What is the difference between UK GDPR and the Data Protection Act 2018?
They work together rather than compete. UK GDPR sets the principles, the rights and the obligations that apply when personal data is processed. The Data Protection Act 2018 supplements it, applies the exemptions, and covers what the regulation leaves to national law, including law enforcement processing.
Compliance means meeting both, which is why this course treats them as one subject across its eight modules.
What are the seven data protection principles?
UK GDPR sets seven: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. The first six describe how personal data has to be handled. Accountability is the one that catches organisations out, because it requires you to demonstrate compliance rather than simply achieve it.
Records, policies and training logs are what that demonstration looks like when the ICO asks to see it.
What are the lawful bases for processing personal data?
Six bases exist under UK GDPR: consent, contract, legal obligation, vital interests, public task and legitimate interests. You pick one before processing begins, record the choice, and set it out in your privacy notice. Swapping basis part way through is difficult, so the decision belongs at the start.
Consent is the most misused of the six. It has to be freely given, specific, informed, unambiguous, and as easy to withdraw as it was to give. A pre-ticked box fails that test, and so does making a service conditional on consent to processing the service does not actually need.
How quickly does a data breach have to be reported?
A personal data breach that is likely to pose a risk to people’s rights and freedoms must be reported to the Information Commissioner’s Office within 72 hours of the organisation becoming aware of it, where feasible. Every breach gets documented internally either way, and where the risk is high the affected individuals have to be told without undue delay too.
Most staff will never file that report themselves. Recognising that a lost laptop, a misdirected email or an unlocked filing cabinet might be a breach, and flagging it quickly so the right person can judge the risk, is the part that depends on training.
What rights do people have over their data?
Eight rights: to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and rights relating to automated decision making and profiling. A subject access request can arrive by email, over the phone or inside a complaint letter. The one-month response clock runs from receipt, though it can pause while identity is confirmed or a reasonably required clarification is answered.
Most requests land on an ordinary member of staff long before they reach anyone with data protection in their job title.
Who should take a UK GDPR course?
Anyone who handles personal data at work: HR, finance, reception, marketing, care and support staff, and the managers deciding what gets collected and how long it is kept. The ICO expects staff training as part of an organisation’s accountability measures and can ask what training was in place after an incident.
The course takes two to three hours and ends with a CPD accredited certificate. If you are arranging this for a whole team, the guide to GDPR training for employees covers frequency and record keeping.