VadeLab

Data Protection Act 2018

Sections and provisions with full text and the judgments that cite each one.

Section 82A — Designation of processing by a qualifying competent authority

Designation of processing by a qualifying competent authority 82A 1 For the purposes of this Part, the Secretary of State may give a notice designating processing of personal data by a qualifying…

Section 82B — Duration of designation notice

Duration of designation notice 82B 1 A designation notice must state when it comes into force. 2 A designation notice ceases to be in force at the earliest of the following times— a at the end of the…

Section 82C — Review and withdrawal of designation notice

Review and withdrawal of designation notice 82C 1 Subsections (2) to (4) apply where processing is the subject of a designation notice for the time being in force. 2 A person who applied for the…

Section 82D — Records of designation notices

Records of designation notices 82D 1 Where the Secretary of State gives a designation notice— a the Secretary of State must send a copy of the notice to the Commissioner, and b the Commissioner must…

Section 82E — Appeal against designation notice

Appeal against designation notice 82E 1 A person directly affected by a designation notice may appeal to the Tribunal against the notice. 2 If, on an appeal under this section, the Tribunal finds…

Section 83 — Meaning of “controller” and “processor”

Meaning of “controller” and “processor” 83 A1 For the purposes of this Part— a an intelligence service is the “ controller ” in relation to the processing of personal data if it satisfies subsection…

Section 84 — Other definitions

Other definitions 84 1 This section defines other expressions used in this Part. 2 “ Consent ”, in relation to the processing of personal data relating to an individual, means a freely given,…

Section 85 — Overview

Overview 85 1 This Chapter sets out the six data protection principles as follows— a section 86 sets out the first data protection principle (requirement that processing be lawful, fair and…

Section 86 — The first data protection principle

The first data protection principle 86 1 The first data protection principle is that the processing of personal data must be— a lawful, and b fair and transparent. 2 The processing of personal data…

Section 87 — The second data protection principle

The second data protection principle 87 1 The second data protection principle is that— a the purpose for which personal data is collected (whether from the data subject or otherwise) must be…

Section 88 — The third data protection principle

The third data protection principle 88 The third data protection principle is that personal data must be adequate, relevant and not excessive in relation to the purpose for which it is processed.

Section 89 — The fourth data protection principle

The fourth data protection principle 89 The fourth data protection principle is that personal data undergoing processing must be accurate and, where necessary, kept up to date.

Section 90 — The fifth data protection principle

The fifth data protection principle 90 The fifth data protection principle is that personal data must be kept for no longer than is necessary for the purpose for which it is processed.

Section 91 — The sixth data protection principle

The sixth data protection principle 91 1 The sixth data protection principle is that personal data must be processed in a manner that includes taking appropriate security measures as regards risks…

Section 91A — Further provision about sensitive processing

Further provision about sensitive processing 91A 1 The Secretary of State may by regulations— a make provision so that an additional description of processing of personal data is sensitive processing…

Section 92 — Overview

Overview 92 1 This Chapter sets out the rights of the data subject as follows— a section 93 deals with the information to be made available to the data subject; b sections 94 and 95 deal with the…

Section 93 — Right to information

Right to information 93 1 The controller must give a data subject the following information— a the identity and the contact details of the controller; b the legal basis on which, and the purposes for…

Section 94 — Right of access

Right of access 94 1 An individual is entitled to obtain from a controller— a confirmation as to whether or not personal data concerning the individual is being processed, and b where that is the…

Section 95 — Right of access: supplementary

Right of access: supplementary 95 1 The controller must comply with the obligation imposed by section 94(1)(b)(i) by supplying the data subject with a copy of the information in writing unless— a the…

Section 96 — Right not to be subject to automated decision-making

Right not to be subject to automated decision-making 96 1 The controller may not take a decision significantly affecting a data subject that is based on entirely automated processing of personal data…

Section 97 — Right to intervene in automated decision-making

Right to intervene in automated decision-making 97 1 This section applies where— a the controller takes a decision significantly affecting a data subject that is based on entirely automated…

Section 98 — Right to information about decision-making

Right to information about decision-making 98 1 Where— a the controller processes personal data relating to a data subject, and b results produced by the processing are applied to the data subject,…

Section 99 — Right to object to processing

Right to object to processing 99 1 A data subject is entitled at any time, by notice given to the controller, to require the controller— a not to process personal data relating to the data subject,…

Section 100 — Rights to rectification and erasure

Rights to rectification and erasure 100 1 If a court is satisfied on the application of a data subject that personal data relating to the data subject is inaccurate, the court may order the…

Section 101 — Overview

Overview 101 This Chapter sets out— a the general obligations of controllers and processors (see sections 102 to 106); b specific obligations of controllers and processors with respect to security…

Section 102 — General obligations of the controller

General obligations of the controller 102 Each controller must implement appropriate measures— a to ensure, and b to be able to demonstrate, in particular to the Commissioner, that the processing of…

Section 103 — Data protection by design

Data protection by design 103 1 Where a controller proposes that a particular type of processing of personal data be carried out by or on behalf of the controller, the controller must, prior to the…

Section 104 — Joint controllers

Joint controllers 104 1 Where two or more controllers jointly determine the purposes and means of processing personal data, they are joint controllers for the purposes of this Part. 2 Joint…

Section 105 — Processors

Processors 105 1 This section applies to the use by a controller of a processor to carry out processing of personal data on behalf of the controller. 2 The controller may use only a processor who…

Section 106 — Processing under the authority of the controller or processor

Processing under the authority of the controller or processor 106 A processor, and any person acting under the authority of a controller or processor, who has access to personal data may not process…

Section 107 — Security of processing

Security of processing 107 1 Each controller and each processor must implement security measures appropriate to the risks arising from the processing of personal data. 2 In the case of automated…

Section 108 — Communication of a personal data breach

Communication of a personal data breach 108 1 If a controller becomes aware of a serious personal data breach in relation to personal data for which the controller is responsible, the controller must…

Section 109 — Transfers of personal data outside the United Kingdom

Transfers of personal data outside the United Kingdom 109 1 A controller may not transfer personal data to— a a country or territory outside the United Kingdom, or b an international organisation,…

Section 110 — National security

National security 110 1 A provision mentioned in subsection (2) does not apply to personal data to which this Part applies if exemption from the provision is required for the purpose of safeguarding…

Section 111 — National security: certificate

National security: certificate 111 1 Subject to subsection (3), a certificate signed by a Minister of the Crown certifying that exemption from all or any of the provisions mentioned in section 110(2)…

Section 112 — Other exemptions

Other exemptions 112 Schedule 11 provides for further exemptions.

Section 113 — Power to make further exemptions

Power to make further exemptions 113 1 The Secretary of State may by regulations amend Schedule 11— a by adding exemptions from any provision of this Part; b by omitting exemptions added by…

Section 114 — The Information Commissioner

The Information Commissioner 114 1 There is to continue to be an Information Commissioner. 2 Schedule 12 makes provision about the Commissioner.

Section 114A — The Information Commission

The Information Commission 114A 1 A body corporate called the Information Commission is established. 2 Schedule 12A makes further provision about the Commission.

Section 115 — General functions under the UK GDPR and safeguards

General functions under the UK GDPR and safeguards 115 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 General functions are conferred on the Commissioner by— a Article 57 of the…

Section 116 — Other general functions

Other general functions 116 A1 The Commissioner is responsible for monitoring the application of Part 3 of this Act, in order to protect the fundamental rights and freedoms of individuals in relation…

Section 117 — Competence in relation to courts etc

Competence in relation to courts etc 117 Nothing in this Act or the UK GDPR permits or requires the Commissioner to exercise functions in relation to the processing of personal data by— a an…

Section 118 — Co-operation between parties to the Data Protection Convention

Co-operation between parties to the Data Protection Convention 118 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .…

Section 119 — Inspection of personal data in accordance with international obligations

Inspection of personal data in accordance with international obligations 119 1 The Commissioner may inspect personal data where the inspection is necessary in order to discharge an international…

Section 119A — Standard clauses for transfers to third countries etc

Standard clauses for transfers to third countries etc 119A 1 The Commissioner may issue a document specifying standard data protection clauses which the Commissioner considers are capable of securing…

Section 120 — Further international role

Further international role 120 1 The Commissioner must, in relation to third countries and international organisations, take appropriate steps to— a develop international co-operation mechanisms to…

Section 120A — Principal objective

Principal objective 120A It is the principal objective of the Commissioner, in carrying out functions under the data protection legislation— a to secure an appropriate level of protection for…

Section 120B — Duties in relation to functions under the data protection legislation

Duties in relation to functions under the data protection legislation 120B In carrying out functions under the data protection legislation, the Commissioner must have regard to such of the following…

Section 120C — Strategy

Strategy 120C 1 The Commissioner must prepare a strategy for carrying out the Commissioner’s functions under the data protection legislation in accordance with the Commissioner’s duties under— a…

Section 120D — Duty to consult other regulators

Duty to consult other regulators 120D 1 The Commissioner must, at such times as the Commissioner considers appropriate, consult the persons mentioned in subsection (2) about how the manner in which…