12.2 Data Protection — DPA 2018 and UK GDPR

Key Takeaways

  • The Data Protection Act 2018 (DPA 2018) and the UK GDPR together govern the processing of personal data in the UK, and the Information Commissioner's Office (ICO) is the independent regulator
  • The UK GDPR Article 5 sets out six data-protection principles (lawfulness/fairness/transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality) plus an overarching accountability principle
  • The six lawful bases for processing personal data are consent, contract, legal obligation, vital interests, public task, and legitimate interests; special category data requires an additional condition
  • Individual rights include the right to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and rights regarding automated decision-making
  • A personal data breach likely to result in a risk to individuals must be reported to the ICO without undue delay and, where feasible, within 72 hours; high-risk breaches must also be communicated to affected individuals
Last updated: August 2026

The Legal Framework

The processing of personal data in the UK is governed by two overlapping instruments: the Data Protection Act 2018 (DPA 2018) and the UK GDPR (the UK's retained version of the EU General Data Protection Regulation). The DPA 2018 complements the UK GDPR by filling in areas the GDPR leaves to national law — for example, processing for law enforcement purposes and immigration — and by setting the rules for competent authorities. The independent regulator for both regimes is the Information Commissioner's Office (ICO), which issues guidance, investigates breaches, and can impose significant monetary penalties.

Quick Answer: Personal data in the UK is governed by the DPA 2018 and the UK GDPR, regulated by the ICO. The six principles of Article 5 sit beneath an accountability principle, and breaches likely to result in a risk to individuals must be reported to the ICO within 72 hours.

Personal Data and Special Category Data

Personal data is any information relating to an identified or identifiable living individual — a "data subject". Names, addresses, national insurance numbers, IP addresses, and claims reference numbers can all be personal data. Special category data is a sub-category of personal data that is more sensitive and attracts extra protection: it includes data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, health data, sex life and sexual orientation. Criminal-conviction data is treated separately but also requires extra protection.

In insurance, firms routinely process both. A motor proposal form contains personal data (name, address, driving licence number); a life or income protection proposal form, with its medical questions, contains special category health data; a claims file may contain a mix of personal data, special category data, and criminal-conviction data (for example, in fraud or theft claims). Processing special category data requires both a lawful basis and a separate condition in Schedule 1 of the DPA 2018 — for insurance, the most commonly relied upon condition is often the insurance condition that allows processing of special category data for insurance purposes.

The Six Data-Protection Principles and Accountability

Article 5 of the UK GDPR sets out six data-protection principles. Anyone processing personal data must comply with them. They are the foundation of the whole regime and are regularly examined in IF1.

PrincipleIn plain English
1. Lawfulness, fairness and transparencyProcess data lawfully, fairly, and in a transparent manner in relation to the data subject.
2. Purpose limitationCollect data for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes.
3. Data minimisationData must be adequate, relevant and limited to what is necessary for the purposes for which it is processed.
4. AccuracyData must be accurate and, where necessary, kept up to date; inaccurate data must be corrected or erased.
5. Storage limitationData must be kept in a form which permits identification of data subjects for no longer than is necessary.
6. Integrity and confidentiality (security)Process data securely, using appropriate technical or organisational measures against unauthorised or unlawful processing, accidental loss, destruction or damage.

Sitting above these six is the accountability principle in Article 5(2): the controller is responsible for, and must be able to demonstrate, compliance with the principles. This is not a seventh principle in the same sense — it is an overarching obligation to keep records, undertake data protection impact assessments where required, and be able to show the ICO what the firm is doing.

Lawful Bases for Processing

Personal data must be processed on at least one of the six lawful bases set out in Article 6 of the UK GDPR:

  1. Consent — the data subject has given clear, specific, freely given consent.
  2. Contract — processing is necessary for the performance of a contract with the data subject (for example, underwriting a policy and paying claims under it).
  3. Legal obligation — processing is necessary to comply with a legal obligation (for example, reporting to the FCA or complying with a court order).
  4. Vital interests — processing is necessary to protect someone's life.
  5. Public task — processing is necessary to carry out a task in the public interest or in the exercise of official authority.
  6. Legitimate interests — processing is necessary for the legitimate interests of the controller or a third party, except where those interests are overridden by the data subject's rights. This basis requires a legitimate interests assessment and is widely used by insurers and brokers for activities such as fraud detection.

For special category data, the controller needs both a lawful basis and a separate Article 9 condition (implemented in the DPA 2018 Schedule 1).

Individuals' Rights

The UK GDPR gives individuals (data subjects) a suite of enforceable rights against controllers:

  • The right to be informed — through privacy notices that explain what data is collected and why.
  • The right of access — a subject access request (SAR), which must usually be answered within one month and is free of charge in most cases.
  • The right to rectification — correction of inaccurate data.
  • The right to erasure (the "right to be forgotten") — in defined circumstances.
  • The right to restrict processing — temporarily halting processing while a dispute is resolved.
  • The right to data portability — receiving personal data in a structured, machine-readable format.
  • The right to object — to processing based on legitimate interests, public task, or direct marketing (which can almost always be stopped).
  • Rights in relation to automated decision-making and profiling — including a right not to be subject to a decision based solely on automated processing that has legal or similarly significant effects, subject to limited exceptions.

In insurance, these rights interact with the business in concrete ways: a policyholder can make a subject access request for the claims file the insurer holds about them; an applicant can ask for a correction to a medical disclosure they say was recorded inaccurately; and a consumer can object to their data being used for marketing.

Data Breaches and the 72-Hour Rule

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. It includes losing a laptop containing unencrypted customer data, emailing a claims file to the wrong recipient, or a cyber-attack that exfiltrates policyholder records.

Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, the controller must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach. If notification is not made within 72 hours, the controller must give reasons for the delay. Where the breach is likely to result in a high risk to individuals, the controller must also communicate the breach to the affected individuals without undue delay, so that they can take protective steps (for example, changing passwords or monitoring bank accounts).

The ICO encourages a "report early, update later" approach: firms should report what they know within 72 hours even if the picture is incomplete, and then provide further information in phases. Processors (for example, a third-party claims handler) must notify the controller without undue delay after becoming aware of a breach. In insurance, a broker or insurer that suffers a breach must consider whether to notify the ICO, affected policyholders, its professional indemnity insurer, the FCA (under Principle 11 and SUP 15.3 obligations), and, where relevant, the police or the National Cyber Security Centre.

Insurance Relevance

Insurers and brokers hold large volumes of personal and special category data — medical questionnaires for life and income protection underwriting, financial information for affordability checks, claims histories, and sometimes criminal-conviction data for fraud screening. They must:

  • identify a lawful basis for each processing activity and, for special category data, a separate Article 9 / Schedule 1 condition;
  • keep a Record of Processing Activities (ROPA) and, for higher-risk processing, undertake Data Protection Impact Assessments (DPIAs);
  • maintain security appropriate to the risk — encryption, access controls, staff training, incident response plans;
  • honour subject access requests within one month, generally free of charge; and
  • report notifiable breaches to the ICO within 72 hours and to affected individuals where the risk is high.

The ICO can impose substantial penalties for serious infringements: the higher maximum is £17.5 million or 4% of total worldwide annual turnover, whichever is the greater.

Key Takeaways

  • The DPA 2018 and the UK GDPR govern processing of personal data in the UK; the ICO is the regulator.
  • The UK GDPR Article 5 sets out six data-protection principles (lawfulness/fairness/transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality) plus an overarching accountability principle.
  • The six lawful bases for processing personal data are consent, contract, legal obligation, vital interests, public task, and legitimate interests; special category data needs an additional Article 9 / Schedule 1 condition.
  • Individuals' rights include the right to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and rights in relation to automated decision-making.
  • A personal data breach likely to result in a risk to individuals must be notified to the ICO without undue delay and within 72 hours where feasible; a high-risk breach must also be communicated to the affected individuals.
Test Your Knowledge

An insurance broker loses an unencrypted laptop containing a spreadsheet of policyholders' names, addresses, dates of birth and national insurance numbers. The broker assesses that the loss is likely to result in a risk to those individuals. What is the broker's obligation regarding notification to the ICO?

A
B
C
D
Test Your Knowledge

Which of the following correctly lists the six data-protection principles set out in Article 5 of the UK GDPR?

A
B
C
D
Test Your Knowledge

A life insurer underwrites an income protection policy and asks the applicant detailed medical questions. The answers constitute health data. What additional requirement applies to processing this data compared with ordinary personal data such as a name and address?

A
B
C
D