- Section 55Overview and scope
(1) This Chapter— (a) sets out the general obligations of controllers and processors (see sections 56 to 65 ); (b) sets out specific obligations of controllers and processors…
- Section 56General obligations of the controller
(1) Each controller must implement appropriate technical and organisational measures to ensure, and to be able to demonstrate, that the processing of personal data complies with the requirements…
- Section 57Data protection by design and default
(1) Each controller must implement appropriate technical and organisational measures which are designed— (a) to implement the data protection principles in an effective manner, and (b) to integrate…
- Section 58Joint controllers
(1) Where two or more competent authorities jointly determine the purposes and means of processing personal data, they are joint controllers for the purposes of this Part. (2)…
- Section 59Processors
(1) This section applies to the use by a controller of a processor to carry out processing of personal data on behalf of the controller. (2) The controller…
- Section 60Processing under the authority of the controller or processor
A processor, and any person acting under the authority of a controller or processor, who has access to personal data may not process the data except— (a) on…
- Section 61Records of processing activities
(1) Each controller must maintain a record of all categories of processing activities for which the controller is responsible. (2) The controller's record must contain the following information—…
- Section 62Logging
(1) A controller (or, where personal data is processed on behalf of the controller by a processor, the processor) must keep logs for at least the following processing…
- Section 63Co-operation with the Commission
Each controller and each processor must co-operate, on request, with the Commission in the performance of the Commission's tasks.
- Section 64Data protection impact assessment
(1) Where a type of processing is likely to result in a high risk to the rights and freedoms of individuals, the controller must, prior to the processing,…
- Section 65Prior consultation with the Commission
(1) This section applies where a controller intends to create a filing system and process personal data forming part of it. (2) The controller must consult the Commission…
- Section 66Security of processing
(1) Each controller and each processor must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risks arising from the processing of…
- Section 67Notification of a personal data breach to the Commission
(1) If a controller becomes aware of a personal data breach in relation to personal data for which the controller is responsible, the controller must notify the breach…
- Section 68Communication of a personal data breach to the data subject
(1) Where a personal data breach is likely to result in a high risk to the rights and freedoms of individuals, the controller must inform the data subject…
- Section 69Designation of a data protection officer
(1) The controller must designate a data protection officer, unless the controller is a court, or other judicial authority, acting in its judicial capacity. (2) When designating a…
- Section 70Position of data protection officer
(1) The controller must ensure that the data protection officer is involved, properly and in a timely manner, in all issues which relate to the protection of personal…
- Section 71Tasks of data protection officer
(1) The controller must entrust the data protection officer with at least the following tasks— (a) informing and advising the controller, any processor engaged by the controller, and…
- Section 71ACodes of conduct
(1) The Commission must encourage expert public bodies to produce codes of conduct intended to contribute to compliance with this Part. (2) Under subsection (1) , the Commission…
https://dpa2018.digiphile.law/part/part-3-chapter-4.html
Text as at 18 September 2026.
This is an unofficial convenience version of the Data Protection Act 2018. It is presented “as is” without guarantee of accuracy, completeness or reliability. See the source text for the official version. This site was last updated in September 2026.