Search Legislation

Data Protection Act 2018

 Help about what version

What Version

 Help about advanced features

Advanced Features

 Help about opening options

Opening OptionsExpand opening options

Changes over time for: Cross Heading: Definitions

 Help about opening options

Alternative versions:

Changes to legislation:

Data Protection Act 2018, Cross Heading: Definitions is up to date with all changes known to be in force on or before 25 February 2025. There are changes that may be brought into force at a future date. Changes that have been made appear in the content and are referenced with annotations. Help about Changes to Legislation

DefinitionsU.K.

83Meaning of “controller” and “processor”U.K.

(1)In this Part, “controller” means the intelligence service which, alone or jointly with others—

(a)determines the purposes and means of the processing of personal data, or

(b)is the controller by virtue of subsection (2).

(2)Where personal data is processed only—

(a)for purposes for which it is required by an enactment to be processed, and

(b)by means by which it is required by an enactment to be processed,

the intelligence service on which the obligation to process the data is imposed by the enactment (or, if different, one of the enactments) is the controller.

(3)In this Part, “processor” means any person who processes personal data on behalf of the controller (other than a person who is an employee of the controller).

84Other definitionsU.K.

(1)This section defines other expressions used in this Part.

(2)Consent”, in relation to the processing of personal data relating to an individual, means a freely given, specific, informed and unambiguous indication of the individual's wishes by which the individual, by a statement or by a clear affirmative action, signifies agreement to the processing of the personal data.

(3)Employee”, in relation to any person, includes an individual who holds a position (whether paid or unpaid) under the direction and control of that person.

(4)Personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

(5)Recipient”, in relation to any personal data, means any person to whom the data is disclosed, whether a third party or not, but it does not include a person to whom disclosure is or may be made in the framework of a particular inquiry in accordance with the law.

(6)Restriction of processing” means the marking of stored personal data with the aim of limiting its processing for the future.

(7)Sections 3 and 205 include definitions of other expressions used in this Part.

Back to top

Options/Help

You have chosen to open The Whole Act without Schedules

The Whole Act without Schedules you have selected contains over 200 provisions and might take some time to download. You may also experience some issues with your browser, such as an alert box that a script is taking a long time to run.

Would you like to continue?

You have chosen to open The Whole Act without Schedules as a PDF

The Whole Act without Schedules you have selected contains over 200 provisions and might take some time to download.

Would you like to continue?