Legislation – Data Protection Act 2018
Changes to legislation:
Data Protection Act 2018, Paragraph 58 is up to date with all changes known to be in force on or before 09 April 2026. There are changes that may be brought into force at a future date. Changes that have been made appear in the content and are referenced with annotations.![]()
Changes to Legislation
Revised legislation carried on this site may not be fully up to date. Changes and effects are recorded by our editorial team in lists which can be found in the ‘Changes to Legislation’ area. Where those effects have yet to be applied to the text of the legislation by the editorial team they are also listed alongside the legislation in the affected provisions. Use the ‘more’ link to open the changes and effects relevant to the provision you are viewing.
Changes and effects yet to be applied to Schedule 19 Paragraph 58:
- s. 26(2)(f)(ai) omitted by 2025 c. 18 Sch. 10 para. 9
- s. 44(1)(da) inserted by 2025 c. 18 Sch. 10 para. 10(2)(a)
- s. 44(5)(ca) inserted by 2025 c. 18 Sch. 10 para. 10(3)(a)
- s. 45(2)(ea) inserted by 2025 c. 18 Sch. 10 para. 11(2)(a)
- s. 45(5)(ca) inserted by 2025 c. 18 Sch. 10 para. 11(3)(a)
- s. 45A(2)(ca) inserted by 2025 c. 18 Sch. 10 para. 12
- s. 48(1)(b)(iia) inserted by 2025 c. 18 Sch. 10 para. 13(2)(a)
- s. 48(4)(ba) inserted by 2025 c. 18 Sch. 10 para. 13(3)(a)
- s. 149(5A) inserted by 2025 c. 18 Sch. 10 para. 16(3)
- s. 157(4A) inserted by 2025 c. 18 Sch. 10 para. 18
- s. 187(2)(za) inserted by 2025 c. 18 Sch. 10 para. 21(3)(a)
- Sch. 3 para. 8(1)(y) added by 2022 c. 18 (N.I.) Sch. 3 para. 78(3)
Changes and effects yet to be applied to the whole Act associated Parts and Chapters:
Whole provisions yet to be inserted into this Act (including any effects on those provisions):
- s. 26(2)(f)(ai) omitted by 2025 c. 18 Sch. 10 para. 9
- s. 44(1)(da) inserted by 2025 c. 18 Sch. 10 para. 10(2)(a)
- s. 44(5)(ca) inserted by 2025 c. 18 Sch. 10 para. 10(3)(a)
- s. 45(2)(ea) inserted by 2025 c. 18 Sch. 10 para. 11(2)(a)
- s. 45(5)(ca) inserted by 2025 c. 18 Sch. 10 para. 11(3)(a)
- s. 45A(2)(ca) inserted by 2025 c. 18 Sch. 10 para. 12
- s. 48(1)(b)(iia) inserted by 2025 c. 18 Sch. 10 para. 13(2)(a)
- s. 48(4)(ba) inserted by 2025 c. 18 Sch. 10 para. 13(3)(a)
- s. 149(5A) inserted by 2025 c. 18 Sch. 10 para. 16(3)
- s. 157(4A) inserted by 2025 c. 18 Sch. 10 para. 18
- s. 187(2)(za) inserted by 2025 c. 18 Sch. 10 para. 21(3)(a)
- Sch. 3 para. 8(1)(y) added by 2022 c. 18 (N.I.) Sch. 3 para. 78(3)
SCHEDULE 19Minor and consequential amendments
PART 1Amendments of primary legislation
Freedom of Information Act 2000 (c. 36)
58
(1)
Section 40 (personal information) is amended as follows.
(2)
In subsection (2)—
(a)
in paragraph (a), for “do” substitute “
, and
does
”
(b)
in paragraph (b), for “either the first or the second” substitute “
.
the first, second or third
”
(3)
“(3A)
The first condition is that the disclosure of the information to a member of the public otherwise than under this Act—
(a)
would contravene any of the data protection principles, or
(b)
would do so if the exemptions in section 24(1) of the Data Protection Act 2018 (manual unstructured data held by public authorities) were disregarded.
(3B)
The second condition is that the disclosure of the information to a member of the public otherwise than under this Act would contravene Article 21 of the GDPR (general processing: right to object to processing).”
(4)
“(4A)
The third condition is that—
(a)
on a request under Article 15(1) of the GDPR (general processing: right of access by the data subject) for access to personal data, the information would be withheld in reliance on provision made by or under section 15, 16 or 26 of, or Schedule 2, 3 or 4 to, the Data Protection Act 2018, or
(b)
on a request under section 45(1)(b) of that Act (law enforcement processing: right of access by the data subject), the information would be withheld in reliance on subsection (4) of that section.”
(5)
“(5A)
The duty to confirm or deny does not arise in relation to information which is (or if it were held by the public authority would be) exempt information by virtue of subsection (1).
(5B)
The duty to confirm or deny does not arise in relation to other information if or to the extent that any of the following applies—
(a)
giving a member of the public the confirmation or denial that would have to be given to comply with section 1(1)(a)—
(i)
would (apart from this Act) contravene any of the data protection principles, or
(ii)
would do so if the exemptions in section 24(1) of the Data Protection Act 2018 (manual unstructured data held by public authorities) were disregarded;
(b)
giving a member of the public the confirmation or denial that would have to be given to comply with section 1(1)(a) would (apart from this Act) contravene Article 21 of the GDPR (general processing: right to object to processing);
(c)
on a request under Article 15(1) of the GDPR (general processing: right of access by the data subject) for confirmation of whether personal data is being processed, the information would be withheld in reliance on a provision listed in subsection (4A)(a);
(d)
on a request under section 45(1)(a) of the Data Protection Act 2018 (law enforcement processing: right of access by the data subject), the information would be withheld in reliance on subsection (4) of that section.”
(6)
Omit subsection (6).
(7)
“(7)
In this section—
“the data protection principles” means the principles set out in—
(a)
Article 5(1) of the GDPR, and
(b)
section 34(1) of the Data Protection Act 2018;
“data subject” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);
“the GDPR”, “personal data”, “processing” and references to a provision of Chapter 2 of Part 2 of the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(2), (4), (10), (11) and (14) of that Act).
(8)
In determining for the purposes of this section whether the lawfulness principle in Article 5(1)(a) of the GDPR would be contravened by the disclosure of information, Article 6(1) of the GDPR (lawfulness) is to be read as if the second sub-paragraph (disapplying the legitimate interests gateway in relation to public authorities) were omitted.”