The DPA, or Data Protection Act 2018, is the piece of UK law that sits alongside UK GDPR and sets out how organisations must handle personal data. If you run a business that holds customer names, employee records, supplier details, or anything else that identifies a living person, this law applies to you, whatever your size, though what counts as reasonable practice will differ depending on your size and the risk involved.

What The DPA Actually Covers

The Data Protection Act 2018 sets the rules for how personal data gets collected, stored, used, and shared in the UK. It works alongside UK GDPR rather than replacing it, filling in detail on areas like law enforcement processing, national security, and how the Information Commissioner’s Office (ICO) can investigate and enforce breaches. For most businesses, the practical effect is the same regardless of which document you point to: you need a lawful reason to hold someone’s data, you need to be clear about what you’re doing with it, and you need to keep it secure.

Codes Of Practice And What They Mean For You

One part of the law that often gets missed is the provision for codes of practice, set out in sections 121 to 128 of the Data Protection Act 2018. These sections require the Information Commissioner to prepare codes covering specific areas of practice, including data sharing, direct marketing, and age-appropriate design for services used by children, which then get laid before Parliament. In plain terms, this means the ICO doesn’t just publish generic advice. It produces detailed, sector-specific guidance that carries real regulatory weight. If a code exists that touches on how your business handles data, you should treat it as close to a rulebook rather than a suggestion.

Lawful Basis, Not Just Consent

A common misunderstanding is that asking for consent solves every data protection question. Consent is only one of several lawful bases you can rely on, alongside others such as contractual necessity, legal obligation, or legitimate interests. Which one applies depends on what you’re doing with the data and why. A payroll system processing employee salaries, for instance, doesn’t need consent because it’s necessary to fulfil a contract. Getting this wrong, or defaulting to consent when another basis fits better (or worse), creates unnecessary friction and can leave you exposed if a regulator asks you to justify your approach.

Where Security Obligations Fit In

The law doesn’t just tell you what you can do with data, it tells you to protect it properly once you’re holding it. That means having sensible technical and organisational measures in place, appropriate to the size of your business and the sensitivity of what you’re storing. For many small and medium businesses, a good starting point is a recognised framework like Cyber Essentials, which demonstrates a baseline level of security hygiene without requiring a huge compliance budget. It’s also worth knowing that NIS2 doesn’t apply directly to UK-only businesses, but it can reach you through EU customers or supply chains that are required to pass its obligations down contractually, and the UK’s own Cyber Security and Resilience Bill is working through Parliament as the more direct domestic equivalent to watch.

Getting Practical Help Without Overspending

Working out exactly what the DPA requires for your specific business, rather than in general terms, often needs an outside pair of eyes. Not every business needs a full-time compliance officer, but most benefit from a proper review at some point, particularly if you’re handling sensitive data, expanding into new markets, or have never formally assessed your data protection posture. If you’re not sure where to start, there’s a decent breakdown of how to find cyber security consultancy services that’s worth reading before you commit to anyone, since the market varies wildly in price and quality.

If you’re ready to get a clearer picture of where your business stands, start with a straightforward Cyber Essentials assessment and build from there.