Data Protection Act 2018 (c. 12) – Section 56 – General obligations of the controller
Sections
Section 56General obligations of the controller
(1) Each controller must implement appropriate technical and organisational measures to ensure, and to be able to demonstrate, that the processing of personal data complies with the requirements of this Part.
(2) Where proportionate in relation to the processing, the measures implemented to comply with the duty under subsection (1) must include appropriate data protection policies.
(3) The technical and organisational measures implemented under subsection (1) must be reviewed and updated where necessary.
(4) [F1 Adherence to a code of conduct approved under section 71A may be used by a controller as a means of demonstrating compliance with the requirements of this Part.]
Amended text
This Section is shown as amended by the Data (Use and Access) Act 2025 (c. 18), among other instruments (see the annotations below) (commenced provisions as at 30 September 2026, ELI), as incorporated in the text in force on 30 September 2026 as published on legislation.gov.uk.
Annotations
Textual Amendments
- F1 S. 56(4) inserted (20.8.2025) by Data (Use and Access) Act 2025 (c. 18), ss. 84(3), 142(1); S.I. 2025/904, reg. 2(d)
Commencement Information
- I1 S. 56 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
https://dpa2018.digiphile.law/article/article-56.html
Text as at 18 September 2026.
This is an unofficial convenience version of the Data Protection Act 2018. It is presented “as is” without guarantee of accuracy, completeness or reliability. See the source text for the official version. This site was last updated in September 2026.