Data Protection Act 2018
|Act of Parliament|
|Long title||An Act to make provision for the regulation of the processing of information relating to individuals; to make provision in connection with the Information Commissioner’s functions under certain regulations relating to information; to make provision for a direct marketing code of practice; and for connected purposes.|
|Citation||2018 c 12|
|Introduced by||Lord Ashton of Hyde|
|Territorial extent||United Kingdom of Great Britain and Northern Ireland|
|Royal assent||23 May 2018|
|Repeals||Data Protection Act 1998|
|Relates to||General Data Protection Regulation, Data Protection Act 1998|
Status: Current legislation
|Text of the Data Protection Act 2018 as in force today (including any amendments) within the United Kingdom, from legislation.gov.uk.|
The Data Protection Act 2018 (c 12) is a United Kingdom Act of Parliament which updates data protection laws in the UK. It is a national law which complements the European Union's General Data Protection Regulation (GDPR) and updates the Data Protection Act 1998.
The Data Protection Act 2018 achieved Royal Assent on 23 May 2018. It applies the EU's GDPR standards. Whereas the GDPR gives member states limited opportunities to make provisions for how it applies in their country, one element of the DPA 2018 is the details of these, applying as the national law. The DPA 2018 is however not limited to the UK GDPR provisions. 
The Act has seven parts. These are outlined in Section 1:
- This Act makes provision about the processing of personal data.
- Most processing of personal data is subject to GDPR.
- Part 2 supplements the GDPR (see Chapter 2) and applies a broadly equivalent regime to certain types of processing to which the GDPR does not apply (see Chapter 3).
- Part 3 makes provision about the processing of personal data by competent authorities for law enforcement purposes and implements the Law Enforcement Directive.
- Part 4 makes provision about the processing of personal data by the intelligence services.
- Part 5 makes provision about the Information Commissioner.
- Part 6 makes provision about the enforcement of the data protection legislation.
- Part 7 makes supplementary provision, including provision about the application of this Act to the Crown and to Parliament.
The Act introduces new offences that include knowingly or recklessly obtaining or disclosing personal data without the consent of the data controller, procuring such disclosure, or retaining the data obtained without consent. Selling, or offering to sell, personal data knowingly or recklessly obtained or disclosed would also be an offence.
Essentially, the Act implements the EU Law Enforcement Directive, it implements those parts of the GDPR which 'are to be determined by Member State law' and it creates a framework similar to the GDPR for the processing of personal data which is outside the scope of the GDPR. This includes intelligence services processing, immigration services processing and the processing of personal data held in unstructured form by public authorities.
- "Publishing Service" (PDF). Gov-UK.
- "Data Protection Act 2018". ico.org.uk. 2018-07-20. Retrieved 2018-08-29.
- "Data Protection Act 2018". UK Government. Retrieved 8 August 2018. This article contains quotations from this source, which is available under the Open Government Licence v3.0. © Crown copyright.
- "New Data Protection Act finalised in the UK". www.out-law.com. Retrieved 2018-08-29.
- DIRECTIVE (EU) 2016/680 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL
- "European Union (Withdrawal) Act 2018". UK Government. Retrieved 8 August 2018.
|This legislation in the United Kingdom, or its constituent jurisdictions article is a stub. You can help Wikipedia by expanding it.|