TermsBox
PricingBlog
LoginGet Started
PricingBlogLogin
Get Started
  1. Home
  2. Blog
  3. Compliance With Data Protection Act: A Practical 2026 Guide
GDPR

Compliance With Data Protection Act: A Practical 2026 Guide

How to achieve compliance with the Data Protection Act 2018 and the UK GDPR: the principles, lawful bases, ICO fees, breach reporting, and penalties.

TermsBox Team|July 26, 202615 min read

Compliance with the Data Protection Act is not a document you file once and forget. The Data Protection Act 2018 works together with the UK GDPR to govern how you collect, store, share, and delete personal data, and the Information Commissioner's Office (ICO) expects you to prove your compliance on demand. This guide covers what the law requires, how to build compliance into your operations, and where organisations most often get caught out. It is educational rather than legal advice, so consult a qualified data protection solicitor for guidance specific to your business.

What Compliance With the Data Protection Act Means

Compliance with the Data Protection Act means you can demonstrate that every use of personal data in your organisation has a lawful basis, follows the seven data protection principles, respects individual rights, and is documented well enough to withstand scrutiny from a regulator.

The word "demonstrate" carries the weight. Article 5(2) of the UK GDPR contains the accountability principle: you are responsible for compliance and for being able to show it. An organisation that behaves lawfully but keeps no records is still exposed, because it cannot evidence anything when the ICO asks.

Three separate instruments make up the current UK framework:

  • The UK GDPR, the retained version of Regulation (EU) 2016/679, which sets the principles, lawful bases, rights, and fines.
  • The Data Protection Act 2018, which supplements the regulation with UK-specific exemptions, defines special category conditions in Schedule 1, and covers law enforcement processing in Part 3 and intelligence services in Part 4.
  • The Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025 and amends both of the above, including changes to automated decision-making, a list of recognised legitimate interests, and a formal complaints route to controllers.

For background on the statute itself, see the deeper explainer on what the Data Protection Act 2018 covers.

Who Must Comply With the Data Protection Act

There is no small business exemption. If you determine why and how personal data is processed, you are a controller and the Act applies to you, whether you are a sole trader running a Shopify store or a 500-person agency.

You are in scope if any of the following is true:

  1. You are established in the UK and process personal data, regardless of where the processing physically happens.
  2. You are outside the UK but offer goods or services to people in the UK.
  3. You are outside the UK but monitor the behaviour of people in the UK, which includes analytics, advertising pixels, and session recording.

The only true carve-out is the domestic purposes exemption in Article 2(2)(a), which covers purely personal or household activity such as a private contacts list. A membership list for a small sports club is not exempt, because the activity has a professional or commercial character.

Processors have direct obligations too. If you host, analyse, or email on behalf of another organisation, Article 28 requires a written contract, and Article 32 makes you directly liable for your own security failures.

The Principles Behind Compliance With the Data Protection Act

Article 5(1) of the UK GDPR sets out seven principles, and almost every enforcement action traces back to one of them. Each principle translates into a concrete operational duty:

  • Lawfulness, fairness, and transparency. Identify a lawful basis before you process, and tell people what you are doing in plain language.
  • Purpose limitation. Collect data for specified purposes and do not repurpose it later without checking compatibility.
  • Data minimisation. Ask for the fields you need. A newsletter signup does not need a date of birth.
  • Accuracy. Keep records correct and correct or erase inaccurate data without delay.
  • Storage limitation. Set and enforce retention periods. Indefinite storage is a breach in itself.
  • Integrity and confidentiality. Apply appropriate technical and organisational security measures under Article 32.
  • Accountability. Document your decisions so you can prove the other six.

The data protection principles explained in detail go further into how regulators interpret each one. If you only audit one thing this quarter, audit storage limitation: it is the principle most organisations quietly ignore, and it is easy for the ICO to test.

Choosing and Recording a Lawful Basis

Article 6(1) gives six lawful bases, and you must pick the right one before processing starts. You cannot switch bases later because the first one became inconvenient.

Lawful basis Article Typical use
Consent 6(1)(a) Marketing emails, non-essential cookies, optional profiling
Contract 6(1)(b) Fulfilling an order, running a paid account
Legal obligation 6(1)(c) Retaining tax records, anti-money laundering checks
Vital interests 6(1)(d) Emergency medical situations
Public task 6(1)(e) Statutory functions of public authorities
Legitimate interests 6(1)(f) Fraud prevention, network security, some B2B outreach

Consent has a high bar under Article 7 and Recital 32: it must be freely given, specific, informed, and given by clear affirmative action. Pre-ticked boxes, bundled consents, and cookie walls that offer no genuine choice all fail.

Legitimate interests is the most flexible basis and the most misused. Using it requires a documented three-part balancing test covering purpose, necessity, and the impact on the individual. Write it down before you launch, not after a complaint arrives.

Special category data, including health, biometric, and political data, needs a second condition from Article 9(2) plus, in most cases, a Schedule 1 condition from the Data Protection Act 2018 and an appropriate policy document.

Publishing a Privacy Notice That Meets the Act

Articles 13 and 14 list exactly what your privacy notice must contain, and the ICO treats missing items as a straightforward transparency failure. Your notice must state:

  • Your identity and contact details, and those of your data protection officer if you have one.
  • The purposes of processing and the lawful basis for each purpose.
  • Your legitimate interests, where that is the basis you rely on.
  • Recipients or categories of recipients, including processors and analytics vendors.
  • Any transfers outside the UK and the safeguards used, such as the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses.
  • Retention periods, or the criteria used to set them.
  • All individual rights, including the right to withdraw consent and to complain to the ICO.
  • Whether providing the data is a statutory or contractual requirement.

Write it for the reader, not the regulator. Article 12(1) requires concise, transparent, intelligible, and easily accessible language, and a 6,000-word wall of legalese fails that test even when every required item is technically present. A privacy policy generator that maps each disclosure to its Article 13 requirement is a faster starting point than adapting a template you found on a competitor's site, because competitor policies rarely match your actual vendor stack.

The notice must also match reality. If your policy says you keep support tickets for 12 months and your helpdesk has records from 2019, the policy is evidence against you.

Handling Individual Rights Requests

Chapter 3 of the UK GDPR gives eight rights. You have one calendar month to respond, extendable by two further months for complex or numerous requests under Article 12(3), and you cannot charge a fee unless the request is manifestly unfounded or excessive.

The rights you must be able to service on request are:

  1. Access to a copy of the data and the supporting information (Article 15).
  2. Rectification of inaccurate data (Article 16).
  3. Erasure, often called the right to be forgotten (Article 17).
  4. Restriction of processing (Article 18).
  5. Data portability in a structured, machine-readable format (Article 20).
  6. Objection to processing, absolute for direct marketing (Article 21).
  7. Rights related to automated decision-making and profiling (Article 22).
  8. The right to be informed, delivered through your privacy notice.

Subject access requests cause the most trouble in practice because they arrive by any channel, including a tweet or a comment to a junior employee, and the clock starts anyway. Train front-line staff to recognise and escalate them, and read up on how subject access requests work under the GDPR before the first one lands.

Registration, Fees, and the ICO

Most UK controllers must pay an annual data protection fee to the ICO under the Data Protection (Charges and Information) Regulations 2018. Failing to pay is a separate enforcement matter from any breach of the principles, and the ICO routinely issues fixed penalties of up to GBP 4,350 for non-payment.

The tiers, as they stand since February 2025, are:

  • Tier 1 (micro organisations): GBP 52, for turnover up to GBP 632,000 or no more than 10 staff.
  • Tier 2 (small and medium): GBP 78, for turnover up to GBP 36 million or no more than 250 staff.
  • Tier 3 (large organisations): GBP 3,763, for everyone above those thresholds.

A GBP 5 discount applies if you pay by direct debit, and some organisations, including certain not-for-profits, are exempt. Run the ICO's fee self-assessment rather than guessing your tier, and see the overview of how the ICO approaches data protection for what happens after a complaint is filed.

Documentation That Proves Compliance With the Data Protection Act

When the ICO investigates, it asks for paperwork. Build these artefacts now, while nothing is on fire:

Privacy Policy Generator

Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.

Generate Now
  • Records of processing activities (ROPA) under Article 30, covering purposes, categories of data and recipients, transfers, retention, and security measures.
  • Legitimate interests assessments for every Article 6(1)(f) purpose.
  • Data protection impact assessments (DPIAs) under Article 35 for high-risk processing such as large-scale profiling, systematic monitoring of public areas, or processing special category data at scale.
  • Processor contracts containing the Article 28(3) clauses, including instructions, confidentiality, sub-processor consent, and deletion at end of contract.
  • A retention schedule mapping each data category to a defined period and a deletion mechanism.
  • A breach log, required by Article 33(5) for every incident, notified or not.

Article 30(5) softens the ROPA requirement for organisations with fewer than 250 employees, but the relief is narrower than most people assume: it falls away if the processing is not occasional, is likely to risk rights and freedoms, or involves special category or criminal offence data. Routine customer databases usually fail that test, so keep the record anyway.

Article 37 requires a designated data protection officer only for public authorities, organisations whose core activities involve regular and systematic monitoring on a large scale, or large-scale processing of special category data. Everyone else still benefits from naming a responsible person. The guide to data protection officers and when you need one covers the appointment criteria.

Cookies, Tracking, and PECR

The Privacy and Electronic Communications Regulations 2003 (PECR) sit on top of the Data Protection Act and govern cookies, similar technologies, and electronic marketing. Regulation 6 requires informed consent before storing or accessing information on a user's device, unless the cookie is strictly necessary to deliver a service the user requested.

That means analytics, advertising, and personalisation cookies all need prior opt-in consent, with reject as easy as accept. The ICO wrote to the UK's top websites in late 2023 and again pursued non-compliant cookie banners through 2024 and 2025, so this is an actively enforced area rather than a theoretical one.

PECR also caps marketing fines at GBP 500,000, and the ICO has increasingly used it against nuisance call and spam text operators because the evidential path is shorter than a full UK GDPR case. Your cookie banner, your cookie policy, and your actual tracker inventory need to agree with each other. Automated scanners such as TermsBox detect the cookies and third-party services actually firing on your pages, which is the only reliable way to keep a policy accurate as marketing tools come and go.

Breach Response and Enforcement Risk

Article 33 gives you 72 hours from becoming aware of a personal data breach to notify the ICO, unless the breach is unlikely to result in a risk to people's rights and freedoms. Where the risk is high, Article 34 requires you to tell the affected individuals without undue delay, in clear and plain language.

"Becoming aware" starts when you have a reasonable degree of certainty that a security incident compromised personal data, not when your investigation concludes. If you cannot gather all the facts in time, submit a phased notification rather than missing the deadline.

The financial exposure has two levels under Article 83 as applied in the UK:

  • Standard maximum: GBP 8.75 million or 2 percent of total worldwide annual turnover, whichever is higher, for failures such as inadequate records or breach notification.
  • Higher maximum: GBP 17.5 million or 4 percent of total worldwide annual turnover, whichever is higher, for breaching the principles, lawful basis rules, individual rights, or transfer restrictions.

The Data Protection Act 2018 adds criminal liability that a corporate fine does not cover. Section 170 makes it an offence to knowingly or recklessly obtain, disclose, or retain personal data without the controller's consent, and Section 171 criminalises re-identifying de-identified data. The ICO has prosecuted individual employees under Section 170 for looking up records they had no business reason to see. Details on incident handling appear in the guide to GDPR data breach obligations.

A Practical Compliance Checklist

Work through this sequence to move from theory to evidence:

  1. Map your data. List every system that holds personal data, what it holds, who can see it, and where it sits.
  2. Assign a lawful basis to each processing purpose and document it, with a balancing test wherever you rely on legitimate interests.
  3. Rewrite your privacy notice against the Article 13 and 14 checklists, matching it to the vendors you actually use.
  4. Set retention periods for every data category and automate deletion where you can.
  5. Audit your trackers and align your cookie banner, consent records, and cookie policy with what is really loading.
  6. Paper your processors with Article 28 contracts and confirm the transfer safeguards for any vendor outside the UK.
  7. Write a rights request procedure with a named owner, a one-month calendar reminder, and an identity verification step.
  8. Write a breach procedure with a 72-hour escalation path and a standing breach log.
  9. Pay the ICO fee and diarise the annual renewal.
  10. Train your staff and record the training, because the ICO asks for attendance evidence.

Review the whole set at least annually, and immediately whenever you launch a product, add a marketing tool, or change a data-handling vendor. A compliance file that was accurate 18 months ago is not a defence today.

Frequently Asked Questions

What does compliance with the Data Protection Act actually require?

Compliance with the Data Protection Act 2018 requires you to process personal data under one of the six lawful bases in Article 6 of the UK GDPR, follow the seven data protection principles, publish a privacy notice, honour individual rights within one month, and keep records that prove all of this. Most organisations must also pay the annual ICO data protection fee.

Does the Data Protection Act 2018 replace the GDPR in the UK?

No. The Data Protection Act 2018 sits alongside the UK GDPR and fills in the areas the regulation left to national law, such as exemptions, the age of consent for online services, and rules for law enforcement and intelligence processing. You need to read both together, plus the amendments made by the Data (Use and Access) Act 2025.

Do small businesses have to comply with the Data Protection Act?

Yes. There is no revenue or headcount threshold in the Data Protection Act 2018, so a sole trader with a mailing list is in scope just as much as a large retailer. Small organisations do get relief in one place: Article 30(5) of the UK GDPR limits full records of processing activities for organisations with fewer than 250 staff, subject to conditions.

How much is the ICO data protection fee?

The fee has three tiers based on turnover, staff numbers, and the type of processing you do. Since February 2025 it has been GBP 52 for tier 1 micro organisations, GBP 78 for tier 2 small and medium organisations, and GBP 3,763 for tier 3 large organisations, with a GBP 5 discount for direct debit. Use the ICO's fee self-assessment to confirm your tier before paying.

What are the penalties for failing to comply with the Data Protection Act?

The higher maximum under the UK GDPR is GBP 17.5 million or 4 percent of total worldwide annual turnover, whichever is greater, with a standard maximum of GBP 8.75 million or 2 percent for lesser breaches. The Data Protection Act 2018 also creates criminal offences, including knowingly obtaining or disclosing personal data without consent under Section 170.

How long do I have to report a personal data breach?

You must notify the ICO within 72 hours of becoming aware of a breach that is likely to result in a risk to people's rights and freedoms, as required by Article 33 of the UK GDPR. If the risk is high, you must also tell the affected individuals without undue delay, and you must log every breach internally even when no notification is needed.

Related Tools

Privacy Policy Generator

Create a comprehensive privacy policy for your website or app

Related Articles

GDPR

GDPR for SaaS: A Practical Compliance Guide for Software Companies

Learn how GDPR for SaaS works: controller vs processor roles, DPAs, subprocessors, data subject rights, and the steps your software company must take.

July 27, 202612 min read
GDPR

Data Protection Agreement: What It Is and When You Need One

A data protection agreement is required under GDPR Article 28 whenever a vendor processes personal data for you. Learn what clauses it must contain.

July 26, 202614 min read
GDPR

GDPR Cookie Compliance: Complete Requirements Guide

GDPR cookie compliance explained: which cookies need consent, what makes consent valid, banner design rules, cookie policy disclosures, and recent fines.

July 24, 202613 min read

Ready to Create Your Legal Documents?

Generate professional privacy policies, terms of service, and more in minutes. Free to start, no credit card required.

View All Generators

On This Page

  • What Compliance With the Data Protection Act Means
  • Who Must Comply With the Data Protection Act
  • The Principles Behind Compliance With the Data Protection Act
  • Choosing and Recording a Lawful Basis
  • Publishing a Privacy Notice That Meets the Act
  • Handling Individual Rights Requests
  • Registration, Fees, and the ICO
  • Documentation That Proves Compliance With the Data Protection Act
  • Cookies, Tracking, and PECR
  • Breach Response and Enforcement Risk
  • A Practical Compliance Checklist
  • Frequently Asked Questions
TermsBox

Scan your website, auto-generate legal documents, add a consent banner, and stay compliant. One platform for everything.

Product
  • Cookie Scanner
  • Consent Banner
  • Cookie Policy Generator
  • Pricing
Generators
  • Privacy Policy Generator
  • Terms and Conditions Generator
  • EULA Generator
  • Disclaimer Generator
  • Return and Refund Policy Generator
Company
  • About
  • Contact
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
GDPR
ePrivacy
CCPA
LGPD
Google Consent Mode v2
IAB TCF 2.2
© 2026 TermsBox. All rights reserved.