UK Data Protection Act 2018
UK implementation of data protection principles post-Brexit. Supplements UK GDPR and applies to all organizations processing personal data of UK residents.
What UK DPA draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Logging Requirements
Controllers MUST keep logs of collection, alteration, consultation, disclosure, combination, or erasure of personal data.
Discovery locates every column holding a subject's data across every connected store, and the access history for that subject is reportable in minutes rather than reconstructed from tickets. The deletion or correction itself is executed by your application or your DBA — what the platform produces is the evidence of where the data was, who touched it, and that the change happened.
Data Protection by Design
Controllers MUST implement appropriate technical measures including access logging from the outset.
Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.
Breach Notification
Personal data breaches MUST be reported to the ICO within 72 hours of becoming aware.
Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.
Subject Access Rights
Organizations MUST provide individuals with access to their personal data and processing information.
Discovery locates every column holding a subject's data across every connected store, and the access history for that subject is reportable in minutes rather than reconstructed from tickets. The deletion or correction itself is executed by your application or your DBA — what the platform produces is the evidence of where the data was, who touched it, and that the change happened.
What UK DPA covers
Special category data at s. 10 and Sch. 1; criminal offence data at s. 11
Personal data as under UK GDPR, with a second heightened class the EU instrument does not have.
In scope
- Personal data as defined by UK GDPR Art. 4(1)
Special category data (s. 10) AND criminal offence data (s. 11)
The instrument's own term, kept as it writes it — these labels differ between frameworks on purpose.
- The Art. 9 special categories
- Personal data relating to criminal convictions and offences
- Personal data relating to alleged offences and related proceedings
What falls outside
Anonymous data, on the same test as the EU instrument.
Criminal offence data is the distinctive part. It is not an Art. 9 special category, it carries its own conditions in Sch. 1, and a programme ported straight from the EU will not have a lawful basis for it.
Data Protection Act 2018, s. 11 · as at 2026-08
How UK DPA is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The Information Commissioner, who also prosecutes the criminal offences.
| Published maximum | Charged | As at |
|---|---|---|
| GBP 17.5 million | the fixed limb of the higher maximum | 2026-08 |
| 4% of total annual worldwide turnover | the percentage limb; the higher applies | 2026-08 |
| GBP 8.7 million | or 2%, the standard maximum | 2026-08 |
The standard maximum for the UK GDPR is GBP 8.7 million or 2%; the higher maximum applies to the more serious infringements. The Act adds criminal offences that the Commissioner prosecutes in her own name, and those reach individuals who act outside their employer instructions.
Individual prosecutions under s.170 and s.173 have resulted in convictions of employees and of company directors, but never in a prison sentence, because the sentence is not available.
Who is personally on the hook
- Who can be charged
- Any person who knowingly or recklessly obtains or discloses personal data without the consent of the controller — and, separately, a controller or their staff who alter records to defeat a subject access request
- For what
- knowingly or recklessly obtaining or disclosing personal data without the consent of the controller, or altering records to defeat a subject access request
- Maximum
- An unlimited fine on conviction. There is no custodial sentence for either offence
- Brought by
- The Information Commissioner, who prosecutes in her own name
Uncapped exposure that sits outside this instrument
These come from company law rather than from UK DPA, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for UK DPA,
not configured for it afterwards
UK Citizen Data Monitoring
Track access to UK resident personal data to prevent insider snooping
UK DPA Compliance Report
2-year retention compliant access log documentation
UK PII Patterns
Detect NI numbers, NHS numbers, and UK-specific identifiers
Insider Threat Detection
Alert on unusual internal access to citizen service data
Other Government frameworks
Walk into the UK DPA audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.