Data Protection Act
A Data Protection Act is a national law that governs how organisations and government bodies collect, store, and use personal information about people. In the United Kingdom, the Data Protection Act 2018 is an Act of Parliament designed to ensure that personal data is handled responsibly. The specific rules, scope, and obligations depend on the particular Act and the country that enacted it.
"Data Protection Act" is a naming convention used by several jurisdictions for statutes that regulate the processing of personal data by controllers and processors. The most prominent current example is the UK's Data Protection Act 2018, an Act of Parliament governing the collection, storage, and handling of personal data. The term is not universal: it should not be treated as interchangeable with other regimes such as the EU GDPR, the UK GDPR, or US state and federal privacy laws, each of which has distinct scope, definitions, and obligations. Where a jurisdiction uses this title, the precise duties allocated between controllers and processors, the lawful bases for processing, and the enforcement mechanisms are defined by that specific Act and any accompanying regulations. This entry does not cover cross-border transfer mechanics, retention requirements, specific article or section references, or enforcement penalties, and readers should consult the text of the relevant Act for those details.
Why it matters
The phrase "Data Protection Act" is a naming convention adopted by several jurisdictions for statutes that regulate how personal data is processed, so its practical significance depends entirely on which Act is being referenced. In the United Kingdom, the Data Protection Act 2018 is an Act of Parliament designed to ensure that personal data is collected, stored, and handled responsibly by organisations and government bodies. For compliance and governance professionals, this means the title alone tells you little; the specific scope, definitions, and obligations must be drawn from the text of the particular Act and the country that enacted it.
Treating any "Data Protection Act" as equivalent to another privacy regime is a common and consequential error. The term should not be used interchangeably with the EU GDPR, the UK GDPR, or US state and federal privacy laws, each of which has distinct scope, definitions, and allocation of duties. Professionals who assume a single, universal set of rules risk misapplying obligations, misidentifying which party bears which responsibility, and building programmes against the wrong legal baseline.
Because the precise duties allocated between controllers and processors, the lawful bases for processing, and the enforcement mechanisms are defined by the specific Act in question, accountability requires anchoring your programme to the correct instrument and being able to demonstrate that alignment with evidence. Stating an intention to comply is not sufficient under governance frameworks; the operative text and its accompanying regulations must be consulted directly.
Who it's relevant to
Inside DPA
Common questions
Answers to the questions practitioners most commonly ask about DPA.