The Data Protection Act 2018 is the UK law governing how organisations collect, store, and use personal data. It incorporates UK GDPR and is enforced by the Information Commissioner's Office. GCSE students must know its seven principles and the rights it gives to individuals over their personal data.

Personal data is any information that can identify a living person — directly or indirectly. Examples include a person's name, address, email, National Insurance number, IP address, location data, and biometric data such as fingerprints.

Without legal protection, organisations could collect personal data without consent, sell it to third parties, store it indefinitely and insecurely, or use it for purposes the individual never agreed to. The DPA 2018 / UK GDPR creates a legal framework that prevents this and gives individuals meaningful control over their own information.

What are the seven principles of the UK GDPR?

The UK GDPR establishes seven core principles that every organisation handling personal data must follow:

Principle What it requires
1. Lawfulness, fairness, and transparency Data must be processed legally, fairly, and openly — individuals must know their data is being collected
2. Purpose limitation Data collected for one purpose cannot be used for a different, incompatible purpose
3. Data minimisation Only the minimum data necessary for the stated purpose should be collected
4. Accuracy Data must be kept accurate and up to date
5. Storage limitation Data must not be kept longer than necessary for its purpose
6. Integrity and confidentiality Data must be protected from unauthorised access, loss, or damage — i.e. kept secure
7. Accountability Organisations must be able to demonstrate that they comply with all the above principles

At GCSE, you are typically expected to recall three or four of these principles and explain what they mean in a given scenario.

What rights do individuals have under the UK GDPR?

The UK GDPR gives individuals (called data subjects) a set of rights over their personal data:

  1. Right of access — the right to request a copy of all personal data an organisation holds about them (a Subject Access Request, or SAR). Organisations have one month to respond.
  2. Right to rectification — the right to have inaccurate data corrected without undue delay.
  3. Right to erasure ("right to be forgotten") — the right to have personal data deleted when it is no longer needed for the purpose it was collected, when consent is withdrawn, or in certain other circumstances.
  4. Right to data portability — the right to receive a copy of their data in a commonly used machine-readable format and transfer it to another service.
  5. Right to object — the right to object to processing of their data for direct marketing.
  6. Right to restrict processing — the right to ask an organisation to pause processing their data while accuracy is disputed.

Who enforces the Data Protection Act?

The Information Commissioner's Office (ICO) is the independent public body that enforces the DPA 2018 in the UK. Its powers include:

  • Issuing fines of up to £17.5 million or 4% of an organisation's global annual turnover (whichever is greater) for serious breaches.
  • Issuing enforcement notices requiring organisations to change their practices.
  • Carrying out audits of organisations' data-handling procedures.
  • Investigating complaints from individuals about how their data has been handled.

Individuals can report concerns to the ICO at ico.org.uk if they believe an organisation has mishandled their personal data.

How does the DPA 2018 differ from the Computer Misuse Act 1990?

These two laws are both relevant to computing but cover entirely different things:

Law What it covers Who it protects
Data Protection Act 2018 / UK GDPR How organisations collect, use, store, and share personal data Individuals whose data is held
Computer Misuse Act 1990 Unauthorised access to computer systems and data, and introducing malware Owners of computer systems

The Computer Misuse Act deals with hacking and cybercrime — actions taken without authorisation. The DPA 2018 deals with lawful but potentially abusive data handling by organisations that legitimately hold data.

Why is this relevant to everyday computing and careers?

Any organisation that processes personal data — schools, hospitals, shops, banks, social media companies — must comply with the DPA 2018. Software developers must build systems with "privacy by design", meaning data protection is built into systems from the start rather than added as an afterthought. This is increasingly a professional skill requirement, making DPA awareness valuable beyond the exam room.

Frequently asked questions

What is the difference between DPA 2018 and GDPR?

The EU's General Data Protection Regulation (GDPR) came into force in May 2018 across all EU member states. The UK's Data Protection Act 2018 enacted GDPR into UK law at the same time. After Brexit, the UK created "UK GDPR" — essentially the same rules retained in UK domestic law, with the ICO as the enforcement body rather than EU data protection authorities. For GCSE purposes, treat DPA 2018 and GDPR as the same framework.

What is a Subject Access Request?

A Subject Access Request (SAR) is a formal request made by an individual to an organisation asking for a copy of all personal data held about them. Under the UK GDPR, organisations must respond within one month and must provide the data free of charge. An SAR might reveal, for example, what purchase history an online retailer holds, or what notes a doctor has recorded. Understanding SARs is part of GCSE content on individuals' rights.

Does the Data Protection Act protect all information, including public information?

No. The DPA 2018 / UK GDPR applies specifically to personal data — information that identifies or can identify a living individual. Publicly available information about an organisation (e.g. a company's registered address) or genuinely anonymous data that cannot be traced back to an individual is not covered. However, if a combination of seemingly anonymous data points can identify a person, that combination counts as personal data.

What happens if a company breaks the Data Protection Act?

The ICO can investigate and impose fines, issue enforcement notices, or even refer cases for criminal prosecution. In 2019, the ICO issued a proposed £183 million fine against British Airways for a data breach affecting 500,000 customers (later settled at £20 million after considering the company's financial position during the pandemic). High-profile cases demonstrate that the DPA 2018 has real teeth and that organisations take data protection seriously as a result.


For Socratic GCSE Computer Science tutoring on computing law, ethics, and exam technique, visit aitutors.me.