← Back to Policies and compliance

UK GDPR and Data Protection Act 2018

Status: Compliant

Last reviewed: 18 May 2026

What this is

The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 are the principal laws governing how personal data is processed in the United Kingdom. They set out the rights of individuals whose data is processed, the lawful bases on which processing can take place, and the obligations of organisations acting as data controllers or data processors.

Compliance is a legal requirement for any organisation operating in the UK that processes personal data, including health and care data. It is enforced by the Information Commissioner's Office (ICO).

Our status

Codara complies with UK GDPR and the Data Protection Act 2018 in all processing activities, and is registered with the Information Commissioner's Office:

Verify independently

You can view our entry on the ICO public register.