Data Protection Act (DPA): What It Is & Why It Matters

Clipboard with a document titled 'DATA PROTECTION ACT (DPA)' being signed with a pen; nearby are glasses and a blue lock icon for security.

If you handle customer records, employee files, or supplier details, someone in your business has almost certainly asked what the DPA data protection act actually requires. It’s a fair question. UK GDPR gets most of the attention, but the Data Protection Act 2018 sits alongside it and fills in the gaps GDPR leaves for member states to decide, from criminal records processing to how law enforcement and intelligence services handle personal data.

So what is a data protection act, in plain terms? It’s UK legislation that sets out the rules organisations must follow when they collect, store, and use personal information, and it gives individuals rights over their own data. Understanding what is the purpose of the data protection act matters whether you’re drafting a privacy policy or responding to a subject access request.

This article walks through what the Act covers, the key principles it establishes, who it applies to, and how it connects to your day-to-day compliance obligations. We work with businesses on ISO 27001 and cyber risk daily, and the DPA is usually where those conversations start.

Why the Data Protection Act matters for your business

Most business owners think of the Data Protection Act 2018 as a compliance box to tick, but that framing undersells what’s actually at stake. Get it wrong and you’re not just risking a fine, you’re risking the trust that keeps customers, suppliers, and staff willing to hand over their personal details in the first place. Get it right and you build a genuine operational advantage, because organisations that can demonstrate solid data handling practices win contracts, pass supplier due diligence checks, and recover faster when something does go wrong.

The legal and financial stakes

Enforcement under the Act is not theoretical. The Information Commissioner’s Office (ICO) has the power to issue fines, order audits, and force organisations to stop processing data altogether. Under UK GDPR, which the Act implements domestically, penalties sit on two tiers depending on the severity of the breach.

The legal and financial stakes

TierMaximum fineTypical trigger
Standard£8.7 million or 2% of global turnoverRecord-keeping failures, inadequate security measures
Higher£17.5 million or 4% of global turnoverBreaches of core data protection principles, unlawful processing

These figures come straight from the ICO’s guidance on penalties, and they apply regardless of company size. A five-person consultancy faces the same legal exposure as a national retailer, just scaled to turnover.

A data breach doesn’t just cost you a fine, it costs you the trust that took years to build.

Trust as a competitive advantage

Beyond the penalties, customer confidence is increasingly a deciding factor in who wins business. Procurement teams now routinely ask suppliers to prove they handle personal data properly before signing a contract, particularly in sectors like insurance, finance, and healthcare. Showing that you understand and apply the Act’s principles, rather than just having a privacy policy nobody reads, signals to clients and partners that you take information security seriously across the board, not just on paper.

Where the DPA touches your daily operations

Someone unfamiliar with the Act often assumes it only matters to marketing teams sending emails or HR departments storing CVs. In reality, it touches almost every function in a modern business:

  • Customer records: how you store, access, and eventually delete purchase history and contact details
  • Employee data: payroll, performance reviews, health information, and disciplinary records
  • Supplier and partner data: contracts, financial details, and shared systems access
  • IT and security systems: logging, backups, and who has permission to view what
  • Incident response: your legal obligation to report certain breaches to the ICO within 72 hours

That last point catches out a lot of businesses. Under the Act, you don’t get to quietly fix a breach and move on if personal data was compromised in a way likely to risk people’s rights and freedoms. You have to report it, and the clock starts the moment you become aware, not when you’ve finished investigating. Working through what counts as a reportable incident before one happens saves a lot of panic later, which is exactly why incident response planning and DPA compliance tend to sit on the same to-do list.

The key principles of the Data Protection Act

Every obligation under the Data Protection Act 2018 traces back to seven core principles, borrowed directly from UK GDPR and woven into the Act’s framework. These aren’t abstract legal ideas. They’re the practical test the ICO applies when deciding whether an organisation handled personal data properly, and they should shape how you design any system that touches customer or staff information.

The seven principles at a glance

Below is the full list as set out in Article 5 of UK GDPR, which the Act incorporates into domestic law.

PrincipleWhat it means in practice
Lawfulness, fairness, transparencyYou need a valid legal basis for processing and must tell people what you’re doing with their data
Purpose limitationData collected for one reason can’t quietly get reused for something unrelated
Data minimisationCollect only what you actually need, not everything you might one day find useful
AccuracyKeep records correct and up to date, and fix errors when they’re flagged
Storage limitationDon’t hold personal data longer than necessary; set retention periods and stick to them
Integrity and confidentialityProtect data with appropriate technical and organisational security measures
AccountabilityYou must be able to demonstrate compliance, not just claim it

If you can’t demonstrate a principle, the ICO will treat it as though you never applied it.

Applying them in practice

Getting these principles onto paper is one thing, embedding them into daily operations is another. Storage limitation, for example, sounds simple until you audit a CRM that’s been quietly accumulating contact records since 2015 with no deletion schedule ever applied. Handling that properly means setting retention periods by data type, not by department habit, and building deletion into your systems rather than relying on someone remembering to do it manually.

Minimisation causes similar problems. Sales teams often want every field they can get on a customer, but each extra field is another piece of data you’re legally responsible for protecting. Reviewing what you actually collect against what you actually use tends to reveal a lot of unnecessary risk sitting in forms nobody’s questioned in years. These principles work best when they’re checked regularly, not treated as a one-time policy exercise.

Rights and responsibilities under the DPA

The Data Protection Act doesn’t just impose rules on organisations, it hands individuals a set of enforceable data subject rights that you need to be ready to act on at short notice. Ignoring a request, or handling it badly, is one of the fastest ways to end up on the ICO’s radar, because rights requests are often the first thing an unhappy customer or ex-employee tries before making a formal complaint.

The rights individuals hold

Each person whose data you process can exercise the following rights under the Act:

  • Right of access: request a copy of the personal data you hold on them (a subject access request, or SAR)
  • Right to rectification: have inaccurate or incomplete data corrected
  • Right to erasure: request deletion of their data in certain circumstances, sometimes called the "right to be forgotten"
  • Right to restrict processing: pause how you use their data while a dispute is resolved
  • Right to data portability: receive their data in a usable format to transfer elsewhere
  • Right to object: object to processing for direct marketing or based on legitimate interests

Most SARs must be answered within one calendar month, and that clock starts the moment the request lands, not when you get round to reading it.

What this means for your business

Someone in your organisation needs clear ownership of these requests, whether that’s a Data Protection Officer, a compliance lead, or an outsourced adviser. Responsibilities under the Act extend beyond just responding to requests: you also need documented processes for identifying personal data quickly, verifying who’s asking before you hand anything over, and logging every request in case the ICO ever asks for evidence.

A rights request you can’t fulfil on time is a compliance failure, even if nothing was ever mishandled.

Training matters here too. Front-line staff, not just IT or legal, are usually the first people to receive a request, often by email or over the phone, and they need to know it has to be escalated immediately rather than filed away. The ICO’s guide to individual rights sets out the detail, but building the internal habit of recognising and routing these requests fast is what actually keeps you compliant.

How to comply with the Data Protection Act

Compliance with the Data Protection Act 2018 isn’t a document you write once and file away. It’s an ongoing operational habit, and most businesses that fall foul of the ICO didn’t lack a policy, they lacked a process for actually following it. Building compliance properly means starting with the basics and then making sure they get maintained as your business changes, adds new suppliers, or launches new systems.

Build the foundations first

Getting the groundwork right makes everything downstream easier, from answering a subject access request to surviving an ICO audit. Start with these steps:

  • Map your data: know what personal data you hold, where it sits, and why you collected it
  • Record your lawful basis: document the legal grounds for every type of processing you carry out
  • Appoint responsibility: assign a Data Protection Officer or compliance lead, even if it’s a part-time role
  • Write clear policies: privacy notices, retention schedules, and an incident response plan that staff can actually follow
  • Vet your suppliers: check that any third party handling data on your behalf meets the same standards you do

Compliance built on paperwork alone collapses the first time someone actually tests it.

Keep it running day to day

Maintaining compliance means treating it as a live system rather than a static file. Regular staff training keeps people alert to phishing attempts and rights requests, both common entry points for a breach. Reviewing your data protection impact assessments whenever you introduce new software or processes catches risks before they become incidents rather than after.

Security measures need the same ongoing attention as your policies. Vulnerability assessments, endpoint monitoring, and a tested incident response plan all feed directly into the Act’s requirement for "appropriate technical and organisational measures." The ICO’s accountability framework sets out what evidence they expect you to hold if they ever ask.

Working with a partner who handles cyber risk assessments and ISO 27001 alignment alongside DPA compliance means these pieces reinforce each other instead of sitting in separate silos, which is usually where gaps quietly appear.

Data Protection Act vs UK GDPR: what’s the difference

Confusion between these two pieces of legislation is common, and it’s understandable given how tightly they’re linked. UK GDPR sets out the core data protection framework, largely inherited from the EU regulation after Brexit, while the Data Protection Act 2018 is the domestic law that implements it, fills in the gaps GDPR leaves open, and extends coverage to areas GDPR doesn’t touch at all, like law enforcement and national security processing. Neither works properly without the other, which is why businesses rarely deal with one in isolation.

What each piece of legislation actually covers

UK GDPR provides the principles, lawful bases, and individual rights that most businesses interact with daily. The Act builds on top of that, covering exemptions, enforcement powers, and specific processing rules that GDPR deliberately left to member states to decide.

AspectUK GDPRData Protection Act 2018
ScopeGeneral rules for processing personal dataImplements GDPR domestically plus extra provisions
Covers law enforcement dataNoYes, Part 3
Covers intelligence servicesNoYes, Part 4
Sets exemptions (journalism, research)LimitedYes, detailed exemptions
Enforcement bodyICOICO

Treat UK GDPR and the Data Protection Act as one system, not two competing rulebooks.

Why the distinction matters for compliance

Understanding what is the purpose of the Data Protection Act in relation to GDPR isn’t just academic. If you’re a school handling safeguarding data, a healthcare provider processing special category information, or a business dealing with a subject access request that touches on criminal records, you’re relying on Part 2 and Part 3 of the Act, not GDPR alone. Getting the two confused often leads businesses to assume GDPR’s general rules cover every scenario, when the Act’s specific exemptions or extra safeguards actually apply instead. Reviewing which parts of the Act apply to your sector, alongside your UK GDPR obligations, gives you a clearer picture of where your real compliance gaps sit rather than assuming a generic privacy policy covers everything.

Real-world breaches and penalties under the DPA

Numbers on a page only tell you so much. Looking at actual ICO enforcement action shows how ordinary the failures usually are: a missed patch, an unencrypted laptop, a supplier contract nobody checked properly. None of the businesses below set out to breach the Act, they just treated a control as optional until it wasn’t.

Notable enforcement cases

Several cases have shaped how the ICO applies the Act in practice, and they cut across sectors and company sizes.

Notable enforcement cases

OrganisationWhat happenedOutcome
British AirwaysAttackers harvested customer payment data via a compromised website script£20 million fine, reduced from an initial £183 million notice
Marriott InternationalGuest reservation data exposed after an acquired system was compromised years earlier£18.4 million fine
InterservePhishing attack led to malware infection and exposure of up to 113,000 employees’ data£4.4 million fine for inadequate security measures
Clearview AIFacial recognition images scraped without a lawful basis or transparency£7.5 million fine and enforcement notice

These figures come from the ICO’s enforcement action records, which publish full details of every fine and the reasoning behind it.

Most enforcement cases trace back to one basic control that was never properly implemented.

What these cases actually teach you

Patterns emerge once you look past the headline figures. Legacy systems inherited through acquisitions, as with Marriott, carry risk long after the deal closes. Phishing, as with Interserve, remains the most common route into a network regardless of company size. Scraping personal data without consent, as with Clearview AI, shows the ICO will act even when the organisation itself never suffered a breach.

Quantifying the fine is only half the story. Reputational damage, lost contracts, and the internal cost of remediation often exceed the penalty itself. Reviewing published ICO decisions against your own setup, particularly around legacy systems, supplier access, and phishing resilience, gives you a realistic sense of where your organisation would actually stand if it were tested tomorrow.

dpa data protection act infographic

Putting data protection into practice

The Data Protection Act 2018 isn’t a document to file away after a compliance audit. It’s a working set of obligations that touches every part of your business, from the CRM your sales team updates daily to the incident response plan you hope you never need. Understanding the seven principles, knowing your responsibilities around data subject rights, and keeping UK GDPR and the Act working together as one system gives you a genuine foundation, not just paperwork that looks good until someone tests it.

Most organisations don’t fail because they lack a policy. They fail because nobody maintains it once the initial project ends. Building that ongoing discipline, mapping data, training staff, testing your defences, is where real protection starts.

If you’d rather have specialists handle that groundwork alongside your wider cyber risk posture, talk to TrustedIA about getting your compliance genuinely audit-ready.