The Data Protection Act, ten years on
As the UK’s main data security law turns ten, IT vendors and lawyers question if it’s still fit for purpose in today’s increasingly networked world.


The Data Protection Act (DPA) 1998 is ten years old today. Originally created to safeguard our personal information, some have questioned whether it is still fit for purpose.
The question is particularly pertinent, coming only a day after the The Office of the Information Commissioner (ICO) launched a scathing attack on government database expansion plans, following a series of high profile UK public and private sector data losses and rising online ID theft.
Jamie Cowper, marketing director (EMEA) at data protection specialist PGP Corporation, said it was difficult not to break data security laws in a world of electronic information that has changed almost completely since the act was enacted.
"The sheer proliferation of data within both public and private sector organisations in terms of stored records and transactions is mind-boggling," Cowper said. "As a result, I'd be surprised if nearly all companies aren't in some way contravening the act as it currently stands, whether they realise it or not."
He added: "The increased reporting of data loss incidents from missing CDs to hacked databases has simply shown how lax many organisations have become in following the guidelines laid out by the Act. If the DPA is to be of use in reducing such incidents, it must be positioned as a visible deterrent with punitive powers."
Cowper, like many others, said the DPA was a good step in the right direction, and has definitely done a lot to raise awareness of how consumers' personal information is used and sometimes abused by organisations. "However, it has perhaps been less effective in penalising those companies that have mishandled data, with, for instance, permission for inspections needed before any action can be taken," he said.
Dai Davis, partner at law firm Brooke North agreed the DPA was not fit for purpose. But he said the recent addition of criminal penalties for failing to comply with an ICO enforcement notice - such as those issued to Her Majesty's Revenue and Customs (HMRC) and the Ministry of Defence (MoD) yesterday - was a step in the right direction towards giving the law some teeth.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"The use of data and its value is manifestly greater than it was ten years ago and will continue to increase in importance over the next ten years," he said. "I think what we're seeing, with the Information Commissioner more willing to use his enforcement powers now there's some clout behind them, is good."
But Davis added: "We also need to give the authorities charged with investigating the crimes of data abuse, like the former Hi-Tech Crime Unit, much more funding."
The ICO told IT PRO: "The Data Protection Act has a crucial role in ensuring our personal information is effectively protected. It requires organisations to ensure that our personal information is stored and processed securely, that it is accurate and up to date and that it is not kept for longer than is necessary.
"Recent security breaches have reinforced the importance of data protection and we continue to urge the public and private sectors to take data protection seriously or risk losing the confidence and trust of individuals."
"It is equally important that individuals understand the value of their personal details and take appropriate steps to protect them. The Act gives us all important rights and protection in an age where more and more of our personal information is being collected and traded," the watchdog said.
A 25-year veteran enterprise technology expert, Miya Knights applies her deep understanding of technology gained through her journalism career to both her role as a consultant and as director at Retail Technology Magazine, which she helped shape over the past 17 years. Miya was educated at Oxford University, earning a master’s degree in English.
Her role as a journalist has seen her write for many of the leading technology publishers in the UK such as ITPro, TechWeekEurope, CIO UK, Computer Weekly, and also a number of national newspapers including The Times, Independent, and Financial Times.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
ICO admits it's too slow dealing with complaints – so it's eying up automation to cut staff workloads
News The UK's data protection authority has apologized for being slow to respond to data protection complaints, saying it's been overwhelmed by increased workloads.
By Emma Woollacott
-
AI recruitment tools are still a privacy nightmare – here's how the ICO plans to crack down on misuse
News The ICO has issued guidance for recruiters and AI developers after finding that many are mishandling data
By Emma Woollacott
-
“You must do better”: Information Commissioner John Edwards calls on firms to beef up support for data breach victims
News Companies need to treat victims with swift, practical action, according to the ICO
By Emma Woollacott
-
LinkedIn backtracks on AI training rules after user backlash
News UK-based LinkedIn users will now get the same protections as those elsewhere in Europe
By Emma Woollacott
-
UK's data protection watchdog deepens cooperation with National Crime Agency
News The two bodies want to improve the support given to organizations experiencing cyber attacks and ransomware recovery
By Emma Woollacott
-
ICO slams Electoral Commission over security failures
News The Electoral Commission has been reprimanded for poor security practices, including a failure to install security updates and weak password policies
By Emma Woollacott
-
Disgruntled ex-employees are using ‘weaponized’ data subject access requests to pester firms
News Some disgruntled staff are using DSARs as a means to pressure former employers into a financial settlement
By Emma Woollacott
-
ICO reprimands Coventry school over repeated data protection failures
News The ICO said the academy trust failed to follow previous guidance, which caused a serious data breach
By Emma Woollacott