GDPR and DPA are two terms that appear together constantly in UK data protection compliance, and they are regularly confused. GDPR refers to the General Data Protection Regulation, the EU’s primary data protection law. DPA has two distinct meanings depending on context: it can refer to the Data Protection Act 2018, the UK statute that sits alongside and supplements the GDPR, or it can refer to a Data Processing Agreement, the contract required between controllers and processors under data protection law.
This guide explains what each term means, how GDPR and the Data Protection Act 2018 relate to each other, whether GDPR replaced the DPA, what a Data Processing Agreement must contain, and how the framework applies to UK businesses after Brexit.
Key Definitions
| Term | What it means |
|---|---|
| GDPR | General Data Protection Regulation. Regulation (EU) 2016/679. The EU’s primary data protection law, applicable since 25 May 2018 |
| UK GDPR | The version of the GDPR retained in UK domestic law following Brexit, as modified by the Data Protection Act 2018 and the European Union (Withdrawal) Act 2018 |
| DPA 2018 | Data Protection Act 2018. The UK statute that implemented the GDPR into domestic law and supplements it with UK-specific provisions |
| DPA (agreement) | Data Processing Agreement. The contract required under Article 28 GDPR between a controller and a processor |
| Controller | The entity that determines the purposes and means of processing personal data |
| Processor | The entity that processes personal data on behalf of a controller |
| ICO | Information Commissioner’s Office. The UK’s data protection supervisory authority |
What Is the GDPR
The GDPR, General Data Protection Regulation, is Regulation (EU) 2016/679. It was adopted by the European Parliament and Council on 27 April 2016 and became directly applicable across all EU member states on 25 May 2018, replacing the previous EU Data Protection Directive 95/46/EC.
The GDPR establishes a comprehensive framework for the processing of personal data, covering lawful bases for processing, individual rights, security obligations, breach notification, international data transfers, and enforcement. It applies to any organisation processing the personal data of EU residents, regardless of where that organisation is established.
The GDPR is a regulation, not a directive. This means it applied directly in all EU member states without requiring national implementing legislation. However, the GDPR also contains approximately 50 provisions that allow member states to exercise national discretion, meaning national laws were still needed to fill those gaps.
What Does DPA Stand For in GDPR
In the context of GDPR, DPA stands for two different things depending on how it is used.
DPA as Data Protection Act: In UK context, DPA most commonly refers to the Data Protection Act 2018, the UK statute that implemented the GDPR and supplemented it with UK-specific provisions. When UK practitioners refer to “GDPR and DPA” they typically mean the GDPR and the Data Protection Act 2018 operating together as the UK data protection framework.
DPA as Data Processing Agreement: In a contractual context, DPA refers to a Data Processing Agreement, the contract required under Article 28 of the GDPR between a data controller and a data processor. When a business engages a third-party service provider to process personal data on its behalf, a DPA must be in place before processing begins.
| Context | What DPA means |
|---|---|
| UK data protection law generally | Data Protection Act 2018 |
| Controller-processor relationships | Data Processing Agreement |
| Supervisory authority abbreviation | Data Protection Authority (the ICO in the UK) |
GDPR and DPA: How They Relate
The Data Protection Act 2018
The Data Protection Act 2018 was enacted to perform three functions. First, it implemented the GDPR into UK domestic law by exercising the national discretions available under the GDPR. Second, it provided a separate regime for law enforcement data processing not covered by the GDPR, implementing the Law Enforcement Directive 2016/680. Third, it provided a regime for intelligence services data processing.
The DPA 2018 and the GDPR worked together as a single framework before Brexit. The GDPR was the directly applicable regulation. The DPA 2018 filled the gaps, exercised national discretions, and added UK-specific provisions.
| Framework element | Legal source |
|---|---|
| Core data protection principles | GDPR Article 5 |
| Lawful bases for processing | GDPR Article 6 |
| Special category data processing conditions | GDPR Article 9 and DPA 2018 Schedule 1 |
| Criminal convictions data conditions | GDPR Article 10 and DPA 2018 Schedule 1 |
| Exemptions (journalism, research, national security) | DPA 2018 Schedule 2 |
| Age of consent for information society services | DPA 2018 Section 9 (set at 13 in the UK) |
| Law enforcement processing | DPA 2018 Part 3 |
| Intelligence services processing | DPA 2018 Part 4 |
| ICO powers and enforcement | DPA 2018 Part 6 |
Did GDPR Replace the DPA
This is one of the most common questions in UK data protection compliance. The answer requires separating pre-Brexit and post-Brexit positions.
Before Brexit: The GDPR did not entirely replace the DPA. The Data Protection Act 1998, the previous UK data protection statute, was repealed and replaced by the Data Protection Act 2018. The DPA 2018 and the GDPR then operated together as a combined framework. The GDPR was directly applicable as EU law. The DPA 2018 supplemented it.
After Brexit: The European Union (Withdrawal) Act 2018 retained the GDPR in UK domestic law as the UK GDPR. The DPA 2018 was amended to work alongside the UK GDPR rather than the EU GDPR. Both remain in force. The UK GDPR and the DPA 2018 together constitute the current UK data protection framework.
| Question | Answer |
|---|---|
| Did GDPR replace the Data Protection Act 1998? | Yes. The DPA 1998 was repealed and replaced by the DPA 2018 |
| Did GDPR replace the Data Protection Act 2018? | No. The DPA 2018 and GDPR operate together as a combined framework |
| Does GDPR still apply in the UK after Brexit? | Yes, as the UK GDPR, retained in domestic law |
| Is the DPA 2018 still in force? | Yes. It supplements the UK GDPR |
Is the DPA the Same as the GDPR
No. The DPA 2018 and the GDPR are distinct legal instruments that operate together. The GDPR is an EU regulation containing the core data protection framework. The DPA 2018 is a UK Act of Parliament that exercises national discretions available under the GDPR, provides supplementary regimes for law enforcement and intelligence services, and contains UK-specific provisions including exemptions, enforcement powers, and the ICO’s regulatory framework.
Saying “GDPR and DPA” when referring to UK data protection law is accurate. Treating them as synonyms is not.
After Brexit, the distinction became more significant. The EU GDPR continues to apply to UK businesses that process personal data of EU residents. The UK GDPR applies to processing of UK residents’ personal data. A UK business with customers in both the EU and the UK must comply with both simultaneously.
GDPR vs DPA: Key Differences
| Feature | EU GDPR | UK GDPR + DPA 2018 |
|---|---|---|
| Legal instrument | EU Regulation (directly applicable) | Retained in UK domestic law + UK statute |
| Territorial scope | Processing of EU residents’ personal data | Processing of UK residents’ personal data |
| Supervisory authority | National DPAs (e.g. CNIL, BfDI, DPC) | Information Commissioner’s Office (ICO) |
| Maximum fine | €20 million or 4% of worldwide turnover | £17.5 million or 4% of worldwide turnover |
| Age of consent (information society services) | 16 (member states may lower to 13) | 13 |
| Law enforcement processing | Law Enforcement Directive (separate instrument) | DPA 2018 Part 3 |
| National exemptions | Available under GDPR Articles 85-91 | Exercised through DPA 2018 Schedule 2 |
| Adequacy status | UK has EU adequacy decision (under review) | EU has UK adequacy decision (under review) |
What Is a Data Processing Agreement (DPA)
A Data Processing Agreement is the contract required under Article 28 of the GDPR whenever a controller engages a processor to process personal data on its behalf. The DPA governs the relationship between the controller and the processor and ensures the processor only handles personal data in accordance with the controller’s instructions and the GDPR’s requirements.
When Is a DPA Required
A DPA is required whenever a controller shares personal data with a third party that processes that data on the controller’s behalf rather than for its own purposes. Common examples include:
| Scenario | DPA required |
|---|---|
| Using a cloud storage provider for personal data | Yes |
| Using a payroll processing service | Yes |
| Using an email marketing platform | Yes |
| Using a CRM system hosted by a third party | Yes |
| Sharing data with a joint controller | No (joint controller agreement required instead) |
| Sharing data with a recipient acting as an independent controller | No (but other transfer mechanisms may apply) |
What Must a DPA Contain
Article 28(3) of the GDPR sets out the mandatory content of a Data Processing Agreement. Every DPA must specify:
| Mandatory DPA provision | What it must cover |
|---|---|
| Subject matter and duration | What processing is covered and for how long |
| Nature and purpose | What the processor will do with the data and why |
| Type of personal data | Categories of data involved |
| Categories of data subjects | Who the data relates to |
| Controller’s obligations and rights | The controller’s instructions and the processor’s obligations |
| Processing only on instructions | Processor must process only on documented controller instructions |
| Confidentiality | Personnel must be committed to confidentiality |
| Security measures | Processor must implement appropriate security under Article 32 |
| Sub-processing | Processor may only engage sub-processors with controller authorisation |
| Assistance with rights | Processor must assist controller in responding to data subject rights requests |
| Assistance with obligations | Processor must assist controller in meeting security, breach notification, and DPIA obligations |
| Deletion or return | Processor must delete or return data at end of service |
| Audit rights | Processor must allow and contribute to audits by controller or authorised auditor |
GDPR, DPA, and UK Businesses After Brexit
Brexit created a dual compliance requirement for UK businesses with EU operations or EU customers.
A UK business established in the UK that processes personal data of UK residents is subject to the UK GDPR and the DPA 2018, enforced by the ICO.
The same UK business, if it processes personal data of EU residents, is also subject to the EU GDPR, enforced by the relevant national data protection authority in the EU member state of the affected individuals. This means UK businesses serving EU customers must comply with both frameworks simultaneously.
The EU has granted the UK an adequacy decision, currently in force but subject to periodic review. This means personal data can flow from the EU to the UK without additional safeguards. The UK has granted the EU an adequacy decision, meaning personal data can flow from the UK to the EU without additional safeguards. Both decisions are subject to ongoing review and could be revoked.
| Transfer direction | Legal mechanism | Current status |
|---|---|---|
| EU to UK | UK adequacy decision | In force, subject to review |
| UK to EU | EU adequacy decision | In force, subject to review |
| UK to US | UK Extension to EU-US DPF | In force, subject to review |
| EU to US | EU-US Data Privacy Framework | In force, under legal challenge |
GDPR, DPA, and the EU AI Act
UK and EU businesses using AI systems that process personal data face compliance obligations under both data protection law and the EU AI Act simultaneously. The two frameworks interact in several important areas.
The EU AI Act’s data governance requirements under Article 10 require providers of high-risk AI systems to examine training, validation, and testing datasets for bias and to implement appropriate data governance practices. Where those datasets include personal data, GDPR obligations including lawful basis, data minimisation, and purpose limitation apply in addition to the AI Act requirements.
Deployers of high-risk AI systems who conduct a Fundamental Rights Impact Assessment under Article 27 of the AI Act must coordinate that assessment with any Data Protection Impact Assessment required under Article 35 GDPR where the system processes personal data. The two assessments address overlapping but distinct questions and must both be completed.
FAQ
sdasd
asdasd
