Everything you need to know about UK DPA 2018 compliance, data security requirements, and secure data disposal.
Following Brexit, organizations handling the personal data of individuals in the United Kingdom must navigate two closely related legal frameworks: the Data Protection Act 2018 (DPA 2018) and the UK General Data Protection Regulation (UK GDPR). Together, they form the backbone of data protection law in the UK, and while they closely mirror the EU's GDPR, there are meaningful differences organizations need to understand.
Background
The Data Protection Act 2018 was originally enacted to implement the EU's GDPR into UK domestic law and to give effect to the EU Law Enforcement Directive. When the UK left the EU on January 31, 2020, and the Brexit transition period ended on December 31, 2020, the EU GDPR was incorporated directly into UK domestic law as the "UK GDPR" through the European Union (Withdrawal) Act 2018, with technical amendments made via the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019. The DPA 2018 continues to operate alongside UK GDPR, filling in gaps and covering areas outside UK GDPR's scope, such as law enforcement processing and national security.
How UK GDPR Relates to EU GDPR
UK GDPR is, in substance, a near-identical copy of the EU GDPR at the point the UK left the EU, adapted for a UK-only context. The core principles, individual rights, and general obligations remain largely the same. However:
- The UK's supervisory authority is the Information Commissioner's Office (ICO), not an EU Data Protection Authority
- UK GDPR and EU GDPR can diverge over time as each jurisdiction amends its own law independently
- Organizations that handle data of both UK and EU residents may need to comply with both frameworks simultaneously, including appointing separate UK and EU representatives where required
Who Must Comply
The UK GDPR and DPA 2018 apply to organizations that:
- Are established in the UK and process personal data, or
- Are established outside the UK but offer goods or services to individuals in the UK, or monitor their behavior
Key Rights and Principles
The frameworks preserve the core data protection principles familiar from EU GDPR — lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability — along with individual rights including access, rectification, erasure, restriction of processing, data portability, and objection to processing.
The DPA 2018's Additional Scope
Beyond implementing UK GDPR, the DPA 2018 separately covers:
- Processing by law enforcement agencies for policing and criminal justice purposes
- Processing by intelligence services
- Specific derogations and exemptions applicable in a UK context, such as for journalism, research, and archiving purposes
Enforcement and Penalties
The ICO enforces both frameworks and can impose fines of up to £17.5 million or 4% of global annual turnover, whichever is higher, for the most serious infringements — deliberately set to mirror the maximum penalties under EU GDPR. The ICO can also issue enforcement notices, conduct audits, and order organizations to stop processing data.
Data Erasure and the Right to Be Forgotten
As with EU GDPR, UK GDPR's storage limitation principle and right to erasure require organizations to permanently destroy personal data once it is no longer needed or when a valid erasure request is made. This obligation extends to physical storage media — laptops, servers, and mobile devices retired from service must be sanitized using verifiable, standards-based methods, since data recovered from improperly disposed hardware can trigger a reportable data breach under UK GDPR's 72-hour notification requirement.
Official Regulatory Reference
For the most accurate, authentic, and up-to-date legal text, we highly recommend consulting the official legislative documentation provided by the respective regional government or data protection authority. Relying on the official source of truth is the best way to ensure full compliance.
Streamlining Compliance with D-Secure Solutions
Meeting strict data sanitization requirements doesn't have to be a manual, error-prone process. Our enterprise data sanitization solutions are purpose-built to help organizations seamlessly meet these strict regulatory mandates.
By utilizing D-Secure Drive Eraser, your organization can permanently wipe sensitive data and automatically generate tamper-evident erasure certificates. This creates a rigorous, verifiable audit trail that satisfies regulatory bodies and eliminates the risk of data leaks.
Conclusion
For organizations operating in or serving customers in the UK, compliance requires treating the DPA 2018 and UK GDPR as a combined framework, understanding where UK law now diverges from its EU counterpart, and maintaining the same rigor around data subject rights, breach notification, and secure data disposal that GDPR compliance has always demanded.
No comments yet. Be the first to comment.