Data Protection Act 2018
Sections and provisions with full text and the judgments that cite each one.
Section 82A — Designation of processing by a qualifying competent authority
Designation of processing by a qualifying competent authority 82A 1 For the purposes of this Part, the Secretary of State may give a notice designating processing of personal data by a qualifying…
Section 82B — Duration of designation notice
Duration of designation notice 82B 1 A designation notice must state when it comes into force. 2 A designation notice ceases to be in force at the earliest of the following times— a at the end of the…
Section 82C — Review and withdrawal of designation notice
Review and withdrawal of designation notice 82C 1 Subsections (2) to (4) apply where processing is the subject of a designation notice for the time being in force. 2 A person who applied for the…
Section 82D — Records of designation notices
Records of designation notices 82D 1 Where the Secretary of State gives a designation notice— a the Secretary of State must send a copy of the notice to the Commissioner, and b the Commissioner must…
Section 82E — Appeal against designation notice
Appeal against designation notice 82E 1 A person directly affected by a designation notice may appeal to the Tribunal against the notice. 2 If, on an appeal under this section, the Tribunal finds…
Section 83 — Meaning of “controller” and “processor”
Meaning of “controller” and “processor” 83 A1 For the purposes of this Part— a an intelligence service is the “ controller ” in relation to the processing of personal data if it satisfies subsection…
Section 84 — Other definitions
Other definitions 84 1 This section defines other expressions used in this Part. 2 “ Consent ”, in relation to the processing of personal data relating to an individual, means a freely given,…
Section 85 — Overview
Overview 85 1 This Chapter sets out the six data protection principles as follows— a section 86 sets out the first data protection principle (requirement that processing be lawful, fair and…
Section 86 — The first data protection principle
The first data protection principle 86 1 The first data protection principle is that the processing of personal data must be— a lawful, and b fair and transparent. 2 The processing of personal data…
Section 87 — The second data protection principle
The second data protection principle 87 1 The second data protection principle is that— a the purpose for which personal data is collected (whether from the data subject or otherwise) must be…
Section 88 — The third data protection principle
The third data protection principle 88 The third data protection principle is that personal data must be adequate, relevant and not excessive in relation to the purpose for which it is processed.
Section 89 — The fourth data protection principle
The fourth data protection principle 89 The fourth data protection principle is that personal data undergoing processing must be accurate and, where necessary, kept up to date.
Section 90 — The fifth data protection principle
The fifth data protection principle 90 The fifth data protection principle is that personal data must be kept for no longer than is necessary for the purpose for which it is processed.
Section 91 — The sixth data protection principle
The sixth data protection principle 91 1 The sixth data protection principle is that personal data must be processed in a manner that includes taking appropriate security measures as regards risks…
Section 91A — Further provision about sensitive processing
Further provision about sensitive processing 91A 1 The Secretary of State may by regulations— a make provision so that an additional description of processing of personal data is sensitive processing…
Section 92 — Overview
Overview 92 1 This Chapter sets out the rights of the data subject as follows— a section 93 deals with the information to be made available to the data subject; b sections 94 and 95 deal with the…
Section 93 — Right to information
Right to information 93 1 The controller must give a data subject the following information— a the identity and the contact details of the controller; b the legal basis on which, and the purposes for…
Section 94 — Right of access
Right of access 94 1 An individual is entitled to obtain from a controller— a confirmation as to whether or not personal data concerning the individual is being processed, and b where that is the…
Section 95 — Right of access: supplementary
Right of access: supplementary 95 1 The controller must comply with the obligation imposed by section 94(1)(b)(i) by supplying the data subject with a copy of the information in writing unless— a the…
Section 96 — Right not to be subject to automated decision-making
Right not to be subject to automated decision-making 96 1 The controller may not take a decision significantly affecting a data subject that is based on entirely automated processing of personal data…
Section 97 — Right to intervene in automated decision-making
Right to intervene in automated decision-making 97 1 This section applies where— a the controller takes a decision significantly affecting a data subject that is based on entirely automated…
Section 98 — Right to information about decision-making
Right to information about decision-making 98 1 Where— a the controller processes personal data relating to a data subject, and b results produced by the processing are applied to the data subject,…
Section 99 — Right to object to processing
Right to object to processing 99 1 A data subject is entitled at any time, by notice given to the controller, to require the controller— a not to process personal data relating to the data subject,…
Section 100 — Rights to rectification and erasure
Rights to rectification and erasure 100 1 If a court is satisfied on the application of a data subject that personal data relating to the data subject is inaccurate, the court may order the…
Section 101 — Overview
Overview 101 This Chapter sets out— a the general obligations of controllers and processors (see sections 102 to 106); b specific obligations of controllers and processors with respect to security…
Section 102 — General obligations of the controller
General obligations of the controller 102 Each controller must implement appropriate measures— a to ensure, and b to be able to demonstrate, in particular to the Commissioner, that the processing of…
Section 103 — Data protection by design
Data protection by design 103 1 Where a controller proposes that a particular type of processing of personal data be carried out by or on behalf of the controller, the controller must, prior to the…
Section 104 — Joint controllers
Joint controllers 104 1 Where two or more controllers jointly determine the purposes and means of processing personal data, they are joint controllers for the purposes of this Part. 2 Joint…
Section 105 — Processors
Processors 105 1 This section applies to the use by a controller of a processor to carry out processing of personal data on behalf of the controller. 2 The controller may use only a processor who…
Section 106 — Processing under the authority of the controller or processor
Processing under the authority of the controller or processor 106 A processor, and any person acting under the authority of a controller or processor, who has access to personal data may not process…
Section 107 — Security of processing
Security of processing 107 1 Each controller and each processor must implement security measures appropriate to the risks arising from the processing of personal data. 2 In the case of automated…
Section 108 — Communication of a personal data breach
Communication of a personal data breach 108 1 If a controller becomes aware of a serious personal data breach in relation to personal data for which the controller is responsible, the controller must…
Section 109 — Transfers of personal data outside the United Kingdom
Transfers of personal data outside the United Kingdom 109 1 A controller may not transfer personal data to— a a country or territory outside the United Kingdom, or b an international organisation,…
Section 110 — National security
National security 110 1 A provision mentioned in subsection (2) does not apply to personal data to which this Part applies if exemption from the provision is required for the purpose of safeguarding…
Section 111 — National security: certificate
National security: certificate 111 1 Subject to subsection (3), a certificate signed by a Minister of the Crown certifying that exemption from all or any of the provisions mentioned in section 110(2)…
Section 112 — Other exemptions
Other exemptions 112 Schedule 11 provides for further exemptions.
Section 113 — Power to make further exemptions
Power to make further exemptions 113 1 The Secretary of State may by regulations amend Schedule 11— a by adding exemptions from any provision of this Part; b by omitting exemptions added by…
Section 114 — The Information Commissioner
The Information Commissioner 114 1 There is to continue to be an Information Commissioner. 2 Schedule 12 makes provision about the Commissioner.
Section 114A — The Information Commission
The Information Commission 114A 1 A body corporate called the Information Commission is established. 2 Schedule 12A makes further provision about the Commission.
Section 115 — General functions under the UK GDPR and safeguards
General functions under the UK GDPR and safeguards 115 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 General functions are conferred on the Commissioner by— a Article 57 of the…
Section 116 — Other general functions
Other general functions 116 A1 The Commissioner is responsible for monitoring the application of Part 3 of this Act, in order to protect the fundamental rights and freedoms of individuals in relation…
Section 117 — Competence in relation to courts etc
Competence in relation to courts etc 117 Nothing in this Act or the UK GDPR permits or requires the Commissioner to exercise functions in relation to the processing of personal data by— a an…
Section 118 — Co-operation between parties to the Data Protection Convention
Co-operation between parties to the Data Protection Convention 118 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .…
Section 119 — Inspection of personal data in accordance with international obligations
Inspection of personal data in accordance with international obligations 119 1 The Commissioner may inspect personal data where the inspection is necessary in order to discharge an international…
Section 119A — Standard clauses for transfers to third countries etc
Standard clauses for transfers to third countries etc 119A 1 The Commissioner may issue a document specifying standard data protection clauses which the Commissioner considers are capable of securing…
Section 120 — Further international role
Further international role 120 1 The Commissioner must, in relation to third countries and international organisations, take appropriate steps to— a develop international co-operation mechanisms to…
Section 120A — Principal objective
Principal objective 120A It is the principal objective of the Commissioner, in carrying out functions under the data protection legislation— a to secure an appropriate level of protection for…
Section 120B — Duties in relation to functions under the data protection legislation
Duties in relation to functions under the data protection legislation 120B In carrying out functions under the data protection legislation, the Commissioner must have regard to such of the following…
Section 120C — Strategy
Strategy 120C 1 The Commissioner must prepare a strategy for carrying out the Commissioner’s functions under the data protection legislation in accordance with the Commissioner’s duties under— a…
Section 120D — Duty to consult other regulators
Duty to consult other regulators 120D 1 The Commissioner must, at such times as the Commissioner considers appropriate, consult the persons mentioned in subsection (2) about how the manner in which…
