GDPR and DPA

GDPR and DPA are two terms that appear together constantly in UK data protection compliance, and they are regularly confused. GDPR refers to the General Data Protection Regulation, the EU’s primary data protection law. DPA has two distinct meanings depending on context: it can refer to the Data Protection Act 2018, the UK statute that sits alongside and supplements the GDPR, or it can refer to a Data Processing Agreement, the contract required between controllers and processors under data protection law.

This guide explains what each term means, how GDPR and the Data Protection Act 2018 relate to each other, whether GDPR replaced the DPA, what a Data Processing Agreement must contain, and how the framework applies to UK businesses after Brexit.


Key Definitions

TermWhat it means
GDPRGeneral Data Protection Regulation. Regulation (EU) 2016/679. The EU’s primary data protection law, applicable since 25 May 2018
UK GDPRThe version of the GDPR retained in UK domestic law following Brexit, as modified by the Data Protection Act 2018 and the European Union (Withdrawal) Act 2018
DPA 2018Data Protection Act 2018. The UK statute that implemented the GDPR into domestic law and supplements it with UK-specific provisions
DPA (agreement)Data Processing Agreement. The contract required under Article 28 GDPR between a controller and a processor
ControllerThe entity that determines the purposes and means of processing personal data
ProcessorThe entity that processes personal data on behalf of a controller
ICOInformation Commissioner’s Office. The UK’s data protection supervisory authority

What Is the GDPR

The GDPR, General Data Protection Regulation, is Regulation (EU) 2016/679. It was adopted by the European Parliament and Council on 27 April 2016 and became directly applicable across all EU member states on 25 May 2018, replacing the previous EU Data Protection Directive 95/46/EC.

The GDPR establishes a comprehensive framework for the processing of personal data, covering lawful bases for processing, individual rights, security obligations, breach notification, international data transfers, and enforcement. It applies to any organisation processing the personal data of EU residents, regardless of where that organisation is established.

The GDPR is a regulation, not a directive. This means it applied directly in all EU member states without requiring national implementing legislation. However, the GDPR also contains approximately 50 provisions that allow member states to exercise national discretion, meaning national laws were still needed to fill those gaps.


What Does DPA Stand For in GDPR

In the context of GDPR, DPA stands for two different things depending on how it is used.

DPA as Data Protection Act: In UK context, DPA most commonly refers to the Data Protection Act 2018, the UK statute that implemented the GDPR and supplemented it with UK-specific provisions. When UK practitioners refer to “GDPR and DPA” they typically mean the GDPR and the Data Protection Act 2018 operating together as the UK data protection framework.

DPA as Data Processing Agreement: In a contractual context, DPA refers to a Data Processing Agreement, the contract required under Article 28 of the GDPR between a data controller and a data processor. When a business engages a third-party service provider to process personal data on its behalf, a DPA must be in place before processing begins.

ContextWhat DPA means
UK data protection law generallyData Protection Act 2018
Controller-processor relationshipsData Processing Agreement
Supervisory authority abbreviationData Protection Authority (the ICO in the UK)

GDPR and DPA: How They Relate

The Data Protection Act 2018

The Data Protection Act 2018 was enacted to perform three functions. First, it implemented the GDPR into UK domestic law by exercising the national discretions available under the GDPR. Second, it provided a separate regime for law enforcement data processing not covered by the GDPR, implementing the Law Enforcement Directive 2016/680. Third, it provided a regime for intelligence services data processing.

The DPA 2018 and the GDPR worked together as a single framework before Brexit. The GDPR was the directly applicable regulation. The DPA 2018 filled the gaps, exercised national discretions, and added UK-specific provisions.

Framework elementLegal source
Core data protection principlesGDPR Article 5
Lawful bases for processingGDPR Article 6
Special category data processing conditionsGDPR Article 9 and DPA 2018 Schedule 1
Criminal convictions data conditionsGDPR Article 10 and DPA 2018 Schedule 1
Exemptions (journalism, research, national security)DPA 2018 Schedule 2
Age of consent for information society servicesDPA 2018 Section 9 (set at 13 in the UK)
Law enforcement processingDPA 2018 Part 3
Intelligence services processingDPA 2018 Part 4
ICO powers and enforcementDPA 2018 Part 6

Did GDPR Replace the DPA

This is one of the most common questions in UK data protection compliance. The answer requires separating pre-Brexit and post-Brexit positions.

Before Brexit: The GDPR did not entirely replace the DPA. The Data Protection Act 1998, the previous UK data protection statute, was repealed and replaced by the Data Protection Act 2018. The DPA 2018 and the GDPR then operated together as a combined framework. The GDPR was directly applicable as EU law. The DPA 2018 supplemented it.

After Brexit: The European Union (Withdrawal) Act 2018 retained the GDPR in UK domestic law as the UK GDPR. The DPA 2018 was amended to work alongside the UK GDPR rather than the EU GDPR. Both remain in force. The UK GDPR and the DPA 2018 together constitute the current UK data protection framework.

QuestionAnswer
Did GDPR replace the Data Protection Act 1998?Yes. The DPA 1998 was repealed and replaced by the DPA 2018
Did GDPR replace the Data Protection Act 2018?No. The DPA 2018 and GDPR operate together as a combined framework
Does GDPR still apply in the UK after Brexit?Yes, as the UK GDPR, retained in domestic law
Is the DPA 2018 still in force?Yes. It supplements the UK GDPR

Is the DPA the Same as the GDPR

No. The DPA 2018 and the GDPR are distinct legal instruments that operate together. The GDPR is an EU regulation containing the core data protection framework. The DPA 2018 is a UK Act of Parliament that exercises national discretions available under the GDPR, provides supplementary regimes for law enforcement and intelligence services, and contains UK-specific provisions including exemptions, enforcement powers, and the ICO’s regulatory framework.

Saying “GDPR and DPA” when referring to UK data protection law is accurate. Treating them as synonyms is not.

After Brexit, the distinction became more significant. The EU GDPR continues to apply to UK businesses that process personal data of EU residents. The UK GDPR applies to processing of UK residents’ personal data. A UK business with customers in both the EU and the UK must comply with both simultaneously.


GDPR vs DPA: Key Differences

FeatureEU GDPRUK GDPR + DPA 2018
Legal instrumentEU Regulation (directly applicable)Retained in UK domestic law + UK statute
Territorial scopeProcessing of EU residents’ personal dataProcessing of UK residents’ personal data
Supervisory authorityNational DPAs (e.g. CNIL, BfDI, DPC)Information Commissioner’s Office (ICO)
Maximum fine€20 million or 4% of worldwide turnover£17.5 million or 4% of worldwide turnover
Age of consent (information society services)16 (member states may lower to 13)13
Law enforcement processingLaw Enforcement Directive (separate instrument)DPA 2018 Part 3
National exemptionsAvailable under GDPR Articles 85-91Exercised through DPA 2018 Schedule 2
Adequacy statusUK has EU adequacy decision (under review)EU has UK adequacy decision (under review)

What Is a Data Processing Agreement (DPA)

A Data Processing Agreement is the contract required under Article 28 of the GDPR whenever a controller engages a processor to process personal data on its behalf. The DPA governs the relationship between the controller and the processor and ensures the processor only handles personal data in accordance with the controller’s instructions and the GDPR’s requirements.

When Is a DPA Required

A DPA is required whenever a controller shares personal data with a third party that processes that data on the controller’s behalf rather than for its own purposes. Common examples include:

ScenarioDPA required
Using a cloud storage provider for personal dataYes
Using a payroll processing serviceYes
Using an email marketing platformYes
Using a CRM system hosted by a third partyYes
Sharing data with a joint controllerNo (joint controller agreement required instead)
Sharing data with a recipient acting as an independent controllerNo (but other transfer mechanisms may apply)

What Must a DPA Contain

Article 28(3) of the GDPR sets out the mandatory content of a Data Processing Agreement. Every DPA must specify:

Mandatory DPA provisionWhat it must cover
Subject matter and durationWhat processing is covered and for how long
Nature and purposeWhat the processor will do with the data and why
Type of personal dataCategories of data involved
Categories of data subjectsWho the data relates to
Controller’s obligations and rightsThe controller’s instructions and the processor’s obligations
Processing only on instructionsProcessor must process only on documented controller instructions
ConfidentialityPersonnel must be committed to confidentiality
Security measuresProcessor must implement appropriate security under Article 32
Sub-processingProcessor may only engage sub-processors with controller authorisation
Assistance with rightsProcessor must assist controller in responding to data subject rights requests
Assistance with obligationsProcessor must assist controller in meeting security, breach notification, and DPIA obligations
Deletion or returnProcessor must delete or return data at end of service
Audit rightsProcessor must allow and contribute to audits by controller or authorised auditor

GDPR, DPA, and UK Businesses After Brexit

Brexit created a dual compliance requirement for UK businesses with EU operations or EU customers.

A UK business established in the UK that processes personal data of UK residents is subject to the UK GDPR and the DPA 2018, enforced by the ICO.

The same UK business, if it processes personal data of EU residents, is also subject to the EU GDPR, enforced by the relevant national data protection authority in the EU member state of the affected individuals. This means UK businesses serving EU customers must comply with both frameworks simultaneously.

The EU has granted the UK an adequacy decision, currently in force but subject to periodic review. This means personal data can flow from the EU to the UK without additional safeguards. The UK has granted the EU an adequacy decision, meaning personal data can flow from the UK to the EU without additional safeguards. Both decisions are subject to ongoing review and could be revoked.

Transfer directionLegal mechanismCurrent status
EU to UKUK adequacy decisionIn force, subject to review
UK to EUEU adequacy decisionIn force, subject to review
UK to USUK Extension to EU-US DPFIn force, subject to review
EU to USEU-US Data Privacy FrameworkIn force, under legal challenge

GDPR, DPA, and the EU AI Act

UK and EU businesses using AI systems that process personal data face compliance obligations under both data protection law and the EU AI Act simultaneously. The two frameworks interact in several important areas.

The EU AI Act’s data governance requirements under Article 10 require providers of high-risk AI systems to examine training, validation, and testing datasets for bias and to implement appropriate data governance practices. Where those datasets include personal data, GDPR obligations including lawful basis, data minimisation, and purpose limitation apply in addition to the AI Act requirements.

Deployers of high-risk AI systems who conduct a Fundamental Rights Impact Assessment under Article 27 of the AI Act must coordinate that assessment with any Data Protection Impact Assessment required under Article 35 GDPR where the system processes personal data. The two assessments address overlapping but distinct questions and must both be completed.

FAQ

sdasd

asdasd