The Data Protection Act 1998, effective from March 2001, implements the EU data protection directive, providing a legal framework to protect citizens' personal data in the UK. It outlines eight principles for processing personal information and grants individuals rights such as access to their data and the ability to object to direct marketing. The Information Commissioner's Office (ICO) is responsible for overseeing compliance, handling complaints, and has the power to impose monetary penalties for serious breaches.