countries etc: public interest
- ...
- 19 Processing for archiving, research and statistical purposes: safeguards
- Minor definition
- 20 Meaning of “court”
- CHAPTER 3 Exemptions for manual unstructured processing and for national security and defence purposes
- Definitions
- 21 Definitions
- ...
- 22 Application of the GDPR to processing to which this Chapter applies
- 23 Power to make provision in consequence of regulations related to the GDPR
- Exemptions etc
- 24 Manual unstructured data held by FOI public authorities
- 25 Manual unstructured data used in longstanding historical research
- 26 National security and defence exemption
- 27 National security: certificate
- 28 National security and defence: modifications to Articles 9 and 32 of the UK GDPR
- PART 3 Law enforcement processing
- CHAPTER 1 Scope and definitions
- Scope
- 29 Processing to which this Part applies
- Definitions
- 30 Meaning of “competent authority”
- 31 “The law enforcement purposes”
- 32 Meaning of “controller” and “processor”
- 33 Other definitions
- CHAPTER 2 Principles
- 34 Overview and general duty of controller
- 35 The first data protection principle
- 36 The second data protection principle
- 37 The third data protection principle
- 38 The fourth data protection principle
- 39 The fifth data protection principle
- 40 The sixth data protection principle
- 41 Safeguards: archiving
- 42 Safeguards: sensitive processing
- 42A Further provision about sensitive processing
- CHAPTER 3 Rights of the data subject
- Overview and scope
- 43 Overview and scope
- Data subject’s rights to information
- 44 ... Controller's general duties
- ...
- 45 Right of access by the data subject
- 45A Exemption from sections 44 and 45: legal professional privilege
- Data subject's rights to rectification or erasure etc
- 46 Right to rectification
- 47 Right to erasure or restriction of processing
- 48 Rights under section 46 or 47: supplementary
- Automated individual decision-making
- 49 Right not to be subject to automated decision-making
- 50 Automated decision-making authorised by law: safeguards
- 50A Automated processing and significant decisions
- 50B Restrictions on automated decision-making based on sensitive processing
- 50C Safeguards for automated decision-making
- 50D Further provision about automated decision-making
- Supplementary
- 51 Exercise of rights through the Commissioner
- 52 Form of provision of information etc
- 53 Manifestly unfounded or excessive requests by the data subject
- 54 Meaning of “applicable time period”
- CHAPTER 4 Controller and processor
- Overview and scope
- 55 Overview and scope
- General obligations
- 56 General obligations of the controller
- 57 Data protection by design and default
- 58 Joint controllers
- 59 Processors
- 60 Processing under the authority of the controller or processor
- 61 Records of processing activities
- 62 Logging
- 63 Co-operation with the Commissioner
- 64 Data protection impact assessment
- 65 Prior consultation with the Commissioner
- Obligations relating to security
- 66 Security of processing
- Obligations relating to personal data breaches
- 67 Notification of a personal data breach to the Commissioner
- 68 Communication of a personal data breach to the data subject
- Data protection officers
- 69 Designation of a data protection officer
- 70 Position of data protection officer
- 71 Tasks of data protection officer
- Codes of conduct
- 71A Codes of conduct
- CHAPTER 5 Transfers of personal data to third countries etc
- Overview and interpretation
- 72 Overview and interpretation
- General principles for transfers
- 73 General principles for transfers of personal data
- 74 Transfers on the basis of an adequacy decision
- 74A Transfers based on adequacy regulations
- 74AA Transfers approved by regulations
- 74AB The data protection test
- 74B Transfers approved by regulations: monitoring
- 75 Transfers subject to appropriate safeguards
- 76 Transfers based on special circumstances
- Additional conditions
- 77 Additional conditions for transfers in reliance on section 73(4)(b)
- Subsequent transfers
- 78 Subsequent transfers
- CHAPTER 6 Supplementary
- 78A National security exemption
- 79 National security: certificate
- 80 Special processing restrictions
- 81 Reporting of infringements
- PART 4 Intelligence services processing
- CHAPTER 1 Scope and definitions
- Scope
- 82 Processing to which this Part applies
- 82A Designation of processing by a qualifying competent authority
- 82B Duration of designation notice
- 82C Review and withdrawal of designation notice
- 82D Records of designation notices
- 82E Appeal against designation notice
- Definitions
- 83 Meaning of “controller” and “processor”
- 84 Other definitions
- CHAPTER 2 Principles
- Overview
- 85 Overview
- The data protection principles
- 86 The first data protection principle
- 87 The second data protection principle
- 88 The third data protection principle
- 89 The fourth data protection principle
- 90 The fifth data protection principle
- 91 The sixth data protection principle
- 91A Further provision about sensitive processing
- CHAPTER 3 Rights of the data subject
- Overview
- 92 Overview
- Rights
- 93 Right to information
- 94 Right of access
- 95 Right of access: supplementary
- 96 Right not to be subject to automated decision-making
- 97 Right to intervene in automated decision-making
- 98 Right to information about decision-making
- 99 Right to object to processing
- 100 Rights to rectification and erasure
- CHAPTER 4 Controller and processor
- Overview
- 101 Overview
- General obligations
- 102 General obligations of the controller
- 103 Data protection by design
- 104 Joint controllers
- 105 Processors
- 106 Processing under the authority of the controller or processor
- Obligations relating to security
- 107 Security of processing
- Obligations relating to personal data breaches
- 108 Communication of a personal data breach
- CHAPTER 5 Transfers of personal data outside the United Kingdom
- 109 Transfers of personal data outside the United Kingdom
- CHAPTER 6 Exemptions
- 110 National security
- 111 National security: certificate
- 112 Other exemptions
- 113 Power to make further exemptions
- PART 5 The Information Commissioner
- The Commissioner
- 114 The Information Commissioner
- The Information Commission
- 114A The Information Commission
- General functions
- 115 General functions under the UK GDPR and safeguards
- 116 Other general functions
- 117 Competence in relation to courts etc
- International role
- 118 Co-operation between parties to the Data Protection Convention
- 119 Inspection of personal data in accordance with international obligations
- 119A Standard clauses for transfers to third countries etc
- 120 Further international role
- Duties in carrying out functions
- 120A Principal objective
- 120B Duties in relation to functions under the data protection legislation
- 120C Strategy
- 120D Duty to consult other regulators
- Codes of practice
- 121 Data-sharing code
- 122 Direct marketing code
- 123 Age-appropriate design code
- 124 Data protection and journalism code
- 124A Other codes of practice
- 124B Panels to consider codes of practice
- 124C Impact assessments for codes of practice
- 125 Approval of codes prepared under sections 121 to 124A
- 126 Publication and review of codes issued under section 125(4)
- 127 Effect of codes issued under section 125(4)
- 128 Other codes of practice
- Consensual audits
- 129 Consensual audits
- Records of national security certificates
- 130 Records of national security certificates
- Information provided to the Commissioner
- 131 Disclosure of information to the Commissioner
- 132 Confidentiality of information
- 133 Guidance about privileged communications
- Fees
- 134 Fees for services
- 135 Manifestly unfounded or excessive requests by data subjects etc
- 136 Guidance about fees
- Charges
- 137 Charges payable to the Commissioner by controllers
- 138 Regulations under section 137: supplementary
- Reports etc
- 139 Reporting to Parliament
- 139A Analysis of performance
- Documents and notices
- 140 Publication by the Commissioner
- 141 Notices from the Commissioner
- PART 6 Enforcement
- Information notices
- 142 Information notices
- 143 Information notices: restrictions
- 144 False statements made in response to information notices
- 145 Information orders
- Assessment notices
- 146 Assessment notices
- 146A Assessment notices: approval of person to prepare report etc
- 147 Assessment notices: restrictions
- Information notices and assessment notices: destruction of documents etc
- 148 Destroying or falsifying information and documents etc
- Interview notices
- 148A Interview notices
- 148B Interview notices: restrictions
- 148C False statements made in response to interview notices
- Enforcement notices
- 149 Enforcement notices
- 150 Enforcement notices: supplementary
- 151 Enforcement notices: rectification and erasure of personal data etc
- 152 Enforcement notices: restrictions
- 153 Enforcement notices: cancellation and variation
- Powers of entry and inspection
- 154 Powers of entry and inspection
- Penalties
- 155 Penalty notices
- 156 Penalty notices: restrictions
- 157 Maximum amount of penalty
- 158 Fixed penalties for non-compliance with charges regulations
- 159 Amount of penalties: supplementary
- Guidance and report
- 160 Guidance about regulatory action
- 161 Approval of first guidance about regulatory action
- 161A Annual report on regulatory action
- Appeals etc
- 162 Rights of appeal
- 163 Determination of appeals
- 164 Applications in respect of urgent notices
- Complaints
- 164A Complaints by data subjects to controllers
- 164B Controllers to notify the Commissioner of the number of complaints
- 165 Complaints by data subjects to the Commissioner
- 166 Orders to progress complaints to the Commissioner
- Remedies in the court
- 167 Compliance orders
- 168 Compensation for contravention of the UK GDPR
- 169 Compensation for contravention of other data protection legislation
- Offences relating to personal data
- 170 Unlawful obtaining etc of personal data
- 171 Re-identification of de-identified personal data
- 172 Re-identification: effectiveness testing conditions
- 173 Alteration etc of personal data to prevent disclosure to data subject
- The special purposes
- 174 The special purposes
- 175 Provision of assistance in special purposes proceedings
- 176 Staying special purposes proceedings
- 177 Guidance about how to seek redress against media organisations
- 178 Review of processing of personal data for the purposes of journalism
- 179 Effectiveness of the media's dispute resolution procedures
- Jurisdiction and court procedure
- 180 Jurisdiction
- 180A Procedure in connection with subject access requests
- Definitions
- 181 Interpretation of Part 6
- PART 7 Supplementary and final provision
- Regulations under this Act
- 182 Regulations and consultation
- Changes to the Data Protection Convention
- 183 Power to reflect changes to the Data Protection Convention
- Prohibitions and restrictions etc on processing
- 183A Protection of prohibitions and restrictions etc on processing: relevant enactments
- 183B Protection of prohibitions and restrictions etc on processing: other enactments
- Rights of the data subject
- 184 Prohibition of requirement to produce relevant records
- 185 Avoidance of certain contractual terms relating to health records
- 186 Protection of data subject’s rights
- 186A Protection of data subject’s rights: further provision
- Representation of data subjects
- 187 Representation of data subjects with their authority
- 188 Representation of data subjects with their authority: collective proceedings
- 189 Duty to review provision for representation of data subjects
- 190 Post-review powers to make provision about representation of data subjects
- Framework for Data Processing by Government
- 191 Framework for Data Processing by Government
- 192 Approval of the Framework
- 193 Publication and review of the Framework
- 194 Effect of the Framework
- Data-sharing: HMRC and reserve forces
- 195 Reserve forces: data-sharing by HMRC
- Offences
- 196 Penalties for offences
- 197 Prosecution
- 198 Liability of directors etc
- 199 Recordable offences
- 200 Guidance about PACE codes of practice
- The Tribunal
- 201 Disclosure of information to the Tribunal
- 202 Proceedings in the First-tier Tribunal: contempt
- 203 Tribunal Procedure Rules
- Interpretation
- 204 Meaning of “health professional” and “social work professional”
- 205 General interpretation
- 206 Index of defined expressions
- Territorial application
- 207 Territorial application of this Act
- General
- 208 Children in Scotland
- 209 Application to the Crown
- 210 Application to Parliament
- 211 Minor and consequential provision
- Final
- 212 Commencement
- 213 Transitional provision
- 214 Extent
- 215 Short title
- SCHEDULES
- Schedule A1 Processing in reliance on relevant international law
- SCHEDULE 1 Special categories of personal data and criminal convictions etc data
- PART 1 Conditions relating to employment, health and research etc
- Employment, social security and social protection
- Health or social care purposes
- Public health
- Research etc
- PART 2 Substantial public interest conditions
- Requirement for an appropriate policy document when relying on conditions in this Part
- Statutory etc and government purposes
- Administration of justice and parliamentary purposes
- Equality of opportunity or treatment
- Racial and ethnic diversity at senior levels of organisations
- Preventing etc unlawful acts
- Protecting the public against dishonesty etc
- Regulatory requirements relating to unlawful acts and dishonesty etc
- Journalism etc in connection with unlawful acts and dishonesty etc
- Preventing fraud
- Suspicion of terrorist financing or money laundering
- Support for individuals with a particular disability or medical condition
- Counselling etc
- Safeguarding of children and of individuals at risk
- Safeguarding of economic well-being of certain individuals
- Insurance
- Occupational pensions
- Political parties
- Elected representatives responding to requests
- Disclosure to elected representatives
- Informing elected representatives about prisoners
- Publication of legal judgments
- Anti-doping in sport
- Standards of behaviour in sport
- PART 3 Additional conditions relating to criminal convictions etc
- Consent
- Protecting individual's vital interests
- Processing by not-for-profit bodies
- Personal data in the public domain
- Legal claims
- Judicial acts
- Administration of accounts used in commission of indecency offences involving children
- Extension of conditions in Part 2 of this Schedule referring to substantial public interest
- Extension of insurance conditions
- PART 4 Appropriate policy document and additional safeguards
- Application of this Part of this Schedule
- Requirement to have an appropriate policy document in place
- Additional safeguard: retention of appropriate policy document
- Additional safeguard: record of processing
- SCHEDULE 2 Exemptions etc from the UK GDPR
- PART 1 Adaptations and restrictions as described in Articles 6(3) and 23(1)
- UK GDPR provisions to be adapted or restricted: “the listed GDPR provisions”
- Crime and taxation: general
- Crime and taxation: risk assessment systems
- Immigration
- Immigration: safeguards: immigration exemption decisions
- Immigration: safeguard: record of decision that exemption applies
- Information required to be disclosed by law etc or in connection with legal proceedings
- PART 2 Restrictions as described in Article 23(1): restrictions of rules in Articles 13 to 21 and 34
- UK GDPR provisions to be restricted: “the listed GDPR provisions”
- Functions designed to protect the public etc
- Audit functions
- Functions of the Bank of England
- Regulatory functions relating to legal services, the health service and children's services
- Regulatory functions of certain other persons
- Parliamentary privilege
- Judicial appointments, judicial independence and judicial proceedings
- Crown honours, dignities and appointments
- PART 3 Restriction for the protection of rights of others
- Protection of the rights of others: general
- Assumption of reasonableness for health workers, social workers and education workers
- PART 4 Restrictions as described in Article 23(1): restrictions of rules in Articles 13 to 15
- UK GDPR provisions to be restricted: “the listed GDPR provisions”
- Legal professional privilege
- Self incrimination
- Corporate finance
- Management forecasts
- Negotiations
- Confidential references
- Exam scripts and exam marks
- PART 5 Exemptions etc... for reasons of freedom of expression and information
- Journalistic, academic, artistic and literary purposes
- PART 6 Derogations etc... for research, statistics and archiving
- Research and statistics
- Archiving in the public interest
- SCHEDULE 3 Exemptions etc from the UK GDPR: health, social work, education and child abuse data
- PART 1 UK GDPR provisions to be restricted
- PART 2 Health data
- Definitions
- Exemption from the listed GDPR provisions: data processed by a court
- Exemption from the listed GDPR provisions: data subject's expectations and wishes
- Exemption from Article 15 of the UK GDPR: serious harm
- Restriction of Article 15 of the UK GDPR: prior opinion of appropriate health professional
- PART 3 Social work data
- Definitions
- Exemption from the listed GDPR provisions: data processed by a court
- Exemption from the listed GDPR provisions: data subject's expectations and wishes
- Exemption from Article 15 of the UK GDPR: serious harm
- Restriction of Article 15 of the UK GDPR: prior opinion of Principal Reporter
- PART 4 Education data
- Educational records
- Other definitions
- Exemption from the listed GDPR provisions: data processed by a court
- Exemption from Article 15 of the UK GDPR: serious harm
- Restriction of Article 15 of the UK GDPR: prior opinion of Principal Reporter
- PART 5 Child abuse data
- Exemption from Article 15 of the UK GDPR: child abuse data
- SCHEDULE 4 Exemptions etc from the UK GDPR: disclosure prohibited or restricted by an enactment
- UK GDPR provisions to be restricted: “the listed GDPR provisions”
- Human fertilisation and embryology information
- Adoption records and reports
- Statements of special educational needs
- Parental order records and reports
- Information provided by Principal Reporter for children's hearing
- SCHEDULE 5 Accreditation of certification providers: reviews and appeals
- Introduction
- Review
- Right to appeal
- Appeal panel
- Hearing
- Decision following referral to appeal panel
- Meaning of “working day”
- SCHEDULE 6 The applied GDPR and the applied Chapter 2
- PART 1 Modifications to the GDPR
- Introductory
- References to the GDPR and its provisions
- References to Union law and Member State law
- References to the Union and to Member States
- References to supervisory authorities
- References to the national parliament
- Chapter I of the GDPR (general provisions)
- Chapter II of the GDPR (principles)
- Section 1 of Chapter III of the GDPR (rights of the data subject: transparency and modalities)
- Section 2 of Chapter III of the GDPR (rights of the data subject: information and access to personal data)
- Section 3 of Chapter III of the GDPR (rights of the data subject: rectification and erasure)
- Section 4 of Chapter III of the GDPR (rights of the data subject: right to object and automated individual decision-making)
- Section 5 of Chapter III of the GDPR (rights of the data subject: restrictions)
- Section 1 of Chapter IV of the GDPR (controller and processor: general obligations)
- Section 3 of Chapter IV of the GDPR (controller and processor: data protection impact assessment and prior consultation)
- Section 4 of Chapter IV of the GDPR (controller and processor: data protection officer)
- Section 5 of Chapter IV of the GDPR (controller and processor: codes of conduct and certification)
- Chapter V of the GDPR (transfers of data to third countries or international organisations)
- Section 1 of Chapter VI of the GDPR (independent supervisory authorities: independent status)
- Section 2 of Chapter VI of the GDPR (independent supervisory authorities: competence, tasks and powers)
- Chapter VII of the GDPR (co-operation and consistency)
- Chapter VIII of the GDPR (remedies, liability and penalties)
- Chapter IX of the GDPR (provisions relating to specific processing situations)
- Chapter X of the GDPR (delegated acts and implementing acts)
- Chapter XI of the GDPR (final provisions)
- PART 2 Modifications to Chapter 2 of Part 2
- Introductory
- General modifications
- Exemptions
- SCHEDULE 7 Competent authorities
- Chief officers of police and other policing bodies
- Other authorities with investigatory functions
- Authorities with functions relating to offender management
- Other authorities
- SCHEDULE 8 Conditions for sensitive processing under Part 3
- Statutory etc purposes
- Administration of justice
- Protecting individual's vital interests
- Safeguarding of children and of individuals at risk
- Personal data already in the public domain
- Legal claims
- Judicial acts
- Preventing fraud
- Archiving etc
- SCHEDULE 9 Conditions for processing under Part 4
- SCHEDULE 10 Conditions for sensitive processing under Part 4
- Consent to particular processing
- Right or obligation relating to employment
- Vital interests of a person
- Safeguarding of children and of individuals at risk
- Data already published by data subject
- Legal proceedings etc
- Administration of justice, parliamentary, statutory etc and government purposes
- Medical purposes
- Equality
- SCHEDULE 11 Other exemptions under Part 4
- Preliminary
- Crime
- Information required to be disclosed by law etc or in connection with legal proceedings
- Parliamentary privilege
- Judicial proceedings
- Crown honours and dignities
- Armed forces
- Economic well-being
- Legal professional privilege
- Negotiations
- Confidential references given by the controller
- Exam scripts and marks
- Research and statistics
- Archiving in the public interest
- SCHEDULE 12 The Information Commissioner
- Status and capacity
- Appointment
- Resignation and removal
- Salary etc
- Officers and staff
- Carrying out of the Commissioner's functions by officers and staff
- Authentication of the seal of the Commissioner
- Presumption of authenticity of documents issued by the Commissioner
- Money
- Fees etc and other sums
- Accounts
- Scotland
- Schedule 12A The Information Commission
- Status
- Number of members
- Membership: general
- Membership: non-executive members to outnumber executive members
- Membership: selection on merit etc
- Membership: conflicts of interests
- Tenure of the chair
- Tenure of deputy chair
- Tenure of the other non-executive members
- Remuneration and pensions of non-executive members
- Executive members: terms and conditions
- Other staff: appointment, terms and conditions
- Committees
- Delegation of functions
- Advice from committees
- Proceedings
- Records of proceedings
- Disqualification for acting in relation to certain matters
- Validity of proceedings
- Money
- Fees etc and other sums
- Accounts
- Authentication of seal and presumption of authenticity of documents
- Supplementary powers
- Transitional provision: interim chief executive
- Interpretation
- SCHEDULE 13 Other general functions of the Commissioner
- General tasks
- General powers
- Definitions
- SCHEDULE 14 Co-operation and mutual assistance
- PART 1 Law Enforcement Directive
- Co-operation
- Requests for information and assistance from LED supervisory authorities
- Fees
- Restrictions on use of information
- LED supervisory authority
- PART 2 Data Protection Convention
- Co-operation between the Commissioner and foreign designated authorities
- Assisting persons resident outside the UK with requests under Article 14 of the Convention
- Assisting UK residents with requests under Article 8 of the Convention
- Restrictions on use of information
- Foreign designated authority
- SCHEDULE 15 Powers of entry and inspection
- Issue of warrants in connection with non-compliance and offences
- Issue of warrants in connection with assessment notices
- Restrictions on issuing warrants: processing for the special purposes
- Restrictions on issuing warrants: procedural requirements
- Content of warrants
- Copies of warrants
- Execution of warrants: reasonable force
- Execution of warrants: time when executed
- Execution of warrants: occupier of premises
- Execution of warrants: seizure of documents etc
- Matters exempt from inspection and seizure: privileged communications
- Matters exempt from inspection and seizure: Parliamentary privilege
- Partially exempt material
- Return of warrants
- Offences
- Self-incrimination
- Vessels, vehicles etc
- Scotland
- Northern Ireland
- SCHEDULE 16 Penalties
- Meaning of “penalty”
- Notice of intent to impose penalty
- Contents of notice of intent
- Giving a penalty notice
- Contents of penalty notice
- Period for payment of penalty
- Variation of penalty
- Cancellation of penalty
- Enforcement of payment
- SCHEDULE 17 Review of processing of personal data for the purposes of journalism
- Interpretation
- Information notices
- Assessment notices
- Interview notices
- Applications in respect of urgent notices
- SCHEDULE 18 Relevant records
- Relevant records
- Relevant health records
- Relevant records relating to a conviction or caution
- Relevant records relating to statutory functions
- Data subject access right
- Records stating that personal data is not processed
- Power to amend
- SCHEDULE 19 Minor and consequential amendments
- PART 1 Amendments of primary legislation
- Registration Service Act 1953 (c. 37)
- Veterinary Surgeons Act 1966 (c. 36)
- Parliamentary Commissioner Act 1967 (c. 13)
- Local Government Act 1974 (c. 7)
- Consumer Credit Act 1974 (c. 39)
- Pharmacy (Northern Ireland) Order 1976 (S.I. 1976/1213 (N.I. 22))
- Representation of the People Act 1983 (c. 2)
- Medical Act 1983 (c. 54)
- Dentists Act 1984 (c. 24)
- Companies Act 1985 (c. 6)
- Access to Medical Reports Act 1988 (c. 28)
- Opticians Act 1989 (c. 44)
- Access to Health Records Act 1990 (c. 23)
- Human Fertilisation and Embryology Act 1990 (c. 37)
- Trade Union and Labour Relations (Consolidation) Act 1992 (c. 52)
- Tribunals and Inquiries Act 1992 (c. 53)
- Industrial Relations (Northern Ireland) Order 1992 (S.I. 1992/807 (N.I. 5))
- Health Service Commissioners Act 1993 (c. 46)
- Data Protection Act 1998 (c. 29)
- Crime and Disorder Act 1998 (c. 37)
- Food Standards Act 1999 (c. 28)
- Immigration and Asylum Act 1999 (c. 33)
- Financial Services and Markets Act 2000 (c. 8)
- Terrorism Act 2000 (c. 11)
- Freedom of Information Act 2000 (c. 36)
- Political Parties, Elections and Referendums Act 2000 (c. 41)
- Public Finance and Accountability (Scotland) Act 2000 (asp 1)
- Criminal Justice and Police Act 2001 (c. 16)
- Anti-terrorism, Crime and Security Act 2001 (c.24)
- Health and Personal Social Services Act (Northern Ireland) 2001 (c. 3 (N.I.))
- Justice (Northern Ireland) Act 2002 (c. 26)
- Proceeds of Crime Act 2002 (c. 29)
- Enterprise Act 2002 (c. 40)
- Scottish Public Services Ombudsman Act 2002 (asp 11)
- Freedom of Information (Scotland) Act 2002 (asp 13)
- Courts Act 2003 (c. 39)
- Sexual Offences Act 2003 (c. 42)
- Criminal Justice Act 2003 (c. 44)
- Mental Health (Care and Treatment) (Scotland) Act 2003 (asp 13)
- Public Audit (Wales) Act 2004 (c. 23)
- Companies (Audit, Investigations and Community Enterprise) Act 2004 (c. 27)
- Domestic Violence, Crime and Victims Act 2004 (c. 28)
- Children Act 2004 (c. 31)
- Constitutional Reform Act 2005 (c. 4)
- Mental Capacity Act 2005 (c. 9)
- Public Services Ombudsman (Wales) Act 2005 (c. 10)
- Commissioners for Revenue and Customs Act 2005 (c. 11)
- Gambling Act 2005 (c. 19)
- Commissioner for Older People (Wales) Act 2006 (c. 30)
- National Health Service Act 2006 (c. 41)
- National Health Service (Wales) Act 2006 (c. 42)
- Companies Act 2006 (c. 46)
- Tribunals, Courts and Enforcement Act 2007 (c. 15)
- Statistics and Registration Service Act 2007 (c. 18)
- Serious Crime Act 2007 (c. 27)
- Legal Services Act 2007 (c. 29)
- Adoption and Children (Scotland) Act 2007 (asp 4)
- Criminal Justice and Immigration Act 2008 (c. 4)
- Regulatory Enforcement and Sanctions Act 2008 (c. 13)
- Health and Social Care Act 2008 (c. 14)
- Counter-Terrorism Act 2008 (c. 28)
- Public Health etc. (Scotland) Act 2008 (asp 5)
- Banking Act 2009 (c. 1)
- Borders, Citizenship and Immigration Act 2009 (c. 11)
- Marine and Coastal Access Act 2009 (c. 23)
- Coroners and Justice Act 2009 (c. 25)
- Broads Authority Act 2009 (c. i)
- Health and Social Care (Reform) Act (Northern Ireland) 2009 (c. 1 (N.I.))
- Terrorist Asset-Freezing etc. Act 2010 (c. 38)
- Marine (Scotland) Act 2010 (asp 5)
- Charities Act 2011 (c. 25)
- Welsh Language (Wales) Measure 2011 (nawm 1)
- Safeguarding Board Act (Northern Ireland) 2011 (c. 7 (N.I))
- Health and Social Care Act 2012 (c. 7)
- Protection of Freedoms Act 2012 (c. 9)
- HGV Road User Levy Act 2013 (c. 7)
- Crime and Courts Act 2013 (c. 22)
- Marine Act (Northern Ireland) 2013 (c. 10 (N.I.))
- Local Audit and Accountability Act 2014 (c. 2)
- Anti-social Behaviour, Crime and Policing Act 2014 (c. 12)
- Immigration Act 2014 (c. 22)
- Care Act 2014 (c. 23)
- Social Services and Well-being (Wales) Act 2014 (anaw 4)
- Counter-Terrorism and Security Act 2015 (c. 6)
- Small Business, Enterprise and Employment Act 2015 (c. 26)
- Modern Slavery Act 2015 (c. 30)
- Human Trafficking and Exploitation (Criminal Justice and Support for Victims) Act (Northern Ireland) 2015 (c. 2 (N.I.))
- Justice Act (Northern Ireland) 2015 (c. 9 (N.I.))
- Immigration Act 2016 (c. 19)
- Investigatory Powers Act 2016 (c. 25)
- Public Services Ombudsman Act (Northern Ireland) 2016 (c. 4 (N.I.))
- Health and Social Care (Control of Data Processing) Act (Northern Ireland) 2016 (c. 12 (N.I.))
- Mental Capacity Act (Northern Ireland) 2016 (c. 18 (N.I.))
- Justice Act (Northern Ireland) 2016 (c. 21 (N.I.))
- Policing and Crime Act 2017 (c. 3)
- Children and Social Work Act 2017 (c. 12)
- Higher Education and Research Act 2017 (c. 29)
- Digital Economy Act 2017 (c. 30)
- Landfill Disposals Tax (Wales) Act 2017 (anaw 3)
- Additional Learning Needs and Educational Tribunal (Wales) Act 2018 (anaw 2)
- This Act
- PART 2 Amendments of other legislation
- Estate Agents (Specified Offences) (No. 2) Order 1991 (S.I. 1991/1091)
- Channel Tunnel (International Arrangements) Order 1993 (S.I. 1993/1813)
- Access to Health Records (Northern Ireland) Order 1993 (S.I. 1993/1250 (N.I. 4))
- Channel Tunnel (Miscellaneous Provisions) Order 1994 (S.I. 1994/1405)
- European Primary and Specialist Dental Qualifications Regulations 1998 (S.I. 1998/811)
- Scottish Parliamentary Corporate Body (Crown Status) Order 1999 (S.I. 1999/677)
- Northern Ireland Assembly Commission (Crown Status) Order 1999 (S.I. 1999/3145)
- Data Protection (Corporate Finance Exemption) Order 2000 (S.I. 2000/184)
- Data Protection (Conditions under Paragraph 3 of Part II of Schedule 1) Order 2000 (S.I. 2000/185)
- Data Protection (Functions of Designated Authority) Order 2000 (S.I. 2000/186)
- Data Protection (International Co-operation) Order 2000 (S.I. 2000/190)
- Data Protection (Subject Access) (Fees and Miscellaneous Provisions) Regulations 2000 (S.I. 2000/191)
- Consumer Credit (Credit Reference Agency) Regulations 2000 (S.I. 2000/290)
- Data Protection (Subject Access Modification) (Health) Order 2000 (S.I. 2000/413)
- Data Protection (Subject Access Modification) (Education) Order 2000 (S.I. 2000/414)
- Data Protection (Subject Access Modification) (Social Work) Order 2000 (S.I. 2000/415)
- Data Protection (Crown Appointments) Order 2000 (S.I. 2000/416)
- Data Protection (Processing of Sensitive Personal Data) Order 2000 (S.I. 2000/417)
- Data Protection (Miscellaneous Subject Access Exemptions) Order 2000 (S.I. 2000/419)
- Data Protection (Designated Codes of Practice) (No. 2) Order 2000 (S.I. 2000/1864)
- Representation of the People (England and Wales) Regulations 2001 (S.I. 2001/341)
- Representation of the People (Scotland) Regulations 2001 (S.I. 2001/497)
- Financial Services and Markets Act 2000 (Disclosure of Confidential Information) Regulations 2001 (S.I. 2001/2188)
- Nursing and Midwifery Order 2001 (S.I. 2002/253)
- Electronic Commerce (EC Directive) Regulations 2002 (S.I. 2002/2013)
- Data Protection (Processing of Sensitive Personal Data) (Elected Representatives) Order 2002 (S.I. 2002/2905)
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (S.I. 2003/2426)
- Nationality, Immigration and Asylum Act 2002 (Juxtaposed Controls) Order 2003 (S.I. 2003/2818)
- Pupils' Educational Records (Scotland) Regulations 2003 (S.S.I. 2003/581)
- European Parliamentary Elections (Northern Ireland) Regulations 2004 (S.I. 2004/1267)
- Freedom of Information and Data Protection (Appropriate Limit and Fees) Regulations 2004 (S.I. 2004/3244)
- Environmental Information Regulations 2004 (S.I. 2004/3391)
- Environmental Information (Scotland) Regulations 2004 (S.S.I. 2004/520)
- Licensing Act 2003 (Personal Licences) Regulations 2005 (S.I. 2005/41)
- Education (Pupil Information) (England) Regulations 2005 (S.I. 2005/1437)
- Civil Contingencies Act 2004 (Contingency Planning) Regulations 2005 (S.I. 2005/2042)
- Register of Judgments, Orders and Fines Regulations 2005 (S.I. 2005/3595)
- Civil Contingencies Act 2004 (Contingency Planning) (Scotland) Regulations 2005 (S.S.I. 2005/494)
- Data Protection (Processing of Sensitive Personal Data) Order 2006 (S.I. 2006/2068)
- National Assembly for Wales (Representation of the People) Order 2007 (S.I. 2007/236)
- Mental Capacity Act 2005 (Loss of Capacity during Research Project) (England) Regulations 2007 (S.I. 2007/679)
- National Assembly for Wales Commission (Crown Status) Order 2007 (S.I. 2007/1118)
- Mental Capacity Act 2005 (Loss of Capacity during Research Project) (Wales) Regulations 2007 (S.I. 2007/837 (W.72))
- Representation of the People (Absent Voting at Local Elections) (Scotland) Regulations 2007 (S.S.I. 2007/170)
- Representation of the People (Post-Local Government Elections Supply and Inspection of Documents) (Scotland) Regulations 2007 (S.S.I. 2007/264)
- Education (Pupil Records and Reporting) (Transitional) Regulations (Northern Ireland) 2007 (S.R. (N.I.) 2007 No. 43)
- Representation of the People (Northern Ireland) Regulations 2008 (S.I. 2008/1741)
- Companies Act 2006 (Extension of Takeover Panel Provisions) (Isle of Man) Order 2008 (S.I. 2008/3122)
- Controlled Drugs (Supervision of Management and Use) (Wales) Regulations 2008 (S.I. 2008/3239 (W.286))
- Energy Order 2003 (Supply of Information) Regulations (Northern Ireland) 2008 (S.R. (N.I.) 2008 No. 3)
- Companies (Disclosure of Address) Regulations 2009 (S.I. 2009/214)
- Overseas Companies Regulations 2009 (S.I. 2009/1801)
- Data Protection (Processing of Sensitive Personal Data) Order 2009 (S.I. 2009/1811)
- Provision of Services Regulations 2009 (S.I. 2009/2999)
- INSPIRE Regulations 2009 (S.I. 2009/3157)
- INSPIRE (Scotland) Regulations 2009 (S.S.I. 2009/440)
- Controlled Drugs (Supervision of Management and Use) Regulations (Northern Ireland) 2009 (S.R (N.I.) 2009 No. 225)
- Data Protection (Monetary Penalties) (Maximum Penalty and Notices) Regulations 2010 (S.I. 2010/31)
- Pharmacy Order 2010 (S.I. 2010/231)
- Data Protection (Monetary Penalties) Order 2010 (S.I. 2010/910)
- National Employment Savings Trust Order 2010 (S.I. 2010/917)
- Local Elections (Northern Ireland) Order 2010 (S.I. 2010/2977)
- Pupil Information (Wales) Regulations 2011 (S.I. 2011/1942 (W.209))
- Debt Arrangement Scheme (Scotland) Regulations 2011 (S.S.I. 2011/141)
- Police and Crime Commissioner Elections Order 2012 (S.I. 2012/1917)
- Data Protection (Processing of Sensitive Personal Data) Order 2012 (S.I. 2012/1978)
- Neighbourhood Planning (Referendums) Regulations 2012 (S.I. 2012/2031)
- Controlled Drugs (Supervision of Management and Use) Regulations 2013 (S.I. 2013/373)
- Communications Act 2003 (Disclosure of Information) Order 2014 (S.I. 2014/1825)
- Criminal Justice and Data Protection (Protocol No. 36) Regulations 2014 (S.I. 2014/3141)
- Data Protection (Assessment Notices) (Designation of National Health Service Bodies) Order 2014 (S.I. 2014/3282)
- The Control of Explosives Precursors etc Regulations (Northern Ireland) 2014 (S.R. (N.I.) 2014 No. 224)
- Control of Poisons and Explosives Precursors Regulations 2015 (S.I. 2015/966)
- Companies (Disclosure of Date of Birth Information) Regulations 2015 (S.I. 2015/1694)
- Small and Medium Sized Business (Credit Information) Regulations 2015 (S.I. 2015/1945)
- European Union (Recognition of Professional Qualifications) Regulations 2015 (S.I. 2015/2059)
- Scottish Parliament (Elections etc) Order 2015 (S.S.I. 2015/425)
- Recall of MPs Act 2015 (Recall Petition) Regulations 2016 (S.I. 2016/295)
- Register of People with Significant Control Regulations 2016 (S.I. 2016/339)
- Electronic Identification and Trust Services for Electronic Transactions Regulations 2016 (S.I. 2016/696)
- Court Files Privileged Access Rules (Northern Ireland) 2016 (S.R. (N.I.) 2016 No. 123)
- Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (S.I. 2017/692)
- Scottish Partnerships (Register of People with Significant Control) Regulations 2017 (S.I. 2017/694)
- Data Protection (Charges and Information) Regulations 2018 (S.I. 2018/480)
- National Health Service (General Medical Services Contracts) (Scotland) Regulations 2018 (S.S.I. 2018/66)
- National Health Service (Primary Medical Services Section 17C Agreements) (Scotland) Regulations 2018 (S.S.I. 2018/67)
- PART 3 Modifications
- Introduction
- General modifications
- Specific modification of references to terms used in the Data Protection Act 1998
- PART 4 Supplementary
- Definitions
- Provision inserted in subordinate legislation by this Schedule
- SCHEDULE 20 Transitional provision etc
- PART 1 General
- Interpretation
- PART 2 Rights of data subjects
- Right of access to personal data under the 1998 Act
- Right to prevent processing likely to cause damage or distress under the 1998 Act
- Right to prevent processing for purposes of direct marketing under the 1998 Act
- Automated processing under the 1998 Act
- Compensation for contravention of the 1998 Act or Part 4 of the 2014 Regulations
- Rectification, blocking, erasure and destruction under the 1998 Act
- Jurisdiction and procedure under the 1998 Act
- Exemptions under the 1998 Act
- Prohibition by this Act of requirement to produce relevant records
- Avoidance under this Act of certain contractual terms relating to health records
- PART 3 The UK GDPR and Part 2 of this Act
- Exemptions from the GDPR: restrictions of rules in Articles 13 to 15 of the GDPR
- Manual unstructured data held by FOI public authorities
- PART 4 Law enforcement and intelligence services processing
- Logging
- Regulation 50 of the 2014 Regulations (disapplication of the 1998 Act)
- Maximum fee for data subject access requests to intelligence services
- PART 5 National security certificates
- National security certificates: processing of personal data under the 1998 Act
- National security certificates: processing of personal data under the 2018 Act
- PART 6 The Information Commissioner
- Appointment etc
- Accounts
- Annual report
- Fees etc received by the Commissioner
- Functions in connection with the Data Protection Convention
- Co-operation with the European Commission: transfers of personal data outside the EEA
- Charges payable to the Commissioner by controllers
- Requests for assessment
- Codes of practice
- PART 7 Enforcement etc under the 1998 Act
- Interpretation of this Part
- Information notices
- Special information notices
- Assessment notices
- Enforcement notices
- Determination by Commissioner as to the special purposes
- Restriction on enforcement in case of processing for the special purposes
- Offences
- Powers of entry
- Monetary penalties
- Appeals
- Exemptions
- Tribunal Procedure Rules
- Obstruction etc
- Enforcement etc under the 2014 Regulations
- PART 8 Enforcement etc under this Act
- Information notices
- Powers of entry
- Tribunal Procedure Rules
- PART 9 Other enactments
- Powers to disclose information to the Commissioner
- Codes etc required to be consistent with the Commissioner's data-sharing code
- Consumer Credit Act 1974
- Freedom of Information Act 2000
- Freedom of Information (Scotland) Act 2002
- Access to Health Records (Northern Ireland) Order 1993 (S.I. 1993/1250 (N.I. 4))
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (S.I. 2003/2450)
- Health and Personal Social Services (Quality, Improvement and Regulation) (Northern Ireland) Order 2003 (S.I. 2003/431 (N.I. 9))
- Environmental Information Regulations 2004 (S.I. 2004/3391)
- Environmental Information (Scotland) Regulations 2004 (S.S.I. 2004/520)
- SCHEDULE 21 Further transitional provision etc
- Part 1 Interpretation
- The applied GPDR
- Part 2 Continuation of existing acts etc
- Merger of the directly applicable GDPR and the applied GDPR
- Part 3 Transfers to third countries and international organisations
- UK GDPR: transfers approved by regulations
- UK GDPR: transfers subject to appropriate safeguards provided by standard data protection clauses
- UK GDPR: transfers subject to appropriate safeguards provided by binding corporate rules
- Part 3 (law enforcement processing): transfers approved by regulations
- Part 4 Repeal of provisions in Chapter 3 of Part 2
- Applied GDPR: power to make provision in consequence of GDPR regulations
- Applied GDPR: national security certificates
- Part 5 The Information Commissioner
- Confidentiality of information
- Part 6 Enforcement
- GDPR: maximum amount of penalties
- GDPR: right to an effective remedy against the Commissioner