FREE example training video

UK GDPR principles and the Data Protection 2018 Act explained

DSH Article images (4)

What are the GDPR principles?

The GDPR principles form the foundation of UK data protection law. Every organisation processing personal data should understand and apply them.

The seven principles are:

  • Lawfulness, fairness and transparency – Use personal data legally, fairly and openly.
  • Purpose limitation – Only use data for the specific reason it was collected.
  • Data minimisation – Collect only the personal data you genuinely need.
  • Accuracy – Keep personal data correct and up to date.
  • Storage limitation – Do not keep personal data longer than necessary.
  • Integrity and confidentiality (security) – Protect personal data against loss, misuse or unauthorised access.
  • Accountability – Take responsibility and keep evidence that you comply with data protection law.

Rather than viewing these as separate rules, organisations should consider them throughout every stage of handling personal data.

What is the Data Protection Act 2018?

The Data Protection Act 2018 complements UK GDPR by providing the UK’s legislative framework for data protection.

It:

  • Supplements UK GDPR.
  • Sets out additional rules for specific processing activities.
  • Covers law enforcement and intelligence services.
  • Establishes enforcement powers and penalties.
  • Provides exemptions where appropriate.

For most organisations, UK GDPR and the Data Protection Act 2018 work together rather than separately.

What is the Data (Use and Access) Act?

The Data (Use and Access) Act updates and modernises the UK’s data protection framework, but it does not replace the UK GDPR or the Data Protection Act 2018 (DPA 2018). Instead, it amends both pieces of legislation to make certain requirements clearer and more proportionate while maintaining high standards of data protection.

In summary:

  • UK GDPR remains the primary law governing how organisations process personal data.
  • The Data Protection Act 2018 continues to supplement the UK GDPR by providing UK-specific provisions, including rules for law enforcement processing, intelligence services, and regulatory enforcement.
  • The Data (Use and Access) Act amends both the UK GDPR and the DPA 2018, introducing targeted reforms to simplify compliance, improve data sharing, support innovation and economic growth, and enable trusted digital services, while preserving individuals’ fundamental rights and protections.

Overall, organisations should continue to treat the UK GDPR and the DPA 2018 as the core UK data protection framework, with the Data (Use and Access) Act providing updates and enhancements rather than creating a wholly new regime.

How Data Support Hub can help

Our platform brings everything you need into one platform, with practical guidance, easy-to-use tools and straightforward support to help you understand your responsibilities, protect personal data and stay compliant with confidence.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top