Legislation – Data Protection Act 2018
Changes to legislation:
Data Protection Act 2018, Section 57 is up to date with all changes known to be in force on or before 06 April 2026. There are changes that may be brought into force at a future date. Changes that have been made appear in the content and are referenced with annotations.![]()
Changes to Legislation
Revised legislation carried on this site may not be fully up to date. Changes and effects are recorded by our editorial team in lists which can be found in the ‘Changes to Legislation’ area. Where those effects have yet to be applied to the text of the legislation by the editorial team they are also listed alongside the legislation in the affected provisions. Use the ‘more’ link to open the changes and effects relevant to the provision you are viewing.
Changes and effects yet to be applied to Section 57:
- s. 26(2)(f)(ai) omitted by 2025 c. 18 Sch. 10 para. 9
- s. 44(1)(da) inserted by 2025 c. 18 Sch. 10 para. 10(2)(a)
- s. 44(5)(ca) inserted by 2025 c. 18 Sch. 10 para. 10(3)(a)
- s. 45(2)(ea) inserted by 2025 c. 18 Sch. 10 para. 11(2)(a)
- s. 45(5)(ca) inserted by 2025 c. 18 Sch. 10 para. 11(3)(a)
- s. 45A(2)(ca) inserted by 2025 c. 18 Sch. 10 para. 12
- s. 48(1)(b)(iia) inserted by 2025 c. 18 Sch. 10 para. 13(2)(a)
- s. 48(4)(ba) inserted by 2025 c. 18 Sch. 10 para. 13(3)(a)
- s. 149(5A) inserted by 2025 c. 18 Sch. 10 para. 16(3)
- s. 157(4A) inserted by 2025 c. 18 Sch. 10 para. 18
- s. 187(2)(za) inserted by 2025 c. 18 Sch. 10 para. 21(3)(a)
- Sch. 3 para. 8(1)(y) added by 2022 c. 18 (N.I.) Sch. 3 para. 78(3)
Changes and effects yet to be applied to the whole Act associated Parts and Chapters:
Whole provisions yet to be inserted into this Act (including any effects on those provisions):
- s. 26(2)(f)(ai) omitted by 2025 c. 18 Sch. 10 para. 9
- s. 44(1)(da) inserted by 2025 c. 18 Sch. 10 para. 10(2)(a)
- s. 44(5)(ca) inserted by 2025 c. 18 Sch. 10 para. 10(3)(a)
- s. 45(2)(ea) inserted by 2025 c. 18 Sch. 10 para. 11(2)(a)
- s. 45(5)(ca) inserted by 2025 c. 18 Sch. 10 para. 11(3)(a)
- s. 45A(2)(ca) inserted by 2025 c. 18 Sch. 10 para. 12
- s. 48(1)(b)(iia) inserted by 2025 c. 18 Sch. 10 para. 13(2)(a)
- s. 48(4)(ba) inserted by 2025 c. 18 Sch. 10 para. 13(3)(a)
- s. 149(5A) inserted by 2025 c. 18 Sch. 10 para. 16(3)
- s. 157(4A) inserted by 2025 c. 18 Sch. 10 para. 18
- s. 187(2)(za) inserted by 2025 c. 18 Sch. 10 para. 21(3)(a)
- Sch. 3 para. 8(1)(y) added by 2022 c. 18 (N.I.) Sch. 3 para. 78(3)
PART 3Law enforcement processing
CHAPTER 4Controller and processor
General obligations
57Data protection by design and default
(1)
Each controller must implement appropriate technical and organisational measures which are designed—
(a)
to implement the data protection principles in an effective manner, and
(b)
to integrate into the processing itself the safeguards necessary for that purpose.
(2)
The duty under subsection (1) applies both at the time of the determination of the means of processing the data and at the time of the processing itself.
(3)
Each controller must implement appropriate technical and organisational measures for ensuring that, by default, only personal data which is necessary for each specific purpose of the processing is processed.
(4)
The duty under subsection (3) applies to—
(a)
the amount of personal data collected,
(b)
the extent of its processing,
(c)
the period of its storage, and
(d)
its accessibility.
(5)
In particular, the measures implemented to comply with the duty under subsection (3) must ensure that, by default, personal data is not made accessible to an indefinite number of people without an individual’s intervention.