UK Data Protection Law
Introduction
Data protection law in the United Kingdom is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018). Following the UK’s withdrawal from the European Union, the EU GDPR was incorporated into UK law as the UK GDPR, with amendments to reflect the UK’s status as a third country. The DPA 2018 supplements the UK GDPR, providing derogations, exemptions, and additional provisions for law enforcement processing and national security. The Information Commissioner’s Office (ICO) is the independent supervisory authority responsible for enforcing data protection law.
The UK GDPR
The UK GDPR sets out the core principles, rights, and obligations of data protection law. The six data protection principles (Article 5 UK GDPR) require that personal data be: processed lawfully, fairly, and in a transparent manner; collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes; adequate, relevant, and limited to what is necessary; accurate and kept up to date; kept in a form that permits identification of data subjects for no longer than necessary; and processed in a manner that ensures appropriate security.
Lawful basis for processing (Article 6 UK GDPR) requires that processing be justified by one of six lawful bases: consent; performance of a contract; compliance with a legal obligation; protection of vital interests; performance of a task in the public interest; or the legitimate interests of the controller or a third party. For the processing of special category data (including racial or ethnic origin, political opinions, religious beliefs, health data, and biometric data), additional conditions under Article 9 apply.
Rights of Data Subjects
The UK GDPR confers a range of rights on data subjects — individuals whose personal data is processed. The right to be informed requires controllers to provide privacy information at the point of data collection. The right of access (Article 15) enables data subjects to obtain confirmation of whether their data is being processed and to access that data. The right to rectification (Article 16) allows data subjects to have inaccurate data corrected.
The right to erasure (Article 17) — also known as the right to be forgotten — entitles data subjects to have their data erased in certain circumstances, including where the data is no longer necessary for the purpose for which it was collected, where consent is withdrawn, or where the data has been unlawfully processed. The right is not absolute and must be balanced against other rights and interests.
The right to data portability (Article 20) enables data subjects to obtain their data in a structured, commonly used, and machine-readable format and to transmit that data to another controller. The right applies where the processing is based on consent or contract and is carried out by automated means.
Controller and Processor Obligations
The UK GDPR imposes obligations on both controllers (who determine the purposes and means of processing) and processors (who process data on behalf of controllers). Controllers must implement appropriate technical and organisational measures to ensure compliance with the Regulation, including data protection by design and default (Article 25).
Controllers must conduct a data protection impact assessment (DPIA) where processing is likely to result in high risk to individuals’ rights and freedoms (Article 35). A DPIA is required for systematic and extensive profiling, large-scale processing of special category data, and systematic monitoring of publicly accessible areas. The ICO publishes guidance on when a DPIA is required and maintains a list of processing operations that require a DPIA.
Controllers must also maintain records of processing activities, cooperate with the ICO, and notify personal data breaches to the ICO within 72 hours of becoming aware of the breach (Article 33). Where the breach is likely to result in high risk to individuals’ rights and freedoms, the controller must also communicate the breach to the affected data subjects (Article 34).
Enforcement by the ICO
The Information Commissioner’s Office is the UK’s independent supervisory authority for data protection. The ICO has extensive enforcement powers under the UK GDPR and the DPA 2018, including the power to: issue information notices requiring controllers to provide information; issue assessment notices requiring controllers to permit ICO officers to inspect their processing operations; issue enforcement notices requiring controllers to take specified steps to comply with the law; and impose administrative fines of up to £17.5 million or 4 per cent of annual worldwide turnover, whichever is higher.
The ICO also operates a prior consultation procedure, under which controllers must consult the ICO before processing where a DPIA indicates that the processing would result in high risk in the absence of measures to mitigate that risk. The ICO provides guidance, codes of practice, and advice to support compliance.
Exemptions and Derogations
The DPA 2018 provides a range of exemptions and derogations from the UK GDPR, including exemptions for: crime and taxation (where the application of data protection provisions would prejudice the prevention or detection of crime); immigration control; legal proceedings; journalism, academic, artistic, and literary purposes; and research and statistics. The exemptions are narrowly drawn and must be applied in accordance with the principle of proportionality.
International Transfers
The UK GDPR restricts transfers of personal data to countries outside the UK unless the country ensures an adequate level of protection, the controller provides appropriate safeguards, or a specific derogation applies. The UK has received adequacy decisions from the European Commission, enabling the continued free flow of personal data from the EU to the UK, subject to review every four years.
Conclusion
UK data protection law, comprising the UK GDPR and the Data Protection Act 2018, provides a comprehensive framework for the protection of personal data. The principles, rights, and obligations under the regime are designed to ensure that individuals’ data is processed lawfully, fairly, and transparently, while the ICO’s enforcement powers ensure accountability and compliance.