Skip to content
The Algorithm
The Algorithm/Knowledge Base/DPA 2018
Data Protection Law

DPA 2018

The UK Data Protection Act 2018 is the domestic legislation that implemented GDPR into UK law before Brexit — and continues to govern data protection in the UK alongside UK GDPR.

What You Need to Know

The Data Protection Act 2018 (DPA 2018) is the UK's primary data protection legislation. It implemented EU GDPR into UK law before Brexit, supplemented it with UK-specific provisions, and addressed processing activities not covered by GDPR — including law enforcement processing (Part 3) and intelligence services processing (Part 4). Since Brexit, the DPA 2018 continues in force alongside UK GDPR, which is the retained EU GDPR incorporated into UK law by the European Union (Withdrawal) Act 2018.

For most commercial organizations, practical compliance requirements flow primarily from UK GDPR — with the DPA 2018 providing supplementary provisions including: the list of conditions for processing special category data under Schedule 1, the research and statistics exemptions in Part 6, and the provisions governing ICO powers and enforcement. The DPA 2018 and UK GDPR must be read together — neither operates independently for commercial data processing.

The DPA 2018 includes provisions that diverge from EU GDPR in ways that matter for engineering teams. Schedule 1 created a broader set of conditions for processing special category data — including employment and social security purposes, preventive or occupational medicine, and substantial public interest conditions. Organizations processing special category data in the UK must verify which Schedule 1 condition applies, maintain documentation of that condition, and in some cases have an Appropriate Policy Document (APD) in place — a requirement with no direct EU GDPR equivalent.

How We Handle It

We design UK data protection compliance for the DPA 2018 and UK GDPR together — implementing the appropriate Schedule 1 conditions for special category processing, building Appropriate Policy Documents into the governance framework where required, and designing systems that satisfy ICO enforcement expectations across all UK data processing activities.

Services
Service
Compliance Infrastructure
Service
Regulatory Intelligence
Service
Data Engineering & Analytics
Related Frameworks
UK GDPRGDPRCCPAISO 27001
DECISION GUIDE

Compliance-Native Architecture Guide

Design principles and a structured checklist for building software that is compliant by default — not compliant by retrofit. Covers data architecture, access controls, audit trails, and vendor due diligence.

§

Compliance built at the architecture level.

Deploy a team that knows your regulatory landscape before they write their first line of code.

Start the conversation
Related
Service
Compliance Infrastructure
Service
Regulatory Intelligence
Service
Data Engineering & Analytics
Related Framework
UK GDPR
Related Framework
GDPR
Related Framework
CCPA
Platform
ALICE Compliance Engine
Service
Compliance Infrastructure
Engagement
Surgical Strike (Tier I)
Why Switch
vs. Accenture
Get Started
Start a Conversation
Engage Us