Data Protection Act 1998
1998 CHAPTER 29
An Act to make new provision for the regulation of the processing of information relating to individuals, including the obtaining, holding, use or disclosure of such information.
[16th July 1998]
Be it enacted by the Queen’s most Excellent Majesty, by and with the advice and consent of the Lords Spiritual and Temporal, and Commons, in this present Parliament assembled, and by the authority of the same, as follows:—
Part I Preliminary
1 Basic interpretative provisions.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
2 Sensitive personal data.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
3 The special purposes.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
4 The data protection principles.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
5 Application of Act.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
6 The Commissioner . . . .
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Part II Rights of data subjects and others
7 Right of access to personal data.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
8 Provisions supplementary to section 7.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
9 Application of section 7 where data controller is credit reference agency.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
9A Unstructured personal data held by public authorities.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
10 Right to prevent processing likely to cause damage or distress.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
11 Right to prevent processing for purposes of direct marketing.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
12 Rights in relation to automated decision-taking.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
12A Rights of data subjects in relation to exempt manual data.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
13 Compensation for failure to comply with certain requirements.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
14 Rectification, blocking, erasure and destruction.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
15 Jurisdiction and procedure.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Part III Notification by data controllers
16 Preliminary.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
17 Prohibition on processing without registration.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
18 Notification by data controllers.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
19 Register of notifications.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
20 Duty to notify changes.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
21 Offences.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
22 Preliminary assessment by Commissioner.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
23 Power to make provision for appointment of data protection supervisors.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
24 Duty of certain data controllers to make certain information available.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
25 Functions of Commissioner in relation to making of notification regulations.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
26 Fees regulations.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Part IV Exemptions
27 Preliminary.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
28 National security.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
29 Crime and taxation.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
30 Health, education and social work.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
31 Regulatory activity.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
32 Journalism, literature and art.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
33 Research, history and statistics.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
33A Manual data held by public authorities.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
34 Information available to the public by or under enactment.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
35 Disclosures required by law or made in connection with legal proceedings etc.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
35A Parliamentary privilege.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
36 Domestic purposes.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
37 Miscellaneous exemptions.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
38 Powers to make further exemptions by order.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
39 Transitional relief.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Part V Enforcement
40 Enforcement notices.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
41 Cancellation of enforcement notice.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
41A Assessment notices
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
41B Assessment notices: limitations
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
41C Code of practice about assessment notices
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
42 Request for assessment.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
43 Information notices.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
44 Special information notices.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
45 Determination by Commissioner as to the special purposes.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
46 Restriction on enforcement in case of processing for the special purposes.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
47 Failure to comply with notice.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
48 Rights of appeal.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
49 Determination of appeals.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
50 Powers of entry and inspection.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Part VI Miscellaneous and General
Functions of Commissioner
51 General duties of Commissioner.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
52 Reports and codes of practice to be laid before Parliament.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
52A Data-sharing code
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
52AA Direct marketing code
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
52B data-sharing and direct marketing codes: procedure
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
52C Alteration or replacement of data-sharing and direct marketing codes
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
52D Publication of data-sharing and direct marketing codes
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
52E Effect of data-sharing and direct marketing codes
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
53 Assistance by Commissioner in cases involving processing for the special purposes.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
54 International co-operation.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
54A Inspection of overseas information systems
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Unlawful obtaining et ceteralaetc. of personal data
55 Unlawful obtaining etc. of personal data.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Monetary penalties
55A Power of Commissioner to impose monetary penalty
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
55B Monetary penalty notices: procedural rights
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
55C Guidance about monetary penalty notices
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
55D Monetary penalty notices: enforcement
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
55E Notices under sections 55A and 55B: supplemental
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Records obtained under data subject’s right of access
56 Prohibition of requirement as to production of certain records.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
57 Avoidance of certain contractual terms relating to health records.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Information provided to Commissioner or Tribunal
58 Disclosure of information.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
59 Confidentiality of information.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
General provisions relating to offences
60 Prosecutions and penalties.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
61 Liability of directors etc.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Amendments of Consumer Credit Act 1974
62 Amendments of Consumer Credit Act 1974.
(1) In section 158 of the Consumer Credit Act 1974 (duty of agency to disclose filed information)—
(a) in subsection (1)—
(i) in paragraph (a) for “individual” there is substituted “ partnership or other unincorporated body of persons not consisting entirely of bodies corporate ” , and
(ii) for “him” there is substituted “ it ” ,
(b) in subsection (2), for “his” there is substituted “ the consumer’s ” , and
(c) in subsection (3), for “him” there is substituted “ the consumer ” .
(2) In section 159 of that Act (correction of wrong information) for subsection (1) there is substituted—
“ (1) Any individual (the “ objector ”) given—
(a) information under section 7 of the Data Protection Act 1998 by a credit reference agency, or
(b) information under section 158,
who considers that an entry in his file is incorrect, and that if it is not corrected he is likely to be prejudiced, may give notice to the agency requiring it either to remove the entry from the file or amend it. ”
(3) In subsections (2) to (6) of that section—
(a) for “consumer”, wherever occurring, there is substituted “ objector ” , and
(b) for “Director”, wherever occurring, there is substituted “ the relevant authority ” .
(4) After subsection (6) of that section there is inserted—
“ (7) The Data Protection Commissioner may vary or revoke any order made by him under this section.
(8) In this section “ the relevant authority ” means—
(a) where the objector is a partnership or other unincorporated body of persons, the Director, and
(b) in any other case, the Data Protection Commissioner. ”
(5) In section 160 of that Act (alternative procedure for business consumers)—
(a) in subsection (4)—
(i) for “him” there is substituted “ to the consumer ” , and
(ii) in paragraphs (a) and (b) for “he” there is substituted “ the consumer ” and for “his” there is substituted “ the consumer’s ” , and
(b) after subsection (6) there is inserted—
“ (7) In this section “ consumer ” has the same meaning as in section 158. ”
General
63 Application to Crown.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
63A Application to Parliament.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
64 Transmission of notices etc. by electronic or other means.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
65 Service of notices by Commissioner.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
66 Exercise of rights in Scotland by children.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
67 Orders, regulations and rules.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
68 Meaning of “accessible record”.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
69 Meaning of “health professional”.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
70 Supplementary definitions.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
71 Index of defined expressions.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
72 Modifications of Act.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
73 Transitional provisions and savings.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
74 Minor and consequential amendments and repeals and revocations.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
75 Short title, commencement and extent.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
SCHEDULES
Section 4(1) and (2).
SCHEDULE 1 The data protection principles
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Section 4(3).
SCHEDULE 2 Conditions relevant for purposes of the first principle: processing of any personal data
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Section 4(3).
SCHEDULE 3 Conditions relevant for purposes of the first principle: processing of sensitive personal data
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Section 4(3).
SCHEDULE 4 Cases where the eighth principle does not apply
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Section 6(7).
SCHEDULE 5 The Data Protection Commissioner . . .
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Sections 28(12), 48(5).
SCHEDULE 6 Appeal proceedings
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Section 37.
SCHEDULE 7 Miscellaneous exemptions
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Section 39.
SCHEDULE 8 Transitional relief
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Section 50.
SCHEDULE 9 Powers of entry and inspection
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Section 53(6).
SCHEDULE 10 Further provisions relating to assistance under section 53
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Section 68(1)(6).
SCHEDULE 11 Educational records
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Section 68(1)(c).
SCHEDULE 12 Accessible public records
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Section 72.
SCHEDULE 13 Modifications of Act having effect before 24th October 2007
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Section 73.
SCHEDULE 14 Transitional provisions and savings
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Section 74(1).
SCHEDULE 15 Minor and consequential amendments
Public Records Act 1958 (c. 51)
1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Parliamentary Commissioner Act 1967 (c. 13)
2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Superannuation Act 1972 (c. 11)
4 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
House of Commons Disqualification Act 1975 (c. 24)
5 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Northern Ireland Assembly Disqualification Act 1975 (c. 25)
6 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Representation of the People Act 1983 (c. 2)
7 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Access to Medical Reports Act 1988 (c. 28)
8 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Football Spectators Act 1989 (c. 37)
9 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Education (Student Loans) Act 1990 (c. 6)
10 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Access to Health Records Act 1990 (c. 23)
11 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
12 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
13 In section 5(3) of that Act (cases where right of access may be partially excluded) for the words from the beginning to “record” in the first place where it occurs there is substituted “ Access shall not be given under section 3(2) to any part of a health record ” .
Access to Personal Files and Medical Reports (Northern Ireland) Order 1991 (1991/1707 (N.I. 14))
14 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
15 In Article 6(1) of that Order (interpretation), in the definition of “ health professional ”, for “the Data Protection (Subject Access Modification) (Health) Order 1987” there is substituted “ the Data Protection Act 1998 ” .
Tribunals and Inquiries Act 1992 (c. 53)
16 In Part 1 of Schedule 1 to the Tribunals and Inquiries Act 1992 (tribunals under direct supervision of Council on Tribunals), for paragraph 14 there is substituted—
“ Data protection | 14. (a) The Data Protection Commissioner appointed under section 6 of the Data Protection Act 1998; (b) the Data Protection Tribunal constituted under that section, in respect of its jurisdiction under section 48 of that Act. ” |
Access to Health Records (Northern Ireland) Order 1993 (1993/1250 (N.I. 4))
17 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
18 In Article 5(4) of that Order (cases where fee may be required) in sub-paragraph (a), for “the maximum prescribed under section 21 of the Data Protection Act 1984” there is substituted “ such maximum as may be prescribed for the purposes of this Article by regulations under section 7 of the Data Protection Act 1998 ” .
19 In Article 7 of that Order (cases where right of access may be partially excluded) for the words from the beginning to “record” in the first place where it occurs there is substituted “ Access shall not be given under Article 5(2) to any part of a health record ” .
Section 74(2).
SCHEDULE 16 Repeals and revocations
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .