Data Protection Act 2018 (c. 12) – Section 66 – Security of processing
Sections
Section 66Security of processing
(1) Each controller and each processor must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risks arising from the processing of personal data.
(2) In the case of automated processing, each controller and each processor must, following an evaluation of the risks, implement measures designed to—
- (a)prevent unauthorised processing or unauthorised interference with the systems used in connection with it,
- (b)ensure that it is possible to establish the precise details of any processing that takes place,
- (c)ensure that any systems used in connection with the processing function properly and may, in the case of interruption, be restored, and
- (d)ensure that stored personal data cannot be corrupted if a system used in connection with the processing malfunctions.
(3) [F1 Adherence to a code of conduct approved under section 71A may be used by a controller or processor as a means of demonstrating compliance with subsection (1).]
Amended text
This Section is shown as amended by the Data (Use and Access) Act 2025 (c. 18), among other instruments (see the annotations below) (commenced provisions as at 30 September 2026, ELI), as incorporated in the text in force on 30 September 2026 as published on legislation.gov.uk.
Annotations
Textual Amendments
- F1 S. 66(3) inserted (20.8.2025) by Data (Use and Access) Act 2025 (c. 18), ss. 84(5), 142(1); S.I. 2025/904, reg. 2(d)
Commencement Information
- I1 S. 66 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
https://dpa2018.digiphile.law/article/article-66.html
Text as at 18 September 2026.
This is an unofficial convenience version of the Data Protection Act 2018. It is presented “as is” without guarantee of accuracy, completeness or reliability. See the source text for the official version. This site was last updated in September 2026.