The Data Protection Act 2018 is the UK statute that works alongside UK GDPR, filling in the details that the GDPR left to each country: exemptions, extra conditions for sensitive data, the powers of the Information Commissioner and the criminal offences. Shortened to DPA 2018, it is not the same thing as a data processing agreement or Meta’s Dynamic Product Ads.
How the Data Protection Act 2018 works
Its main provisions came into force on 25 May 2018, the day the EU GDPR began to apply. Since the end of the Brexit transition period on 31 December 2020, the UK has had its own version of the GDPR, known as UK GDPR, and the two are read together. UK GDPR sets the principles, lawful bases and rights; the DPA 2018 adds the UK-specific parts. The sections a marketer is most likely to meet are these.
Conditions for sensitive data
Schedule 1 sets out the extra conditions for processing special category data, such as health information, and criminal offence data. Many of these conditions also require an “appropriate policy document” explaining how the data is protected. A private clinic handling patient enquiries meets this part of the Act early.
Exemptions
Schedules 2 to 4 list situations where some UK GDPR rules do not apply, for example to information covered by legal professional privilege, confidential references or management forecasts. They are narrow, they apply case by case, and none of them is a general exemption for marketing.
The regulator and enforcement
The Act sets out the powers of the Information Commissioner’s Office: information notices, assessment notices, enforcement notices and fines of up to £17.5 million or 4% of global annual turnover, whichever is higher, for the most serious breaches. The data protection fee is set by regulations made under the Act.
Criminal offences
It is an offence to knowingly or recklessly obtain or disclose personal data without the controller’s consent, to re-identify data that has been de-identified without permission, and to alter or delete records to stop someone receiving them after a subject access request.
The Data (Use and Access) Act 2025 amends both the DPA 2018 and UK GDPR, with changes commencing in stages. At the time of writing (October 2026), check the ICO’s guidance for which provisions are in force before relying on any of them.
Why it matters for a UK business
Most day-to-day marketing questions are answered by UK GDPR and PECR, so the DPA 2018 can feel like background. It matters in three common situations. When a salesperson leaves and takes a customer list to a competitor, that can be a criminal offence under the Act, not just a breach of contract. When you buy or rent a data list of unclear origin, you risk receiving data that was obtained unlawfully. And when you handle health, ethnicity or similar data, the Schedule 1 conditions apply on top of the UK GDPR rules.
Common mistakes
- Treating the DPA 2018 and UK GDPR as alternatives instead of two parts of one framework.
- Reading an exemption as a blanket permission when it only covers a narrow situation.
- Processing health or other sensitive data without an appropriate policy document where one is required.
- Assuming changes from the 2025 Act are already in force without checking.
- Writing “DPA” in contracts and policies without spelling out which DPA is meant.
How to act on it
Name both laws correctly in your privacy notice and internal policies. If you handle special category data, check whether your Schedule 1 condition needs a policy document and write it. Make sure leavers lose access to the CRM and ad accounts on their last day, and that staff know taking customer data is a criminal matter. When you plan your digital marketing with me, I flag where a campaign or data source raises questions like these, though for legal advice you should speak to a solicitor.
