Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

Data Protection Act 2018 in Health and Social Care Research

How the UK Data Protection Act 2018 works alongside UK GDPR to govern health and social care research: special category conditions under Schedule 1, the Schedule 2 research exemption, and the 2026 move of safeguards from section 19 to UK GDPR Articles 84B/84C.

The Data Protection Act 2018 (DPA 2018) is the UK statute that sits alongside the UK General Data Protection Regulation (UK GDPR) and fills in the parts of the data protection regime that GDPR leaves to individual member states to specify. For health and social care research conducted in the UK, the DPA 2018 does most of the practical work: it supplies the conditions under which special category data — including health data — can lawfully be processed for research, and the safeguards and exemptions that make large-scale, longitudinal, and secondary-use research feasible without re-consenting every participant for every new analysis. This guide covers the UK-specific provisions in depth; for the underlying EU/UK GDPR principles themselves (lawful bases, the core data-protection principles, Article 89 research safeguards generally), see CASRAI’s GDPR dictionary entry and the GDPR and Data Protection Compliance in Research guide.

How the DPA 2018 relates to UK GDPR

Following Brexit, the EU GDPR (Regulation (EU) 2016/679) was retained in UK law and adapted into what is now called “UK GDPR,” principally via the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019. UK GDPR and the DPA 2018 must be read together: UK GDPR sets out the core principles, lawful bases, and data-subject rights; the DPA 2018 supplies the UK-specific detail GDPR leaves open, including:

  • The conditions for processing special category data (Schedule 1), which UK GDPR Article 9 requires member states to specify.
  • Exemptions from specific GDPR obligations and data-subject rights in defined circumstances, including for research (Schedule 2).
  • The Information Commissioner’s Office (ICO) as the UK’s independent supervisory authority, its enforcement powers, and the penalty regime.
  • UK-specific definitions and derogations (e.g. the age of consent for information-society services, and processing by competent authorities for law-enforcement purposes under Part 3).

In practice, a UK health or social care research project needs to satisfy both instruments at once: a UK GDPR Article 6 lawful basis and (for health data) an Article 9 condition, plus the matching DPA 2018 Schedule 1 condition and any applicable Schedule 2 safeguard or exemption.

Special category health data: Article 9 and Schedule 1

UK GDPR Article 9(1) prohibits processing “data concerning health” and other special categories (genetic data, biometric data used for identification, data on racial or ethnic origin, and more) unless one of the Article 9(2) conditions applies. Article 9(2)(j) covers processing “necessary for scientific or historical research purposes” subject to safeguards, but the UK, like other member states did under the original EU GDPR, uses domestic law to spell out exactly when that condition is met. That domestic detail lives in Schedule 1 to the DPA 2018. The paragraphs most relevant to health and social care research are:

  • Schedule 1, Part 1, paragraph 2 — Health or social care purposes. Processing special category data is permitted where necessary for health or social care purposes such as preventive or occupational medicine, medical diagnosis, the provision of health or social care or treatment, or the management of health or social care systems and services, and is carried out by or under the responsibility of a health professional or social work professional, or someone who owes an equivalent duty of confidentiality.
  • Schedule 1, Part 1, paragraph 3 — Public health. Covers processing necessary for reasons of public interest in the area of public health (for example monitoring epidemics or ensuring quality standards for medicines and devices), again subject to professional confidentiality obligations.
  • Schedule 1, Part 1, paragraph 4 — Archiving, research and statistics. The condition most directly relevant to research: it is met where processing is necessary for archiving purposes in the public interest, or for scientific or historical research purposes, or for statistical purposes, carried out in accordance with the UK GDPR’s research-safeguards article and in the public interest.

Most of the Schedule 1 conditions historically required the controller to have an “appropriate policy document” in place, documenting how the condition and the associated safeguards are met and satisfied — a document any institutional research office or NHS Trust information governance team should already hold for its research processing.

The 2026 reform: safeguards move from DPA 2018 section 19 to UK GDPR Article 84B

Researchers using older guidance should note a structural change: as part of the Data (Use and Access) Act 2025 reforms, section 19 of the DPA 2018 (which previously set out the safeguards attaching to the Schedule 1 paragraph 4 research/archiving/statistics condition) was omitted with effect from 5 February 2026. The substantive safeguards were not removed — they were relocated into UK GDPR itself, as new Articles 84B and 84C, covering what the Act calls “RAS purposes” (research, archiving, and statistics). Under Article 84B, processing for RAS purposes must be limited to personal data that will be turned into non-identifiable data, or that is otherwise necessary to fulfil the research purpose, and is subject to safeguards including:

  • Technical and organisational measures ensuring respect for the data-minimisation principle;
  • A requirement that the processing must not be likely to cause substantial damage or substantial distress to the data subject; and
  • A prohibition on using the processing for measures or decisions about a particular, identifiable data subject — unless it is for approved medical research.

For a UK health or social care research project, this means the appropriate-policy-document and safeguards analysis a data protection officer or research governance office would previously have anchored to DPA 2018 section 19 should now be anchored to UK GDPR Articles 84B/84C. The underlying obligations are substantively the same as before the reform, but the citation has changed, and any internal SOP, DPIA template, or research data governance policy referencing “section 19” should be updated accordingly.

Schedule 2 exemptions: what research can be relieved of

Schedule 2, Part 6, paragraph 27 of the DPA 2018 provides a targeted exemption from specific UK GDPR data-subject rights where complying with them would prevent or seriously impair achieving scientific, historical, or statistical research purposes. Where the exemption applies, and the processing satisfies Article 84B, a controller does not have to comply with:

  • Article 15(1)–(3) (the right of access) — but only where results or statistics are not made available in a form that identifies a data subject;
  • Article 16 (the right to rectification);
  • Article 18(1) (the right to restriction of processing); and
  • Article 21(1) (the right to object).

This is deliberately narrow: it does not touch the lawful-basis or special-category-condition analysis above, it does not exempt research from the core data-protection principles, and it is not a blanket “research exemption” from UK GDPR generally — it relieves specific administrative rights only, and only to the extent that honouring them would seriously impair the research (for example, contacting thousands of participants in a long-running cohort study to individually confirm and potentially amend or erase their records mid-study).

Why this matters specifically for health and social care research

Health and social care research in the UK typically layers several distinct legal and governance frameworks on top of each other, and it is easy to conflate them with data protection law:

  • Data protection law (UK GDPR + DPA 2018) governs the lawful processing of personal data, including the special-category conditions and exemptions above.
  • The common law duty of confidentiality is a separate legal obligation covering confidential patient information, which data protection compliance alone does not satisfy or override.
  • Section 251 of the NHS Act 2006 (administered via the Confidentiality Advisory Group, part of the Health Research Authority) provides a route to set aside the common law duty of confidentiality for defined research and public health uses of confidential patient information without explicit consent — a separate approval to any DPA 2018 Schedule 1 analysis.
  • Research ethics approval (via the HRA and Research Ethics Committees) and NHS/HSC research governance sign-off are procedural requirements independent of, though closely coordinated with, data protection compliance.

A study can be fully compliant with DPA 2018 Schedule 1 and still require separate ethics approval and, if relying on confidential patient information without consent, a section 251 support decision. Research administrators should treat the DPA 2018 analysis as one necessary layer among several, not a substitute for the others.

Practical checklist for research offices

  • Identify the UK GDPR Article 6 lawful basis and, for special category data, the Article 9 condition being relied on.
  • Map that Article 9 condition to the matching DPA 2018 Schedule 1 Part 1 paragraph (usually paragraph 2 for direct health/social care processing, paragraph 4 for research).
  • Confirm the appropriate policy document required by Schedule 1 is current, and that safeguards are documented against UK GDPR Articles 84B/84C rather than the now-omitted section 19.
  • Assess whether any Schedule 2, paragraph 27 exemption is being relied on, and document why complying with the specific right would seriously impair the research.
  • Complete a Data Protection Impact Assessment where the processing is likely to result in high risk — large-scale special category processing routinely triggers this requirement.
  • Confirm whether pseudonymisation or anonymisation is being applied, and at what stage of the data pipeline.
  • Separately confirm research ethics approval and, where confidential patient information is used without explicit informed consent, whether a section 251/CAG support decision is required.
  • Ensure the incident-response plan covers UK GDPR/DPA 2018 breach-notification obligations to the ICO alongside NHS or institutional reporting routes — see CASRAI’s data breach response plan entry.

Frequently asked questions

Is the Data Protection Act 2018 the same as UK GDPR?

No. UK GDPR is the retained, UK-adapted version of the EU GDPR regulation itself; the DPA 2018 is separate UK primary legislation that supplements it — supplying special category conditions, exemptions, the ICO’s powers, and other UK-specific detail. They must be applied together.

Does the DPA 2018 let researchers use health data without consent?

Not automatically. Schedule 1 Part 1 paragraph 4 provides a lawful condition for processing special category data for research without relying on explicit consent as the Article 9 condition, but this is a data protection law analysis only. It does not, by itself, satisfy the separate common law duty of confidentiality, and does not replace research ethics approval.

What changed for research safeguards in 2026?

Section 19 of the DPA 2018, which previously set out the safeguards for the Schedule 1 research/archiving/statistics condition, was omitted from 5 February 2026 under the Data (Use and Access) Act 2025. The equivalent safeguards now sit in new UK GDPR Articles 84B and 84C, covering “RAS” (research, archiving, and statistics) purposes; the substance is materially similar but the citation has moved.

Does the DPA 2018 apply to social care research as well as health research?

Yes. Schedule 1 Part 1 paragraph 2 explicitly covers “health or social care purposes” together, including provision of social care and management of social care systems and services, so the same conditions and safeguards apply to social care research involving personal data.

Related CASRAI resources

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →