Data Protection Act 2018UK · 2018 c. 12
Digiphile

Sections

Section 56General obligations of the controller

(1) Each controller must implement appropriate technical and organisational measures to ensure, and to be able to demonstrate, that the processing of personal data complies with the requirements of this Part.
(2) Where proportionate in relation to the processing, the measures implemented to comply with the duty under subsection (1) must include appropriate data protection policies.
(3) The technical and organisational measures implemented under subsection (1) must be reviewed and updated where necessary.
(4) [F1 Adherence to a code of conduct approved under section 71A may be used by a controller as a means of demonstrating compliance with the requirements of this Part.]

Amended text

This Section is shown as amended by the Data (Use and Access) Act 2025 (c. 18), among other instruments (see the annotations below) (commenced provisions as at 30 September 2026, ELI), as incorporated in the text in force on 30 September 2026 as published on legislation.gov.uk.

Annotations

Textual Amendments

  1. F1 S. 56(4) inserted (20.8.2025) by Data (Use and Access) Act 2025 (c. 18), ss. 84(3), 142(1); S.I. 2025/904, reg. 2(d)

Commencement Information

  1. I1 S. 56 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)