UK Controllers: 5 GDPR+DPA 2018 Steps to Avoid £17.5m Fines

Sep 13, 2026 | 0 comments

They are not rivals: the UK GDPR supplies the core data protection rules, and the Data Protection Act 2018 supplements those rules with UK-specific detail. Together they form a single UK data protection regime, enforced by the Information Commissioner’s Office and set out in full on legislation.gov.uk.


TL;DR:

  • Exemptions in the DPA 2018 are narrow and must be justified on a case-by-case basis with detailed documentation; broad policies relying on exemptions are not acceptable.
  • Handling special-category data requires both a lawful basis under the UK GDPR and a matching exemption condition from Schedule 1; missing either invalidates compliance.
  • Most organizations will primarily follow the UK GDPR, only consulting the DPA 2018 for specific exemptions related to special-category data or statutory exceptions.
  • Enforcement fines can reach up to £17.5 million or 4% of global turnover, but the ICO emphasizes records and documentation as critical proof to avoid escalation.
  • Secure disposal of documents through certified shredding services creates a reliable audit trail, reducing physical and legal risk when managing data retention.

Secure-shred
Close Your Secure Disposal Gap
Secure Shred helps Cardiff homes and small businesses dispose of sensitive documents through traceable, compliance-focused shredding services.

Explore secure shredding

Table of Contents

GDPR vs DPA 2018: what each one actually is

The UK GDPR is the retained version of the EU GDPR, written into domestic law after Brexit. It sets out the core principles you already know: lawful bases for processing, data subject rights, accountability obligations, and the rules for keeping personal data secure.

The Data Protection Act 2018 is separate legislation that supplements the UK GDPR rather than duplicating it. It fills in the gaps the UK GDPR leaves open, adding Schedules covering special-category data conditions and statutory exemptions, plus entirely separate Parts dealing with law enforcement and intelligence services processing. GOV.UK’s overview confirms this division directly: follow the UK GDPR for your core obligations, then consult the DPA 2018 for UK-specific rules that apply on top. The full statutory text sits on Legislation.

How the UK GDPR and DPA 2018 work together

Treat the UK GDPR as your default rulebook and the DPA 2018 as the annexe you turn to for particular situations. The government’s data protection guidance frames the relationship exactly this way. The UK GDPR provides the framework of principles and rights, while the DPA 2018 supplements it with UK-specific exemptions and two dedicated regimes.

Relationship between UK GDPR and DPA 2018

Parts 3 and 4 of the DPA 2018 cover law enforcement and intelligence services processing respectively, and sit entirely outside the standard UK GDPR framework. If you work in policing, prosecutions, or national security, those Parts, not the UK GDPR, govern your processing.

For everyone else, the practical rule of thumb is simple. Default to the UK GDPR. Only dip into Schedules 1 to 4 of the DPA 2018 when you are handling special-category data or considering whether a statutory exemption applies. Most controllers will spend the majority of their time in UK GDPR territory and only occasionally need the DPA’s finer print.

The differences between the two texts are not academic. They dictate what you can refuse, what you must document, and where your risk sits.

  • Exemptions are narrow and conditional. Schedules 2 to 4 of the DPA 2018 list exemptions covering areas such as crime and taxation, journalism, and regulatory activity. Each applies only to specific circumstances, never as a blanket excuse to withhold data.
  • Special-category data needs two things, not one. You need an Article 9 lawful basis under the UK GDPR and a matching condition from the 23 conditions in Schedule 1 of the DPA 2018. Missing either one is a compliance gap.
  • Law enforcement and intelligence sit apart. Parts 3 and 4 of the DPA 2018 are deliberately separate statutory regimes, built for a different purpose than commercial or public-sector processing.
  • Post-Brexit divergence is widening. Recent UK reforms introduce targeted flexibility on issues like legitimate interests and transfer mechanisms, moving the UK GDPR gradually away from the EU GDPR. Legal commentary on the UK’s recent reform pillars describes this as deliberate flexibility rather than deregulation.

Pro Tip: Never rely on an exemption as a standing policy. The ICO expects a case-by-case judgement each time, backed by a written note explaining exactly why the exemption applied to that specific request.

Practical compliance steps for controllers and processors

Turning the legal detail into daily practice comes down to five habits outlined on the DiliCheck blog.

  1. Assess DSARs individually. When a subject access request lands, check whether a Schedule 2 exemption genuinely applies before withholding or redacting anything, and never redact more than the exemption justifies.
  2. Map special-category processing twice. Record both the Article 9 basis and the matching Schedule 1 condition in your data protection impact assessments and processing records, not just one or the other.
  3. Document every exemption decision. Keep a written justification, dated and specific, so you can produce it if the ICO enquires or a complaint escalates.
  4. Build retention and disposal into the same process. Once a retention period expires, secure destruction closes the loop. A certificate of destruction from your disposal supplier gives you the audit evidence to match your documented decisions.
  5. Escalate early when in doubt. If a request touches law enforcement processing, intelligence exemptions, or a genuinely novel special-category scenario, get legal counsel involved before you respond, not after.

Pro Tip: Keep a simple exemptions log alongside your record of processing activities. Auditors and the ICO respond far better to a controller who can show their reasoning than one who states a conclusion with no paper trail.

ICO enforcement powers and the cost of getting it wrong

The ICO can impose fines of up to £17.5 million or 4% of global annual turnover, whichever is higher, for the most serious infringements.

Fines are the headline figure, but rarely the whole story. The ICO’s toolkit also includes:

  • Enforcement notices requiring specific corrective action within a set timeframe
  • Formal reprimands and warnings that sit on public record
  • Referral routes that can lead to civil claims brought directly under the DPA 2018

Accountability is what the ICO actually checks for during an investigation: your records of processing, your DPIAs, your contracts with processors, and your documented reasoning for any exemption you relied on. A missing paper trail tends to escalate a case faster than the original complaint.

Where to check the current law and guidance

Bookmark three sources and revisit them whenever your processing changes. The DPA 2018 text on legislation.gov.uk, GOV.UK’s data protection overview, and the ICO’s guidance pages on exemptions, DSARs, and fines. Watch GOV.UK and the ICO for updates as further UK reforms take effect.

Recommended compliance posture for UK practitioners — overview diagram

My honest read of this framework: most organisations overcomplicate it by treating UK GDPR and DPA 2018 as two separate compliance projects. Run one core programme built around UK GDPR principles, then attach jurisdictional modules for the areas where the DPA 2018 or EU rules genuinely diverge, rather than duplicating your entire compliance effort.

Use exemptions sparingly. Every one you claim needs a written justification you would be comfortable showing an ICO investigator, not a general policy statement. If you handle data on both sides of the Channel, prioritise your transfer mechanisms and processor contracts first. Legal analysis of the UK’s recent reforms points squarely at a bifocal approach as the sensible route through growing divergence, and that matches what the enforcement record actually punishes: gaps in documentation, not gaps in intention.

— Dan

Secure disposal: closing the compliance loop with confidence

Good policy on paper still leaves a physical risk if old files and drives end up in a general waste bin. Secure-shred is a straightforward way to close that gap for homes and small to medium-sized businesses across Cardiff and South Wales, giving you a lower-effort route to compliant disposal than trying to manage confidential waste in-house.

Secure-shred

Collections include GPS-tracked vehicles and CCTV monitoring, providing traceable evidence of what happened to documents and media. You get a certificate of destruction and a clear chain of custody for every job, whether that is a one-off archive clear-out or a scheduled pay-as-you-go collection, which gives you the audit paperwork the ICO expects to see documented in the earlier sections. Full details of how this supports your GDPR obligations are on our document shredding and compliance page, and if you would rather book a single collection, our one-off shredding service covers that too. Get a quick quote and put a proper disposal trail behind your retention policy this week.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources

FAQ

Are UK GDPR and the Data Protection Act 2018 the same thing?

No. The UK GDPR sets out the core principles and rights, while the DPA 2018 is separate legislation that supplements it with UK-specific exemptions and dedicated regimes for law enforcement and intelligence processing.

Is the Data Protection Act 2018 still valid?

Yes, it remains in force and works alongside the UK GDPR as the current UK data protection regime, with the ICO overseeing enforcement of both.

What is the difference between UK GDPR and EU GDPR?

They share the same origin, but the UK GDPR has begun diverging through domestic reforms that introduce targeted flexibility on areas like legitimate interests and international transfers, while the EU GDPR continues to evolve separately within the EU.

Has GDPR replaced the DPA 2018?

No. Neither replaced the other. The UK GDPR provides the framework and the DPA 2018 supplements it, and both must be read together to understand a controller’s full obligations.

Do I need to worry about GDPR vs ISO 27001?

They serve different purposes. UK GDPR and the DPA 2018 are legal obligations, while an international information security standard is a voluntary framework that many organisations use to demonstrate the technical and organisational measures their legal compliance requires.