Data Protection and Privacy

Introduction

Data protection and privacy law in the United Kingdom governs the processing of personal data and the protection of individual privacy. The legal framework is composed of the Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR) , which together implement the EU’s General Data Protection Regulation (GDPR) framework as retained domestic law following Brexit. The framework is overseen and enforced by the Information Commissioner’s Office (ICO) . Privacy is also protected by Article 8 of the European Convention on Human Rights (ECHR) (right to respect for private and family life), which is given effect in UK law through the Human Rights Act 1998. The relationship between data protection and privacy raises fundamental questions about the protection of individual autonomy and dignity in a digital age.

Data Protection Act 2018

The Data Protection Act 2018 (DPA 2018) is the principal domestic statute governing data protection in the UK. It supplements and tailors the UK GDPR, providing derogations and exceptions for specific sectors including law enforcement, intelligence services, immigration, and journalism. The Act is divided into several parts. Part 2 (supplementing the UK GDPR) covers general data processing, including provisions on consent, the processing of special category data, and exemptions for national security, crime, and taxation. Part 3 covers law enforcement processing (implementing the Law Enforcement Directive), governing the processing of personal data by competent authorities for the prevention, investigation, detection, and prosecution of criminal offences. Part 4 covers processing by the intelligence services. Part 5 establishes the Information Commissioner as the independent regulator. The DPA 2018 also sets out the data protection principles, the rights of data subjects, and the obligations of data controllers. The Act requires that the UK GDPR and the DPA 2018 be read together, with the Act providing the domestic statutory context for the directly applicable regulation.

UK GDPR Post-Brexit

Following the UK’s withdrawal from the European Union, the European Union (Withdrawal) Act 2018 retained the EU GDPR as UK GDPR, with modifications to ensure it operates effectively in a domestic context. The UK GDPR is directly applicable in UK law and is supplemented by the DPA 2018. The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 made the necessary modifications, including replacing references to EU institutions with UK equivalents, adjusting the territorial scope to cover processing in the UK and processing by UK controllers and processors outside the UK, and creating the Information Commissioner as the independent regulator. The UK has been granted adequacy decisions by the European Commission, recognising that the UK’s data protection framework provides an adequate level of protection for personal data transferred from the EEA. These adequacy decisions are time-limited and subject to review. The UK is also seeking to negotiate data adequacy with other major trading partners. The post-Brexit data protection framework has created some divergence from the EU regime through the Data Protection and Digital Information Act 2024, which introduced reforms aimed at reducing burdens on businesses.

The Information Commissioner’s Office

The Information Commissioner’s Office (ICO) is the independent regulatory authority responsible for enforcing data protection law in the UK. The Information Commissioner is appointed by the Crown and is accountable to Parliament. The ICO has a range of enforcement powers, including the power to issue information notices (requiring the provision of information), assessment notices (requiring an assessment of compliance), enforcement notices (requiring specific steps to achieve compliance), and penalty notices (imposing fines of up to £17.5 million or 4% of annual worldwide turnover, whichever is higher, for serious breaches). The ICO also conducts investigations into data breaches, issues guidance and codes of practice, and handles complaints from data subjects. The ICO has an important role in promoting good practice and raising awareness of data protection rights. The Commissioner can also apply to the High Court for an injunction to prevent serious and imminent harm. The ICO’s decisions are subject to appeal to the First-tier Tribunal (Information Rights) .

Article 8 ECHR and the Human Rights Act 1998

Article 8 of the European Convention on Human Rights provides that everyone has the right to respect for his private and family life, his home and his correspondence. The right is a qualified right: public authorities may interfere with it only where such interference is in accordance with the law, pursues a legitimate aim, and is necessary in a democratic society. The Human Rights Act 1998 gives effect to Article 8 in UK domestic law, requiring public authorities to act compatibly with Convention rights and enabling courts to develop the common law in accordance with Convention principles. The courts have developed a substantial body of case law on Article 8, covering a wide range of matters including physical and psychological integrity, personal relationships, the protection of personal data, and the right to control the dissemination of personal information. Article 8 imposes both negative obligations (to refrain from unjustified interference) and positive obligations (to take steps to protect individuals from interference by others, including private actors).

Campbell v Mirror Group Newspapers (2004)

The case of Campbell v MGN Ltd (2004) is a landmark decision on the protection of privacy under UK law. Naomi Campbell, the supermodel, sued the Daily Mirror for publishing photographs of her leaving a Narcotics Anonymous meeting and articles about her treatment for drug addiction. The House of Lords held that the publication breached Campbell’s confidence and her Article 8 right to privacy. The case established the Campbell test for determining whether a publication violates privacy: the court must first consider whether the claimant has a reasonable expectation of privacy in the information, and, if so, must balance the right to privacy under Article 8 against the right to freedom of expression under Article 10 ECHR. Lord Hope stated that the test is whether a reasonable person of ordinary sensibilities would find the disclosure offensive. The case established that photographs can be particularly intrusive, as they convey information about appearance and context that words cannot adequately describe. Campbell v Mirror remains the leading authority on the misuse of private information tort, which protects individuals from the unauthorised disclosure of private information.

The Interrelationship of Data Protection and Privacy

Data protection and privacy rights are closely related but distinct. Data protection governs the processing of personal data and is primarily concerned with ensuring that data is processed fairly, lawfully, and transparently. Privacy is a broader concept concerned with the protection of personal autonomy, dignity, and the control of intimate personal information. The UK GDPR and the DPA 2018 provide specific procedural and substantive protections for personal data, including the right to access data, the right to rectification, the right to erasure (the “right to be forgotten”), the right to restrict processing, the right to data portability, and the right to object to processing. Article 8 ECHR provides a broader protection for privacy that extends beyond data protection to cover matters such as surveillance, searches, and the publication of personal information. The two regimes operate in parallel, with the courts interpreting them consistently where possible. The Leveson Inquiry (2012) and the Phone Hacking scandal demonstrated the vulnerability of privacy rights in the face of aggressive media practices and led to enhanced protection for individuals’ personal information.

Conclusion

Data protection and privacy are protected by a comprehensive legal framework in the United Kingdom, comprising the Data Protection Act 2018, the UK GDPR, the Human Rights Act 1998 (implementing Article 8 ECHR), and the common law tort of misuse of private information. The Information Commissioner’s Office provides independent regulatory oversight, with substantial enforcement powers including the ability to impose significant financial penalties. The case of Campbell v Mirror established the modern law of privacy in the UK, balancing the right to privacy against the right to freedom of expression. The post-Brexit framework has maintained the essential protections of the EU GDPR while introducing some domestic modifications. The constitutional significance of data protection and privacy lies in their protection of individual autonomy, dignity, and the control of personal information against the power of the state and of powerful private actors.