Learning 1 – Understanding UK Data Protection Law
1. Section 1: Understanding UK data protection law
Section 1: Understanding UK data protection law
Legal foundations, key definitions and organisational roles.
Learning outcomes
By the end of this section, you should be able to:
- describe the relationship between the UK GDPR and the Data Protection Act 2018;
- explain the purpose of the Data (Use and Access) Act 2025 amendments;
- identify personal data, special category data and criminal offence data; and
- distinguish between a controller, processor and data subject.
Why this matters
Organisations use personal information to deliver services, employ staff, communicate with customers, protect people and make decisions. Poor handling can cause identity theft, discrimination, distress, financial loss, physical risk and loss of trust.
Core idea: Data protection is not about preventing the use of personal data. It is about using it responsibly, transparently, securely and for justified purposes.
Section learning route
- Learn how the current legal framework fits together.
- Recognise the different categories of data.
- Understand who decides how data is used.
- Apply the definitions to realistic workplace examples.
Official reference points
- GOV.UK: The UK's data protection legislation
- legislation.gov.uk: Data Protection Act 2018
- legislation.gov.uk: Data (Use and Access) Act 2025
- ICO: UK GDPR guidance and resources
Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.