Legislation – Data Protection Act 2018
Which version?
Latest available (Revised)
Original (As enacted)
Changes to legislation:
Data Protection Act 2018, Cross Heading: Data subject’s rights to information is up to date with all changes known to be in force on or before 09 April 2026. There are changes that may be brought into force at a future date. Changes that have been made appear in the content and are referenced with annotations.![]()
Changes to Legislation
Revised legislation carried on this site may not be fully up to date. Changes and effects are recorded by our editorial team in lists which can be found in the ‘Changes to Legislation’ area. Where those effects have yet to be applied to the text of the legislation by the editorial team they are also listed alongside the legislation in the affected provisions. Use the ‘more’ link to open the changes and effects relevant to the provision you are viewing.
Changes and effects yet to be applied to Part 3 Chapter 3 Crossheading Information-controllers-general-duties:
- s. 26(2)(f)(ai) omitted by 2025 c. 18 Sch. 10 para. 9
- s. 44(1)(da) inserted by 2025 c. 18 Sch. 10 para. 10(2)(a)
- s. 44(5)(ca) inserted by 2025 c. 18 Sch. 10 para. 10(3)(a)
- s. 45(2)(ea) inserted by 2025 c. 18 Sch. 10 para. 11(2)(a)
- s. 45(5)(ca) inserted by 2025 c. 18 Sch. 10 para. 11(3)(a)
- s. 45A(2)(ca) inserted by 2025 c. 18 Sch. 10 para. 12
- s. 48(1)(b)(iia) inserted by 2025 c. 18 Sch. 10 para. 13(2)(a)
- s. 48(4)(ba) inserted by 2025 c. 18 Sch. 10 para. 13(3)(a)
- s. 149(5A) inserted by 2025 c. 18 Sch. 10 para. 16(3)
- s. 157(4A) inserted by 2025 c. 18 Sch. 10 para. 18
- s. 187(2)(za) inserted by 2025 c. 18 Sch. 10 para. 21(3)(a)
- Sch. 3 para. 8(1)(y) added by 2022 c. 18 (N.I.) Sch. 3 para. 78(3)
Changes and effects yet to be applied to the whole Act associated Parts and Chapters:
Whole provisions yet to be inserted into this Act (including any effects on those provisions):
- s. 26(2)(f)(ai) omitted by 2025 c. 18 Sch. 10 para. 9
- s. 44(1)(da) inserted by 2025 c. 18 Sch. 10 para. 10(2)(a)
- s. 44(5)(ca) inserted by 2025 c. 18 Sch. 10 para. 10(3)(a)
- s. 45(2)(ea) inserted by 2025 c. 18 Sch. 10 para. 11(2)(a)
- s. 45(5)(ca) inserted by 2025 c. 18 Sch. 10 para. 11(3)(a)
- s. 45A(2)(ca) inserted by 2025 c. 18 Sch. 10 para. 12
- s. 48(1)(b)(iia) inserted by 2025 c. 18 Sch. 10 para. 13(2)(a)
- s. 48(4)(ba) inserted by 2025 c. 18 Sch. 10 para. 13(3)(a)
- s. 149(5A) inserted by 2025 c. 18 Sch. 10 para. 16(3)
- s. 157(4A) inserted by 2025 c. 18 Sch. 10 para. 18
- s. 187(2)(za) inserted by 2025 c. 18 Sch. 10 para. 21(3)(a)
- Sch. 3 para. 8(1)(y) added by 2022 c. 18 (N.I.) Sch. 3 para. 78(3)
PART 3Law enforcement processing
CHAPTER 3Rights of the data subject
F1Data subject’s rights to information
44F2… Controller’s general duties
(1)
The controller must make available to data subjects the following information (whether by making the information generally available to the public or in any other way)—
(a)
the identity and the contact details of the controller;
(b)
where applicable, the contact details of the data protection officer (see sections 69 to 71);
(c)
the purposes for which the controller processes personal data;
(d)
the existence of the rights of data subjects to request from the controller—
(i)
access to personal data (see section 45),
(ii)
rectification of personal data (see section 46), and
(iii)
erasure of personal data or the restriction of its processing (see section 47);
(e)
the existence of the right to lodge a complaint with the Commissioner and the contact details of the Commissioner.
(2)
The controller must also, in specific cases for the purpose of enabling the exercise of a data subject’s rights under this Part, give the data subject the following—
(a)
information about the legal basis for the processing;
(b)
information about the period for which the personal data will be stored or, where that is not possible, about the criteria used to determine that period;
(c)
where applicable, information about the categories of recipients of the personal data (including recipients in third countries or international organisations);
(d)
such further information as is necessary to enable the exercise of the data subject’s rights under this Part.
(3)
An example of where further information may be necessary as mentioned in subsection (2)(d) is where the personal data being processed was collected without the knowledge of the data subject.
(4)
The controller may restrict, wholly or partly, the provision of information to the data subject under subsection (2) to the extent that and for so long as the restriction is, having regard to the fundamental rights and legitimate interests of the data subject, a necessary and proportionate measure to—
(a)
avoid obstructing an official or legal inquiry, investigation or procedure;
(b)
avoid prejudicing the prevention, detection, investigation or prosecution of criminal offences or the execution of criminal penalties;
(c)
protect public security;
F3(d)
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
(e)
protect the rights and freedoms of others.
(5)
Where the provision of information to a data subject under subsection (2) is restricted F4under subsection (4), wholly or partly, the controller must inform the data subject in writing without undue delay—
(a)
that the provision of information has been restricted,
(b)
of the reasons for the restriction,
(c)
of the data subject’s right to make a request to the Commissioner under section 51,
(d)
of the data subject’s right to lodge a complaint with the Commissioner, and
(e)
of the data subject’s right to apply to a court under section 167.
(6)
Subsection (5)(a) and (b) do not apply to the extent that complying with them would undermine the purpose of the restriction.
(7)
The controller must—
(a)
record the reasons for a decision to restrict (whether wholly or partly) the provision of information to a data subject under subsection (2) F5in reliance on subsection (4), and
(b)
if requested to do so by the Commissioner, make the record available to the Commissioner.