VadeLab

Data Protection Act 2018

Sections and provisions with full text and the judgments that cite each one.

Section 45 — Right of access by the data subject

Right of access by the data subject 45 1 A data subject is entitled to obtain from the controller— a confirmation as to whether or not personal data concerning him or her is being processed, and b…

Section 45A — Exemption from sections 44 and 45: legal professional privilege

Exemption from sections 44 and 45: legal professional privilege 45A 1 Sections 44(2) and 45(1) do not require the controller to give the data subject— a information in respect of which a claim to…

Section 46 — Right to rectification

Right to rectification 46 1 The controller must, if so requested by a data subject, rectify without undue delay inaccurate personal data relating to the data subject. 2 Where personal data is…

Section 47 — Right to erasure or restriction of processing

Right to erasure or restriction of processing 47 1 The controller must erase personal data without undue delay where— a the processing of the personal data would infringe section 35, 36(1) to (3),…

Section 48 — Rights under section 46 or 47: supplementary

Rights under section 46 or 47: supplementary 48 1 Where a data subject requests the rectification or erasure of personal data or the restriction of its processing, the controller must inform the data…

Section 49 — Right not to be subject to automated decision-making

Right not to be subject to automated decision-making 49 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Section 50 — Automated decision-making authorised by law: safeguards

Automated decision-making authorised by law: safeguards 50 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Section 50A — Automated processing and significant decisions

Automated processing and significant decisions 50A 1 For the purposes of sections 50B and 50C— a a decision is based solely on automated processing if there is no meaningful human involvement in the…

Section 50B — Restrictions on automated decision-making based on sensitive processing

Restrictions on automated decision-making based on sensitive processing 50B 1 A significant decision based entirely or partly on sensitive processing may not be taken based solely on automated…

Section 50C — Safeguards for automated decision-making

Safeguards for automated decision-making 50C 1 Subject to subsection (3), where a significant decision taken by or on behalf of a controller in relation to a data subject is— a based entirely or…

Section 50D — Further provision about automated decision-making

Further provision about automated decision-making 50D 1 The Secretary of State may by regulations provide that, for the purposes of sections 50A(1)(a) and 50C(3)(c), there is, or is not, to be taken…

Section 51 — Exercise of rights through the Commissioner

Exercise of rights through the Commissioner 51 1 This section applies where a controller— a restricts under section 44(4) the information provided to the data subject under section 44(2) (duty of the…

Section 52 — Form of provision of information etc

Form of provision of information etc 52 1 The controller must take reasonable steps to ensure that any information that is required by or under this Chapter to be provided to the data subject is…

Section 53 — Manifestly unfounded or excessive requests by the data subject

Manifestly unfounded or excessive requests by the data subject 53 1 Where a request made by a data subject under or by virtue of any of sections 45, 46, 47, 50C or 50D is manifestly unfounded or…

Section 54 — Meaning of “applicable time period”

Meaning of “applicable time period” 54 1 This section defines “ the applicable time period ” for the purposes of sections 45(3)(b) and (5) , 48(2)(b) and 53(7) . 2 “ The applicable time period ”…

Section 55 — Overview and scope

Overview and scope 55 1 This Chapter— a sets out the general obligations of controllers and processors (see sections 56 to 65); b sets out specific obligations of controllers and processors with…

Section 56 — General obligations of the controller

General obligations of the controller 56 1 Each controller must implement appropriate technical and organisational measures to ensure, and to be able to demonstrate, that the processing of personal…

Section 57 — Data protection by design and default

Data protection by design and default 57 1 Each controller must implement appropriate technical and organisational measures which are designed— a to implement the data protection principles in an…

Section 58 — Joint controllers

Joint controllers 58 1 Where two or more competent authorities jointly determine the purposes and means of processing personal data, they are joint controllers for the purposes of this Part. 2 Joint…

Section 59 — Processors

Processors 59 1 This section applies to the use by a controller of a processor to carry out processing of personal data on behalf of the controller. 2 The controller may use only a processor who…

Section 60 — Processing under the authority of the controller or processor

Processing under the authority of the controller or processor 60 A processor, and any person acting under the authority of a controller or processor, who has access to personal data may not process…

Section 61 — Records of processing activities

Records of processing activities 61 1 Each controller must maintain a record of all categories of processing activities for which the controller is responsible. 2 The controller's record must contain…

Section 62 — Logging

Logging 62 1 A controller (or, where personal data is processed on behalf of the controller by a processor, the processor) must keep logs for at least the following processing operations in automated…

Section 63 — Co-operation with the Commissioner

Co-operation with the Commissioner 63 Each controller and each processor must co-operate, on request, with the Commissioner in the performance of the Commissioner's tasks.

Section 64 — Data protection impact assessment

Data protection impact assessment 64 1 Where a type of processing is likely to result in a high risk to the rights and freedoms of individuals, the controller must, prior to the processing, carry out…

Section 65 — Prior consultation with the Commissioner

Prior consultation with the Commissioner 65 1 This section applies where a controller intends to create a filing system and process personal data forming part of it. 2 The controller must consult the…

Section 66 — Security of processing

Security of processing 66 1 Each controller and each processor must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risks arising from the…

Section 67 — Notification of a personal data breach to the Commissioner

Notification of a personal data breach to the Commissioner 67 1 If a controller becomes aware of a personal data breach in relation to personal data for which the controller is responsible, the…

Section 68 — Communication of a personal data breach to the data subject

Communication of a personal data breach to the data subject 68 1 Where a personal data breach is likely to result in a high risk to the rights and freedoms of individuals, the controller must inform…

Section 69 — Designation of a data protection officer

Designation of a data protection officer 69 1 The controller must designate a data protection officer, unless the controller is a court, or other judicial authority, acting in its judicial capacity.…

Section 70 — Position of data protection officer

Position of data protection officer 70 1 The controller must ensure that the data protection officer is involved, properly and in a timely manner, in all issues which relate to the protection of…

Section 71 — Tasks of data protection officer

Tasks of data protection officer 71 1 The controller must entrust the data protection officer with at least the following tasks— a informing and advising the controller, any processor engaged by the…

Section 71A — Codes of conduct

Codes of conduct 71A 1 The Commissioner must encourage expert public bodies to produce codes of conduct intended to contribute to compliance with this Part. 2 Under subsection (1), the Commissioner…

Section 72 — Overview and interpretation

Overview and interpretation 72 1 This Chapter deals with the transfer of personal data to third countries or international organisations, as follows— a sections 73 to 76 set out the general…

Section 73 — General principles for transfers of personal data

General principles for transfers of personal data 73 A1 This section applies in relation to a transfer of personal data to a third country or international organisation for a law enforcement purpose.…

Section 74 — Transfers on the basis of an adequacy decision

Transfers on the basis of an adequacy decision 74 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Section 74A — Transfers based on adequacy regulations

Transfers based on adequacy regulations 74A . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Section 74AA — Transfers approved by regulations

Transfers approved by regulations 74AA 1 For the purposes of section 73, the Secretary of State may by regulations approve transfers of personal data to— a a third country, or b an international…

Section 74AB — The data protection test

The data protection test 74AB 1 For the purposes of section 74AA, the data protection test is met in relation to transfers to a third country or international organisation if the standard of the…

Section 74B — Transfers approved by regulations: monitoring

Transfers approved by regulations: monitoring 74B 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 The Secretary…

Section 75 — Transfers subject to appropriate safeguards

Transfers subject to appropriate safeguards 75 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1A A transfer of personal data to a third country or an international organisation is…

Section 76 — Transfers based on special circumstances

Transfers based on special circumstances 76 A1 A transfer of personal data to a third country or international organisation is based on special circumstances where— a it is made in the absence of…

Section 76B — Disclosure of information to Tribunal

Disclosure of information to Tribunal 76B 1 No enactment or rule of law prohibiting or restricting the disclosure of information precludes a person from providing the First-tier Tribunal or the Upper…

Section 77 — Additional conditions for transfers in reliance on section 73(4)(b)

Additional conditions for transfers in reliance on section 73(4)(b) 77 1 The additional conditions referred to in section 73(4)(b)(ii) are the following four conditions. 2 Condition 1 is that the…

Section 78 — Subsequent transfers

Subsequent transfers 78 A1 Subsections (1) to (6) apply where a transfer to which section 73 applies takes place otherwise than in reliance on section 73(4)(aa) (transfer to processor). 1 ... The…

Section 78A — National security exemption

National security exemption 78A 1 A provision mentioned in subsection (2) does not apply to personal data processed for law enforcement purposes if exemption from the provision is required for the…

Section 79 — National security: certificate

National security: certificate 79 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 . . . . . . . . . . . . . . . .…

Section 80 — Special processing restrictions

Special processing restrictions 80 1 Subsections (3) and (4) apply where, for a law enforcement purpose, a controller transmits or otherwise makes available personal data to a non-UK recipient . 2 In…

Section 81 — Reporting of infringements

Reporting of infringements 81 1 Each controller must implement effective mechanisms to encourage the reporting of an infringement of this Part. 2 The mechanisms implemented under subsection (1) must…

Section 82 — Processing to which this Part applies

Processing to which this Part applies 82 A1 This Part— a applies to processing of personal data by an intelligence service, and b applies to processing of personal data by a qualifying competent…