Glossary

Data protection

Data protection is the law and practice governing how organisations collect, store, use and share personal information. In the UK it rests on the UK GDPR and the Data Protection Act 2018, regulated by the Information Commissioner's Office (ICO).

Last updated

Part of our topic guide on AI Governance & Data Strategy.

Data protection is the law and practice governing how organisations collect, store, use and share personal information: anything that identifies a living person, from a customer's email address to an employee's payroll record. In the UK, the core legal framework is the UK GDPR alongside the Data Protection Act 2018, regulated by the Information Commissioner's Office (ICO), the UK's independent data-protection authority.

The five moving parts of the UK regime

  • Personal data is the trigger for everything else: any information that can identify a living person, directly or indirectly (name, email, IP address, employee ID, and so on). If you hold it, the regime applies to you, which in practice means it applies to nearly every organisation.
  • The UK GDPR sets the core principles: data must be collected for a specific purpose, kept accurate, held no longer than necessary, and kept secure.
  • The Data Protection Act 2018 sits alongside it, covering areas the GDPR doesn't fully address, including some law-enforcement and national-security processing.
  • The ICO oversees compliance, investigates breaches, and can issue enforcement action.
  • The Data (Use and Access) Act 2025 is the newest piece, amending aspects of the UK regime. Detail here is still settling, so check the ICO or legislation.gov.uk for any provision that affects your organisation.

Getting this wrong carries real cost: reputational damage, regulatory action, and lost customer trust.

As organisations build more with data and AI, the people closest to that work (analysts, engineers, product owners) need to understand data protection well enough to build it in from the start, not treat it as something the legal team bolts on afterwards. In our view, that's why data literacy and data protection awareness belong together as foundational skills, not siloed specialisms. The legal team can review a finished system; only the people building it can make it lawful by design.

Is there a funded route into data protection work?

Yes. In England, data protection sits within the funded apprenticeship system through the Level 4 Data Protection and Information Governance Practitioner standard (roughly equivalent to the first year of a degree). Like all apprenticeship standards it's built around knowledge, skills and behaviours rather than a fixed job title, so it can suit people already working in compliance, legal, IT or governance roles, not only those with "data protection" in their title. It combines on-the-job practical work with structured off-the-job training across UK data-protection law, information-security principles, records management and handling subject-access requests and breaches, with the assessment method set by the standard's own assessment plan. iO-Sphere delivers this standard as its Data & AI Governance apprenticeship, so we should say plainly that we have a stake in this route; judge it, like any programme, on what learners actually do on it.

Funding works the same way as other apprenticeships: through the Growth & Skills Levy (formerly the Apprenticeship Levy) for larger employers, with government co-investment or full funding available for smaller employers depending on the apprentice's age and circumstances.