These UK data protection FAQs cover the Data Protection Act 2018, UK GDPR, responsibilities, training, fees, breaches, reporting, and how to protect personal data.
Data protection is important because it prevents personal information from being misused, lost, or accessed without permission, protects individuals’ rights, and helps organisations avoid legal penalties, financial loss, and reputational damage.
The Data Protection Act 2018 is the UK law that sits alongside the UK GDPR, setting out how personal data must be handled in the UK. Together, they establish the legal rules for collecting, using, storing, and protecting personal data, and define individuals’ rights and organisations’ responsibilities.
The Data Protection Act 2018 was introduced in the UK on 25 May 2018, replacing the Data Protection Act 1998 and aligning UK law with the UK GDPR.
Data protection in the UK is regulated by the Information Commissioner’s Office (ICO), which enforces data protection laws, provides guidance to organisations, and has the power to investigate breaches and issue penalties.
The three main types of data protection under UK law relate to personal data, special category data (such as health or biometric data), and criminal offence data, each of which has increasing levels of protection due to the potential risk to individuals.
An example of protected data is personal data such as a person’s name, home address, email address, National Insurance number, or health records, as this information can be used to identify an individual and must be handled securely under UK data protection law.
Data protection is the responsibility of the organisation that decides how and why personal data is used (the data controller), as well as any organisations that handle data on its behalf (data processors), with all staff having a duty to handle personal data lawfully and securely.
A Data Controller is the organisation that decides why and how personal data is collected and used. The controller has primary responsibility for complying with UK data protection law.
A Data Processor processes personal data on behalf of the controller and only follows the controller’s instructions. Processors must keep data secure and meet contractual and legal requirements, but ultimate accountability sits with the controller, as overseen by the Information Commissioner’s Office (ICO).
Yes, a privacy notice is required under UK data protection law. It explains how and why personal data is collected, used, stored, and shared, helping individuals understand what happens to their information.
A clear privacy notice supports the right to be informed, builds trust, and demonstrates compliance with legal duties. It should be provided at the point data is collected and kept up to date, in line with guidance from the Information Commissioner’s Office (ICO).
A Data Protection Impact Assessment (DPIA) is a formal process used to identify and reduce data protection risks before starting high-risk processing of personal data.
It is required when activities are likely to pose a high risk to individuals’ rights and freedoms, such as introducing new technologies, large-scale monitoring (for example CCTV), or processing sensitive personal data. A DPIA helps organisations assess necessity and proportionality, identify risks, and put measures in place to mitigate them, in line with guidance from the Information Commissioner’s Office (ICO).
Under UK data protection law, individuals (data subjects) have several key rights over their personal data. These include the right to be informed about how their data is used, the right of access to their data, the right to rectification if data is inaccurate, and the right to erasure (often called the right to be forgotten) in certain circumstances.
They also have the right to restrict processing, the right to data portability, the right to object to how their data is used (including for direct marketing), and rights related to automated decision-making and profiling.
These rights are enforced and overseen in the UK by the Information Commissioner’s Office (ICO).
A Subject Access Request (SAR) is a request made by an individual to see the personal data an organisation holds about them. Under UK data protection law, organisations must respond within one month and provide a copy of the data, along with information about how it is used, shared, and stored.
In most cases, a SAR is free of charge and can be made verbally or in writing, in line with guidance from the Information Commissioner’s Office (ICO).
You can make a request to see your personal data by submitting a Subject Access Request (SAR). This can usually be done verbally or in writing, such as by email or letter.
Once the organisation receives your request, it must respond within one month and provide a copy of your personal data, usually free of charge, along with information about how your data is used and shared. The process is overseen in the UK by the Information Commissioner’s Office (ICO).
An organisation can only keep your personal data for as long as it is needed for the specific purpose it was collected. Under UK data protection law, data must not be kept longer than necessary and should be securely deleted or anonymised once it is no longer required.
Retention periods should be clearly defined, justified (for example, to meet legal, regulatory, or contractual requirements), and explained in the organisation’s privacy notice.
The Information Commissioner’s Office (ICO) expects organisations to review data regularly and dispose of it securely when it is no longer needed.
You protect data by limiting access to those who need it, using strong passwords and multi-factor authentication, storing and sharing information securely, keeping systems up to date, training staff on data protection, and responding quickly to incidents or breaches.
Data protection still applies when working from home and organisations must take steps to keep personal data secure outside the office. Employees should use approved devices and secure connections, such as a VPN, keep software up to date, and protect devices with strong passwords or biometrics.
Care should also be taken to prevent unauthorised access, for example by locking screens, avoiding printing sensitive documents at home, securing paperwork, and not discussing confidential information where it may be overheard. These measures help reduce the risk of data breaches and support compliance with UK data protection law, as set out by the Information Commissioner’s Office (ICO).
Yes, personal data can be transferred outside of the UK, but only where appropriate safeguards are in place.
Under UK data protection law, transfers are permitted if the destination country has an adequacy decision from the UK government, meaning it provides a similar level of data protection to the UK. If no adequacy decision exists, organisations must use safeguards such as International Data Transfer Agreements (IDTAs) or approved contractual clauses to protect the data.
Organisations must also assess risks, ensure individuals are informed via a privacy notice, and comply with guidance from the Information Commissioner’s Office (ICO).
Yes, data protection law applies to CCTV and workplace monitoring because images, video, and audio that can identify individuals are personal data.
Organisations must have a lawful basis for monitoring, ensure it is necessary and proportionate, and clearly inform people that monitoring is taking place, typically through signage and a privacy notice.
Monitoring should not be excessive, and footage must be stored securely and kept only for as long as necessary, in line with guidance from the Information Commissioner’s Office (ICO).
Data protection training is not explicitly mandatory under a single law, but it is effectively required by the UK GDPR and the Data Protection Act 2018, which expect organisations to ensure staff handling personal data understand their responsibilities and are trained to process data lawfully and securely.
Data protection training should include understanding personal information, safe information handling, protecting data online, recognising risks such as social media phishing, secure use of personal devices (BYOD), keeping software up to date, managing backups, and learning from real-world case studies.
Most UK organisations that process personal data must pay an annual data protection fee to the ICO. The amount depends on your organisation’s size and turnover, and currently ranges from about £52 for micro-organisations, through £78 for small to medium organisations, up to £3,763 for large organisations.
For more details and to check which tier applies to you, see the official ICO guidance.
If you breach data protection in the UK, the Information Commissioner’s Office (ICO) can investigate and take action, which may include enforcement notices, mandatory corrective measures, reputational damage, compensation claims from affected individuals, and fines of up to £17.5 million or 4% of global annual turnover, whichever is higher.
You should report a near miss or potential security incident because it helps prevent a more serious data breach or cyber-attack.
Incidents such as sending an email to the wrong person, clicking a suspicious link, or spotting a vulnerability that did not result in harm still highlight weaknesses in processes or controls.
Reporting them allows organisations to investigate, fix issues, improve training or systems, and reduce the risk of future incidents. Early reporting also supports legal and regulatory compliance and demonstrates a proactive approach to data and cyber security, in line with expectations set by the Information Commissioner’s Office (ICO).
To report a data protection breach in the UK, you must assess the risk to individuals. If the breach is likely to risk people’s rights and freedoms, report it to the Information Commissioner’s Office (ICO) without undue delay and, where required, within 72 hours using the ICO’s online reporting form.
Low-risk breaches do not need to be reported but must be recorded internally. There is a self-assessment tool on the ICO website you can use to assess whether a breach is reportable.
UK GDPR and the Privacy and Electronic Communications Regulations (PECR) work together to regulate how organisations use personal data and carry out electronic communications.
UK GDPR sets out the general rules for processing personal data, including lawful bases, individual rights, and security requirements. PECR sits alongside UK GDPR and provides more specific rules for electronic communications, such as marketing emails and texts, telephone marketing, cookies, and similar tracking technologies.
PECR does not replace UK GDPR; organisations must comply with both. PECR focuses on how electronic communications and marketing are carried out, while UK GDPR governs how personal data is handled overall. Both are regulated and enforced in the UK by the Information Commissioner’s Office (ICO).
In most cases, yes, you need consent to send marketing emails to individuals.
Under UK law, electronic marketing is mainly governed by the Privacy and Electronic Communications Regulations (PECR), working alongside UK GDPR. You must usually obtain clear opt-in consent before sending marketing emails to individuals.
There is a limited exception known as the “soft opt-in”, which allows organisations to email existing customers if the email relates to similar products or services, the customer was given a clear chance to opt out at the time their details were collected, and they are offered an easy way to opt out in every message.
The rules are enforced by the Information Commissioner’s Office (ICO).