UK DPAGovernmentUnited KingdomAll Industries

UK Data Protection Act 2018

UK implementation of data protection principles post-Brexit. Supplements UK GDPR and applies to all organizations processing personal data of UK residents.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

UK DPASection 57Answering for an individual

Logging Requirements

Controllers MUST keep logs of collection, alteration, consultation, disclosure, combination, or erasure of personal data.

Discovery locates every column holding a subject's data across every connected store, and the access history for that subject is reportable in minutes rather than reconstructed from tickets. The deletion or correction itself is executed by your application or your DBA — what the platform produces is the evidence of where the data was, who touched it, and that the change happened.

UK DPASection 59Patching, hardening, and exposureA record of access

Data Protection by Design

Controllers MUST implement appropriate technical measures including access logging from the outset.

Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.

UK DPASection 66Detecting it in time to notify

Breach Notification

Personal data breaches MUST be reported to the ICO within 72 hours of becoming aware.

Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.

UK DPASection 107Answering for an individual

Subject Access Rights

Organizations MUST provide individuals with access to their personal data and processing information.

Discovery locates every column holding a subject's data across every connected store, and the access history for that subject is reportable in minutes rather than reconstructed from tickets. The deletion or correction itself is executed by your application or your DBA — what the platform produces is the evidence of where the data was, who touched it, and that the change happened.

What UK DPA covers

Special category data at s. 10 and Sch. 1; criminal offence data at s. 11

Personal data as under UK GDPR, with a second heightened class the EU instrument does not have.

In scope

  • Personal data as defined by UK GDPR Art. 4(1)

Special category data (s. 10) AND criminal offence data (s. 11)

The instrument's own term, kept as it writes it — these labels differ between frameworks on purpose.

  • The Art. 9 special categories
  • Personal data relating to criminal convictions and offences
  • Personal data relating to alleged offences and related proceedings

What falls outside

Anonymous data, on the same test as the EU instrument.

Criminal offence data is the distinctive part. It is not an Art. 9 special category, it carries its own conditions in Sch. 1, and a programme ported straight from the EU will not have a lawful basis for it.

Data Protection Act 2018, s. 11 · as at 2026-08

How UK DPA is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The Information Commissioner, who also prosecutes the criminal offences.

Published maximumChargedAs at
GBP 17.5 millionthe fixed limb of the higher maximum2026-08
4% of total annual worldwide turnoverthe percentage limb; the higher applies2026-08
GBP 8.7 millionor 2%, the standard maximum2026-08

The standard maximum for the UK GDPR is GBP 8.7 million or 2%; the higher maximum applies to the more serious infringements. The Act adds criminal offences that the Commissioner prosecutes in her own name, and those reach individuals who act outside their employer instructions.

Individual prosecutions under s.170 and s.173 have resulted in convictions of employees and of company directors, but never in a prison sentence, because the sentence is not available.

Who is personally on the hook

Who can be charged
Any person who knowingly or recklessly obtains or discloses personal data without the consent of the controller — and, separately, a controller or their staff who alter records to defeat a subject access request
For what
knowingly or recklessly obtaining or disclosing personal data without the consent of the controller, or altering records to defeat a subject access request
Maximum
An unlimited fine on conviction. There is no custodial sentence for either offence
Brought by
The Information Commissioner, who prosecutes in her own name
Personal fineNot indemnifiable

Uncapped exposure that sits outside this instrument

These come from company law rather than from UK DPA, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for UK DPA,
not configured for it afterwards

Policy Template

UK Citizen Data Monitoring

Track access to UK resident personal data to prevent insider snooping

Report

UK DPA Compliance Report

2-year retention compliant access log documentation

Classification

UK PII Patterns

Detect NI numbers, NHS numbers, and UK-specific identifiers

Alert

Insider Threat Detection

Alert on unusual internal access to citizen service data

Walk into the UK DPA audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment