1-20 of 176 results for legtitle:"Data Protection Act 2018"
Librarians' tools
- Search time
- 0.312 seconds
- Solr query time
- 0.003 seconds
- Search query
- legtitle:"Data Protection Act 2018"
- We searched for
- legislationTitle_t:"Data Protection Act 2018" OR legislationTitle_ses:446426
Type
House
Session
Year
Department
More
Member
More
Primary member
More
Answering member
More
Legislative stage
Legislation
More
Subject
More
Publisher
To ask His Majesty's Government what assessment they had made of the potential impact on privacy rights under (1) the Data Protection Act 2018, and (2) section 22 of the Gender Recognition Act 2004, prior to laying the Equality and Human Rights Commission’s draft Code of Practice for Services, Public...
To ask His Majesty's Government what assessment they had made of the potential impact on privacy rights under (1) the Data Protection Act 2018, and (2) section 22 of the Gender Recognition Act 2004, prior to laying the Equality and Human Rights Commission’s draft Code of Practice for Services, Public...
The draft Code provides a detailed explanation of the Equality Act 2010 to assist service providers, those exercising public functions, and associations in understanding and complying with their legal obligations.
Service providers must continue to pay regard to their existing duties under the Data Protection Act 2018 and the Gender Recognition Act 2004 when exercising their functions and considering how they collect and process information.
To ask the Secretary of State for Health and Social Care, what assurance mechanisms are in place to safeguard patient-identifiable data within the Federated Data Platform (FDP) operating across NHS trusts and the Integrated Care Board in Cheshire and Merseyside; and what independent audit or verification processes are undertaken to...
To ask the Secretary of State for Health and Social Care, what assurance mechanisms are in place to safeguard patient-identifiable data within the Federated Data Platform (FDP) operating across NHS trusts and the Integrated Care Board in Cheshire and Merseyside; and what independent audit or verification processes are undertaken to...
The NHS Federated Data Platform (NHS FDP) is built with robust security and privacy controls to ensure that access to National Health Service data is tightly governed and independently auditable.
The NHS FDP Information Governance Framework clearly lays out the roles and responsibilities relating to breach notification and management, defining organisations’ responsibilities in this area.
All user activity within the NHS FDP environment is logged for auditing purposes. These logs are monitored by both the suppliers platform team and the NHS Cyber Security Operations Centre to detect and respond to any malicious activity.
The NHS FDP contract includes audit provisions that allow NHS England to validate and confirm that contractual requirements are being met. These rights of audit are standard within NHS commercial agreements and provide assurance that the platform operates in accordance with NHS England’s expectations and legal obligations, including compliance with UK General Data Protection Regulation and the Data Protection Act 2018.
To ask the Secretary of State for Science, Innovation and Technology, what safeguards are in place to ensure that automated analysis by private tech companies of the content of private email complies with the UK General Data Protection Regulation and the Data Protection Act 2018.
To ask the Secretary of State for Science, Innovation and Technology, what safeguards are in place to ensure that automated analysis by private tech companies of the content of private email complies with the UK General Data Protection Regulation and the Data Protection Act 2018.
The UK’s data protection legislation applies to any processing of personal data regardless of the technology being used. Technology companies that screen or analyse personal emails must identify an appropriate legal ground for doing so, such as obtaining user consent. Personal data must also be processed fairly and transparently so that people can make informed decisions about whether to use a service.
The data protection legislation is monitored and enforced independently of government by the Information Commissioner’s Office (ICO). The ICO has published guidance for organisations on automated decision making, profiling and artificial intelligence at: Automated decision-making and profiling | ICO and Artificial intelligence | ICO. It will also consider complaints about organisations that fail to comply with the legislation.
To ask the Minister for the Cabinet Office, whether the 2017 Memorandum of Understanding between HMRC and the Cabinet Office has been updated since the introduction of the Data Protection Act 2018; and on what basis data transfers for honours probity checks continues.
To ask the Minister for the Cabinet Office, whether the 2017 Memorandum of Understanding between HMRC and the Cabinet Office has been updated since the introduction of the Data Protection Act 2018; and on what basis data transfers for honours probity checks continues.
As noted in our answer to PQ 92590, the Memorandum of Understanding between the Cabinet Office and HMRC was last updated in 2023. The Memorandum of Understanding, which is published in full on gov.uk, sets out the legal and lawful basis by which data is transferred.
The 2023 Memorandum of Understanding is available at the following link:
To ask the Secretary of State for Science, Innovation and Technology, what mechanisms are in place to ensure that UK institutions and companies comply with the GDPR, the Data Protection Act 2018, and other relevant national security requirements when sharing genomic data internationally.
To ask the Secretary of State for Science, Innovation and Technology, what mechanisms are in place to ensure that UK institutions and companies comply with the GDPR, the Data Protection Act 2018, and other relevant national security requirements when sharing genomic data internationally.
The UK has one of the most robust data protection regimes in the world, with all organisations required to comply with our legislation to safeguard UK personal data when transferring it overseas. Failure to do so can result in enforcement action.
Our data regulator, the Information Commissioner’s Office, has powers to take enforcement action and issue hefty fines. Individuals who consider that their data has been misused can also take legal action.
To ask the Secretary of State for Science, Innovation and Technology, with reference to the Data Protection Act 2018 and Article 5 of the United Kingdom General Data Protection Regulation, what assessment her Department has made of the adequacy of the safeguards to ensure that personal data gathered through the...
To ask the Secretary of State for Science, Innovation and Technology, with reference to the Data Protection Act 2018 and Article 5 of the United Kingdom General Data Protection Regulation, what assessment her Department has made of the adequacy of the safeguards to ensure that personal data gathered through the...
The Department has conducted a data protection impact assessment (DPIA) for the digital Veteran Card, approved by the One Login Senior Responsible Officer and the Department for Science, Innovation and Technology’s Data Protection Officer, in consultation with the Information Commissioner’s Office (ICO). A Data Sharing Agreement governs processing between the Ministry of Defence and the Department for Science, Innovation and Technology and ensures that data is only used for its intended and agreed purpose.
Personal data is stored locally on the veteran’s mobile device and is only shared when the veteran actively chooses to present their digital card. There is no automatic cross-government data sharing. Veterans retain full control of their data and can delete their card at any time.
To ask the Secretary of State for Defence, whether his Department cited (a) national security and (b) public interest exemptions under the Data Protection Act 2018 in relation to the Afghan data breach disclosed in 2021.
To ask the Secretary of State for Defence, whether his Department cited (a) national security and (b) public interest exemptions under the Data Protection Act 2018 in relation to the Afghan data breach disclosed in 2021.
The Ministry of Defence (MOD) reported several personal data incidents to the Information Commissioner’s Office (ICO) in 2021, under the previous administration, in which individuals seeking Afghan Relocations and Assistance Policy (ARAP) support were identified to each other by the sender using the “to” rather than the “bcc” email field.
When MOD engaged with the ICO in relation to these incidents, the Department highlighted the national security context and the ICO accepted the urgent and pressurised circumstances under which the incidents occurred, although they decided that a monetary penalty notice was still justified. The MOD cooperated extensively with the ICO in addressing these incidents, recognising the severity of what happened and working to improve compliance going forward.
Crime and Policing Bill. I. Letter dated 03/11/2025 from Lord Hanson of Flint to Lord Davies of Gower regarding Government amendments for Lords committee stage. 8p. II. Amendment papers (2 docs.). III. Supplementary delegated powers memorandum. 5p. IV. European Convention on Human Rights: Fourth supplementary memorandum by the Home Office and Ministry of Justice. 19p.
Crime and Policing Bill. I. Letter dated 03/11/2025 from Lord Hanson of Flint to Lord Davies of Gower regarding Government amendments for Lords committee stage. 8p. II. Amendment papers (2 docs.). III. Supplementary delegated powers memorandum. 5p. IV. European Convention on Human Rights: Fourth supplementary memorandum by the Home Office...
Lords motions to approve. Agreed to on question.
Lords motions to approve. Agreed to on question.
Lords motion to consider. Agreed to on question.
Lords motion to consider. Agreed to on question.
My Lords, this instrument was laid before the House on 7 July. The then Home Secretary and the current Home Secretary have exercised powers under Section 82(2A) of the Data Protection Act 2018 to specify in this instrument the qualifying competent authorities that will be able to apply for a...
My Lords, this instrument was laid before the House on 7 July. The then Home Secretary and the current Home Secretary have exercised powers under Section 82(2A) of the Data Protection Act 2018 to specify in this instrument the qualifying competent authorities that will be able to apply for a...
My Lords, this instrument is a welcome step in increasing the efficacy of our data sharing and protecting our national security interests. Until the enactment of this instrument, authorities processing information under the Data Protection Act 2018 have been subject to two separate legislative data-processing regimes for law enforcement and...
My Lords, this instrument is a welcome step in increasing the efficacy of our data sharing and protecting our national security interests. Until the enactment of this instrument, authorities processing information under the Data Protection Act 2018 have been subject to two separate legislative data-processing regimes for law enforcement and...
My Lords, I am grateful to the noble Lord, Lord Cameron of Lochiel, for his broad support for this instrument. As he mentioned, the competent authorities, which we have now specified as qualifying competent authorities, have been selected following consultation with partners operating in the area of national security. They...
My Lords, I am grateful to the noble Lord, Lord Cameron of Lochiel, for his broad support for this instrument. As he mentioned, the competent authorities, which we have now specified as qualifying competent authorities, have been selected following consultation with partners operating in the area of national security. They...
Motion that the draft Data Protection Act 2018 (Qualifying Competent Authorities) Regulations 2025, which were laid before this House on 7 July, be approved. Agreed to on question.
Motion that the draft Data Protection Act 2018 (Qualifying Competent Authorities) Regulations 2025, which were laid before this House on 7 July, be approved. Agreed to on question.
Motion to consider. Agreed to on question.
Motion to consider. Agreed to on question.
To ask the Secretary of State for Science, Innovation and Technology, whether the Government plans to publish (a) Keeling Schedules and (b) implementation dates for the changes that have not had immediate effect made by the Data (Use and Access) Act 2025 to the Data Protection Act 2018, UK GDPR...
To ask the Secretary of State for Science, Innovation and Technology, whether the Government plans to publish (a) Keeling Schedules and (b) implementation dates for the changes that have not had immediate effect made by the Data (Use and Access) Act 2025 to the Data Protection Act 2018, UK GDPR...
The Government does not plan to publish Keeling Schedules illustrating how measures in the Data (Use and Access) Act 2025 amend the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations. However, we have published information about each measure, which legislative provisions they amend, and plans for commencement dates, on GOV.UK: https://www.gov.uk/government/collections/data-use-and-access-act-2025
To ask the Secretary of State for Justice, what plans she has with Cabinet colleagues to assess the effectiveness of the right to be forgotten in the Data Protection Act 2018, in the context of people acquitted of crimes.
To ask the Secretary of State for Justice, what plans she has with Cabinet colleagues to assess the effectiveness of the right to be forgotten in the Data Protection Act 2018, in the context of people acquitted of crimes.