The Data Protection Act 1998 shaped how UK organisations handled personal information for two decades. When the Data Protection Act 2018 replaced it, the rules changed significantly. Stronger individual rights, tougher penalties, broader territorial reach, and new obligations around accountability and transparency all came into effect.
This guide breaks down both Acts side by side. It covers what the DPA 1998 required, what the DPA 2018 introduced, how the two compare across every major area, and what organisations must do now to stay compliant under the current framework, including changes brought by the Data (Use and Access) Act 2025.
What Is the Data Protection Act 1998?
The Data Protection Act 1998 (DPA 1998) was an Act of the UK Parliament that governed how organisations collected, stored, and used personal data. It implemented the EU Data Protection Directive 1995 into domestic law and replaced the earlier Data Protection Act 1984, which had focused almost exclusively on computer records.
The DPA 1998 applied to both digital records and organised paper filing systems. It introduced a framework built around eight data protection principles and gave individuals a set of basic rights over their personal information.
The Act was enforced by the Information Commissioner’s Office (ICO), which had the power to issue enforcement notices and impose fines of up to 500,000 pounds for serious breaches.
The Eight Principles of the DPA 1998
Schedule 1 of the DPA 1998 listed eight data protection principles that all data controllers had to follow:
- Personal data must be processed fairly and lawfully.
- Personal data must be obtained for specified and lawful purposes and not processed beyond those purposes.
- Personal data must be adequate, relevant, and not excessive for the stated purpose.
- Personal data must be accurate and, where necessary, kept up to date.
- Personal data must not be kept for longer than necessary.
- Personal data must be processed in line with the rights of data subjects.
- Appropriate technical and organisational measures must protect against unauthorised or unlawful processing, accidental loss, destruction, or damage.
- Personal data must not be transferred outside the European Economic Area unless adequate protections are in place.
These principles formed the backbone of UK data protection law for 20 years. While they covered the essentials, the DPA 1998 had notable gaps, particularly around digital consent, breach notification, and enforcement powers.
Limitations of the DPA 1998
The DPA 1998 was designed for a pre-smartphone, pre-social-media era. Several weaknesses became apparent as technology evolved:
- No mandatory breach notification. Organisations were not legally required to report data breaches to the ICO or affected individuals.
- Weak consent rules. The Act did not require explicit opt-in consent for most data collection.
- Low penalties. The maximum fine was 500,000 pounds, a figure that offered limited deterrence to large corporations.
- Limited territorial scope. The Act only applied to organisations operating within the UK.
- No right to erasure. Individuals could not compel organisations to delete their personal data.
- No data portability. There was no right to receive personal data in a portable, machine-readable format.
What Is the Data Protection Act 2018?
The Data Protection Act 2018 (DPA 2018) replaced the DPA 1998 on 25 May 2018. It brought the EU General Data Protection Regulation (GDPR) into UK law and went further by covering areas the GDPR does not address directly, such as law enforcement processing, intelligence services, and immigration data.
After Brexit, the UK retained GDPR standards through what is now known as the UK GDPR. The DPA 2018 works alongside the UK GDPR, supplementing its provisions and filling in national-level detail. The two must be read together to understand the full picture of UK data protection obligations.
Structure of the DPA 2018
The DPA 2018 is divided into several parts:
- Part 1: Preliminary provisions, definitions, and the role of the Information Commissioner.
- Part 2: General processing, which supplements the UK GDPR for standard data processing activities.
- Part 3: Law enforcement processing, implementing the EU Law Enforcement Directive for police, prosecutors, and other competent authorities.
- Part 4: Intelligence services processing, setting rules for MI5, MI6, and GCHQ.
- Part 5: The Information Commissioner, enforcement powers, and penalties.
- Part 6: Miscellaneous provisions, including rules on re-identification of de-identified data.
The Seven Principles Under UK GDPR
The UK GDPR consolidated the eight principles of the DPA 1998 into seven, adding a new accountability principle:
- Lawfulness, fairness, and transparency: Processing must have a valid legal basis and be carried out openly.
- Purpose limitation: Data must be collected for specified, explicit, and legitimate purposes.
- Data minimisation: Only data that is necessary for the stated purpose should be collected.
- Accuracy: Personal data must be accurate and kept up to date.
- Storage limitation: Data must not be kept longer than necessary.
- Integrity and confidentiality: Appropriate security measures must protect personal data.
- Accountability: Organisations must demonstrate compliance with all the above principles.
The accountability principle is arguably the most significant addition. Under the DPA 1998, organisations simply had to comply. Under the DPA 2018 and UK GDPR, they must actively prove compliance through documentation, impact assessments, and internal governance structures.
Data Protection Act 1998 vs 2018: Key Differences
While both Acts share the same fundamental goal of protecting personal data, the DPA 2018 is substantially broader, more detailed, and more enforceable. The following comparison covers every major area where the two Acts differ.
| Area | DPA 1998 | DPA 2018 / UK GDPR |
| Legal basis | EU Data Protection Directive 1995 | EU GDPR (now UK GDPR post-Brexit) |
| Territorial scope | UK-based organisations only | Any organisation processing UK residents’ data |
| Data principles | Eight principles | Seven principles with explicit accountability |
| Consent | Implied consent often accepted | Must be freely given, specific, informed, unambiguous |
| Right to erasure | Not available | Individuals can request deletion of their data |
| Data portability | Not available | Right to receive data in machine-readable format |
| Breach notification | Not mandatory | Mandatory within 72 hours to the ICO |
| Data Protection Officer | Not required | Required for public bodies and large-scale processing |
| Maximum fine | 500,000 pounds | 17.5 million pounds or 4% of global turnover |
| Children’s data | No specific provisions | Consent age set at 13 in the UK |
| DPIAs | Not required | Required for high-risk processing |
| Law enforcement | Covered by general provisions | Separate Part 3 regime with dedicated rules |
User Consent
Under the DPA 1998, user consent was loosely defined. Organisations could often rely on implied consent, pre-ticked boxes, or bundled terms and conditions. The DPA 2018 and UK GDPR transformed this. Consent must now be freely given, specific, informed, and unambiguous. It requires a clear affirmative action, such as ticking an unticked box or signing a statement. Silence, pre-ticked boxes, and inactivity do not count.
Organisations must also make it as easy to withdraw consent as it was to give it, and they must keep records proving that valid consent was obtained.
Individual Rights
The DPA 1998 gave individuals a basic right of access to their personal data, known as a Subject Access Request (SAR). Organisations could charge up to 10 pounds for responding. The DPA 2018 expanded individual rights significantly:
- Right to be informed: Organisations must explain how and why they use personal data through privacy notices.
- Right of access: Individuals can request copies of their data free of charge.
- Right to rectification: Individuals can have inaccurate data corrected.
- Right to erasure: Also called the right to be forgotten, this allows individuals to request deletion of their data in specific circumstances.
- Right to restrict processing: Individuals can limit how their data is used.
- Right to data portability: Individuals can receive their data in a portable format and transfer it to another provider.
- Right to object: Individuals can object to processing based on legitimate interests or direct marketing.
- Rights related to automated decision-making and profiling: Individuals can challenge decisions made solely by automated means.
Enforcement and Penalties
The enforcement gap between the two Acts is substantial. Under the DPA 1998, the ICO could issue enforcement notices and monetary penalties up to 500,000 pounds. In practice, fines were rare and small.
Under the DPA 2018, the ICO has two tiers of penalties. The lower tier allows fines of up to 8.7 million pounds or 2% of annual worldwide turnover for less severe infringements. The higher tier allows fines of up to 17.5 million pounds or 4% of annual worldwide turnover for the most serious breaches, including unlawful processing or failing to obtain valid consent.
ICO enforcement has intensified in recent years. In the first half of 2025, the ICO issued six fines totalling 5.6 million pounds, double the 2.7 million levied across 18 fines in all of 2024. Notable recent penalties include 14 million pounds against Capita in October 2025 for inadequate cybersecurity and 3.07 million pounds against Advanced Computer Software Group for ransomware vulnerabilities.
Breach Notification
The DPA 1998 had no mandatory breach notification requirement. Organisations could suffer a data breach and choose not to report it.
The DPA 2018 introduced a strict obligation: organisations must notify the ICO within 72 hours of becoming aware of a personal data breach that poses a risk to individuals. If the breach is likely to result in a high risk to people’s rights and freedoms, the affected individuals must also be notified without undue delay.
Data Protection Officers
The DPA 1998 did not require organisations to appoint a Data Protection Officer. The DPA 2018 makes DPO appointment mandatory in three situations: when processing is carried out by a public authority or body, when core activities involve regular and systematic large-scale monitoring of individuals, or when core activities involve large-scale processing of special category data or criminal offence data.
Data Protection Impact Assessments
Data Protection Impact Assessments (DPIAs) are a new requirement under the DPA 2018. Organisations must carry out a DPIA before any processing that is likely to result in a high risk to individuals. This includes large-scale profiling, systematic monitoring of public areas, and processing of special category data on a large scale.
Lawful Bases for Processing Under the DPA 2018
One of the most significant changes is the requirement to identify a lawful basis before processing personal data. Article 6 of the UK GDPR sets out six lawful bases:
- Consent: The individual has given clear consent for a specific purpose.
- Contract: Processing is necessary to fulfil or prepare a contract with the individual.
- Legal obligation: Processing is necessary to comply with the law.
- Vital interests: Processing is necessary to protect someone’s life.
- Public task: Processing is necessary for a task in the public interest or for official functions.
- Legitimate interests: Processing is necessary for legitimate interests, provided these do not override the individual’s rights.
Under the DPA 1998, the concept of lawful bases existed but was less clearly defined and less strictly enforced. The DPA 2018 requires organisations to determine, document, and communicate their lawful basis before processing begins.
Special Category Data
Both Acts recognise that certain types of personal data require extra protection. Under the DPA 1998, this was called “sensitive personal data.” Under the DPA 2018 and UK GDPR, it is referred to as “special category data.”
Special category data includes information about racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, health data, sex life, and sexual orientation.
Processing special category data requires both a lawful basis under Article 6 and a separate condition under Article 9 of the UK GDPR. These conditions include explicit consent, employment obligations, vital interests, activities of not-for-profit bodies, legal claims, substantial public interest, health and social care, and public health.
International Data Transfers
The rules around transferring personal data outside the UK have evolved significantly.
Under the DPA 1998
The eighth data protection principle prohibited transfers of personal data to countries outside the EEA unless the destination country ensured an adequate level of protection. In practice, adequacy assessments were limited and enforcement was minimal.
Under the DPA 2018 and UK GDPR
International transfers are permitted where the destination country has received an adequacy decision from the UK government, where appropriate safeguards are in place (such as Standard Contractual Clauses or Binding Corporate Rules), or where specific derogations apply.
On 19 December 2025, the European Commission renewed the UK’s adequacy decision until 27 December 2031, confirming that data can continue to flow freely between the UK and EEA.
The Data (Use and Access) Act 2025 further refined the UK’s approach, replacing the test of “essential equivalence” with a new threshold requiring that safeguards in the destination country are “not materially lower than” those in the UK.
Law Enforcement and Intelligence Services Processing
One area where the DPA 2018 goes well beyond the DPA 1998 is in regulating data processing by law enforcement and intelligence services.
Part 3: Law Enforcement Processing
Part 3 of the DPA 2018 implements the EU Law Enforcement Directive. It applies to “competent authorities” such as police forces, the National Crime Agency, prosecutors, and other bodies exercising law enforcement functions. It sets out specific data protection principles, lawful bases, and individual rights for law enforcement processing, separate from the UK GDPR regime.
Part 4: Intelligence Services Processing
Part 4 covers processing by MI5, MI6, and GCHQ. These bodies operate under a different set of principles and safeguards, reflecting the unique requirements of national security work.
The DPA 2018 After Brexit
When the UK left the European Union, the EU GDPR ceased to apply directly. However, the UK government retained its standards through the European Union (Withdrawal) Act 2018, which transposed the GDPR into domestic law as the “UK GDPR.”
The DPA 2018 continues to work alongside the UK GDPR, and the ICO remains the supervisory authority. The EU’s renewal of the UK’s adequacy decision in December 2025 confirmed that the UK’s data protection framework continues to meet European standards.
The Data (Use and Access) Act 2025: What Changed
The Data (Use and Access) Act 2025 (DUAA) received Royal Assent on 19 June 2025 and its main data protection provisions came into force on 5 February 2026. Key changes:
- Subject access requests: Organisations can now limit searches to what is “reasonable and proportionate.”
- Recognised legitimate interests: A new lawful basis pre-approving certain processing activities.
- International transfers: The adequacy test shifted from “essential equivalence” to “not materially lower than” UK standards.
- Complaints procedure: From 19 June 2026, data subjects will have the right to complain directly to controllers before escalating to the ICO.
- PECR penalties: From 5 February 2026, maximum PECR fines rose from 500,000 pounds to 17.5 million pounds or 4% of turnover.
Compliance Checklist for Organisations
Organisations operating under the DPA 2018 and UK GDPR should ensure they have the following in place:
- A documented lawful basis for every processing activity.
- Clear, accessible privacy notices explaining how personal data is used.
- Valid, demonstrable consent mechanisms where consent is the lawful basis.
- A process for handling data subject access requests within one month.
- An internal breach detection, investigation, and reporting procedure with 72-hour notification capability.
- Data Protection Impact Assessments for high-risk processing.
- A Data Protection Officer where legally required.
- Records of processing activities.
- Appropriate technical and organisational security measures.
- Contracts with data processors that meet UK GDPR requirements.
- A lawful mechanism for any international data transfers.
- Staff training on data protection obligations and breach response.
Common Mistakes Organisations Make
- Treating consent as the default lawful basis. Consent is only one of six lawful bases and is not always the most appropriate. Relying on consent when legitimate interests or contractual necessity would apply creates unnecessary risk if consent is withdrawn.
- Using outdated privacy notices. Privacy notices written under the DPA 1998 do not meet DPA 2018 requirements.
- Ignoring breach notification timelines. The 72-hour reporting window starts from when the organisation becomes “aware” of the breach, not from when it completes an investigation.
- Failing to conduct DPIAs. Many organisations skip Data Protection Impact Assessments for new projects.
- Over-retaining data. Keeping personal data “just in case” violates the storage limitation principle.
- Neglecting processor agreements. Data sharing with third-party processors without compliant contracts is a common audit finding.
Closing Insights
The Data Protection Act 2018 represents a major step forward from the Data Protection Act 1998, introducing stronger rights, greater accountability, and stricter compliance requirements. Understanding these differences helps organisations reduce risk, protect personal data, and meet today’s evolving UK data protection standards while maintaining trust with customers and regulators.
Stay Globally Compliant with Seers
Managing data protection obligations across your organisation does not have to be overwhelming. Seers provides privacy management tools, GDPR audit services, cookie consent solutions, and staff training to help you meet your compliance requirements under the DPA 2018 and UK GDPR.
Frequently Asked Questions
Does the Data Protection Act 2018 replace the Data Protection Act 1998?
Yes. The DPA 2018 fully replaced the DPA 1998 on 25 May 2018. It brought GDPR into UK law, introduced stronger individual rights including the right to erasure and data portability, expanded territorial scope beyond UK borders, and significantly increased enforcement penalties. Organisations previously compliant with the DPA 1998 needed to review and update their policies, procedures, and documentation to meet the new requirements.
What is the difference between UK GDPR and the Data Protection Act 2018?
The UK GDPR is the retained version of the EU GDPR, adapted for the UK after Brexit. The DPA 2018 supplements the UK GDPR by filling in areas where national-level detail is needed, such as the age of consent for children (set at 13 in the UK), exemptions for law enforcement and intelligence services, and specific conditions for processing special category data. Both must be read together for the complete picture.
What are the penalties for breaching the Data Protection Act 2018?
The ICO can impose fines in two tiers. The lower tier allows penalties of up to 8.7 million pounds or 2% of annual worldwide turnover for administrative failings. The higher tier allows up to 17.5 million pounds or 4% of global turnover for serious infringements such as unlawful processing, failure to obtain consent, or violating data subject rights. Recent enforcement shows the ICO is actively using these powers.
Do I need a Data Protection Officer under the DPA 2018?
A DPO is mandatory if your organisation is a public authority, if your core activities require regular and systematic large-scale monitoring of individuals, or if you process special category data or criminal offence data on a large scale. Even where not legally required, the ICO recommends appointing a DPO as good practice, particularly for organisations handling significant volumes of personal data.
What is the age of consent for children under the DPA 2018?
The DPA 2018 sets the age of consent for information society services at 13 in the UK, lower than the default age of 16 set by the EU GDPR. For children under 13, a parent or guardian must provide or authorise consent. Organisations offering online services to children must make reasonable efforts to verify that consent has been properly given or authorised.
How does the DPA 2018 handle data breaches?
Organisations must notify the ICO within 72 hours of becoming aware of a personal data breach that poses a risk to individuals. If the breach is likely to result in a high risk to affected people, those individuals must also be informed without undue delay. Failure to report is a regulatory offence carrying its own penalties, separate from any fine for the breach itself.
What is a Data Protection Impact Assessment?
A DPIA is a structured process for identifying and minimising data protection risks before starting any processing likely to result in a high risk to individuals. It must describe the processing, assess its necessity and proportionality, evaluate risks to data subjects, and outline mitigation measures. DPIAs are mandatory under the DPA 2018 for high-risk activities such as large-scale profiling or systematic monitoring.
Is the GDPR still relevant in the UK after Brexit?
Yes. The UK retained GDPR standards through the UK GDPR, which has the same practical effect as the EU version for UK-based processing. The DPA 2018 works alongside the UK GDPR. The EU also renewed the UK’s adequacy decision in December 2025, confirming that data can continue to flow freely between the UK and EEA until at least 2031 without additional safeguards.
What lawful bases can I use under the DPA 2018?
There are six lawful bases under Article 6 of the UK GDPR: consent, contractual necessity, legal obligation, vital interests, public task, and legitimate interests. The Data (Use and Access) Act 2025 added a seventh category of “recognised legitimate interests” for pre-approved processing purposes. Organisations must identify and document their lawful basis before processing begins.
What are the main rights of individuals under the DPA 2018?
Individuals have eight key rights: the right to be informed, right of access, right to rectification, right to erasure, right to restrict processing, right to data portability, right to object, and rights related to automated decision-making and profiling. Organisations must respond to rights requests within one month and cannot charge a fee unless the request is manifestly unfounded or excessive.
How does the DPA 2018 apply to international data transfers?
Personal data can be transferred outside the UK where the destination country has a UK adequacy decision, where appropriate safeguards such as Standard Contractual Clauses are in place, or where specific derogations apply. The Data (Use and Access) Act 2025 changed the adequacy test to require safeguards “not materially lower than” UK standards, replacing the previous “essential equivalence” threshold.
What changed with the Data (Use and Access) Act 2025?
The DUAA 2025 introduced several reforms including reasonable and proportionate subject access request searches, a new recognised legitimate interests lawful basis, updated international transfer rules, a mandatory complaints procedure for controllers from June 2026, and aligned PECR penalties with UK GDPR maximums from February 2026. These changes are now in effect and organisations should update their processes accordingly.
