Data Protection Act 2018: Practical Guidance for Businesses

Does your business conduct staff background checks or handle sensitive operational data? While the UK GDPR sets general privacy frameworks, the Data Protection Act 2018 establishes the specific UK statutes governing criminal record processing, employment records and regulatory enforcement. Privacy Helper delivers expert corporate compliance audits to align your internal practices with national data laws and safeguard your enterprise.

Speak to an expert
01234 923643

Hippodrome Casino London Logo
Rocco Forte Hotels Logo
Bedfordshire Chamber of Commerce Logo
Hippodrome Casino London Logo
Hippodrome Casino London Logo
PMDSC Logo
SwiftComm Logo
iCabbi Logo
The Kemnal Academies Trust Logo

Book a free consultation to discuss the act in more detail.

About The Data Protection Act 2018

The Data Protection Act (DPA) 2018 is the complete national statute that updates and replaces the historic 1998 framework. It was passed to apply the rules of the GDPR directly into UK law while setting out specific national exceptions and rules that apply exclusively within the United Kingdom.

For business owners, the DPA 2018 is highly critical because it controls the legalities of the modern workplace. It defines exactly how employers must manage staff records, health data and background checks. Operating without an understanding of the DPA 2018 leaves your business exposed to immediate employment disputes and regulatory penalties.

Key national provisions businesses need to know

The most vital element of the DPA 2018 for commercial entities is its control over special category data and criminal conviction history. The UK GDPR bans the processing of criminal offence data unless authorised by domestic law. The DPA 2018 provides that authorisation through Schedule 1, setting out strict conditions under which a business can legally process background checks for recruitment.

Additionally, the Act officially sets out the legal powers of the Information Commissioner. It grants the regulator the statutory authority to enter business premises, audit electronic systems, issue formal enforcement notices and levy administrative fines. The DPA 2018 is the legal mechanism that turns privacy guidelines into enforceable corporate liabilities.

What organisations must do in practice

Aligning your corporate practices with the DPA 2018 requires establishing specific internal policies that protect both consumer and employee data assets.

At a minimum, your organisation should:

  • Implement an Appropriate Policy Document (APD) to legally justify processing staff health or criminal background data
  • Update your employee privacy notices to detail how staff information is managed throughout the employment lifecycle
  • Review your recruitment screening workflows to verify that criminal record checks satisfy a valid Schedule 1 condition
  • Establish clear data retention schedules to ensure old job applications and staff files are securely destroyed

Who it applies to

The statutory bounds of the DPA 2018 mirror the broad scope of general data protection rules, impacting every employer and trading entity in the UK. Reviewing your compliance framework is necessary if your business:

  • Conducts Disclosure and Barring Service (DBS) checks during recruitment
  • Collects staff sickness records, occupational health reports or drug testing data
  • Manages corporate security infrastructures, including workplace CCTV or building access logs
  • Interacts with UK law enforcement agencies regarding fraud prevention or data disclosures

Risks of non-compliance and regulatory enforcement

Failing to meet the standards of the DPA 2018 carries severe financial penalties that match maximum UK GDPR tiers. Processing employee background checks or health data without a valid legal gateway is a major infraction, risking fines of up to £17.5 million or 4% of global annual turnover.

Beyond financial risk, a DPA 2018 breach frequently triggers devastating employment tribunals. If an employee discovers their sensitive health or disciplinary files were processed unlawfully without a proper policy document in place, your business faces substantial civil compensation claims alongside public reputational damage.

How Privacy Helper protects your enterprise

Privacy Helper eliminates the complexity of domestic data laws. We work alongside your human resources teams and legal counsel to draft mandatory Appropriate Policy Documents, build secure staff data management workflows and audit your recruitment screening processes.

Our data protection specialists ensure your internal systems satisfy both general UK GDPR rules and specific DPA 2018 national statutes, protecting your brand from costly internal disputes and regulatory action.

Next steps

Managing employee information and background screening without robust domestic policies creates an unmanaged corporate liability. Securing your workforce infrastructure requires specialised, professional intervention.

To evaluate your DPA 2018 alignment and deploy a defensible workplace privacy strategy, contact the expert team at Privacy Helper today.

Our Contributors

Andy Chesterman

Andy Chesterman

As co-founder of Privacy Helper, I regularly contribute and provide comment in articles publications and journals on privacy matters. I am also a member of the Betting & Gaming Council’s Working Group on Live Facial Recognition.

Dan Brooks-Tonkin

Dan Brooks-Tonkin

I am a full-time Data Protection Consultant at Privacy Helper, supporting organisations to understand their data protection obligations and implement clear and effective compliance solutions.

Non-compliance Cases

DPA 2018 Specific FAQs

What is an Appropriate Policy Document and do we need one?

An Appropriate Policy Document (APD) is a short internal statement that a business must maintain under the DPA 2018 when processing special category or criminal offence data for employment purposes. The document must outline your legal basis for handling the data and detail your procedures for ensuring compliance with core data principles. Failing to maintain an active APD makes your processing of staff health or background checks entirely unlawful.

Can a business perform criminal record checks on all job applicants?

No. Under the DPA 2018, you cannot systematically run criminal background checks on every applicant as a blanket rule. You must possess a specific legal justification or statutory duty to request this data, such as recruiting for roles in financial services, healthcare, education or positions of trust. Your recruitment workflows must clearly document the exact Schedule 1 condition being relied upon before a check is executed.

How does the DPA 2018 affect workplace CCTV monitoring?

The Act dictates that workplace surveillance must be proportionate, transparent and justifiable. If your business deploys CCTV, you must place clear signage across your premises informing staff and visitors that recording is active. You must also complete a Data Protection Impact Assessment (DPIA) to prove that the monitoring does not cause an unnecessary intrusion into individual privacy rights.

Does the Act allow businesses to share data with the police without a warrant?

Yes, under specific exemptions set out in Schedule 2 of the Act. Private businesses can legally disclose personal data to law enforcement without individual consent if the disclosure is strictly necessary for the prevention or detection of crime, or the apprehension of offenders. However, your compliance team must formally assess each request to verify that releasing the data is entirely proportionate to the situation before handing it over.

Speak to us About the Data Protection Act 2018 Today!

Phone Number
01234 923643