Data protection is one of the few areas of law that applies uniformly across the whole United Kingdom, being a reserved matter. It is also one where almost every organisation has obligations and almost every individual has rights they do not use.
The framework is the UK GDPR together with the Data Protection Act 2018, amended by subsequent legislation including the Data (Use and Access) Act 2025. Because the position has changed recently, current Information Commissioner’s Office guidance should be the reference point rather than older material.
What Counts as Personal Data
Personal data means information relating to an identified or identifiable living person. That is broader than most people assume and includes names, addresses, email addresses, identification numbers, location data, online identifiers such as IP addresses and cookie identifiers, and opinions about someone.
A subset receives extra protection as special category data: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic and biometric data used for identification, health data, and data about sex life or sexual orientation. Criminal offence data has its own regime.
The Lawful Bases
Any processing of personal data requires a lawful basis. There are six, and consent is only one of them.
| Basis | Applies where |
|---|---|
| Consent | Freely given, specific, informed and unambiguous, and capable of being withdrawn |
| Contract | Processing is necessary to perform a contract with the individual |
| Legal obligation | Necessary to comply with the law |
| Vital interests | Necessary to protect someone’s life |
| Public task | Necessary to perform a public function |
| Legitimate interests | Necessary for interests of the controller or a third party, balanced against individual rights |
A frequent organisational error is treating consent as the default. Consent must be genuinely optional and withdrawable, which makes it unsuitable for processing an organisation needs to carry out regardless. Another basis is often more appropriate and more robust.
Your Rights Over Your Own Data
- Right of access. You can make a subject access request for a copy of your personal data and information about how it is used. It is generally free, and the organisation must usually respond within one month, extendable in complex cases.
- Rectification. To have inaccurate data corrected.
- Erasure. The so-called right to be forgotten, which applies in defined circumstances rather than universally.
- Restriction. To limit processing while a dispute is resolved.
- Portability. To receive certain data in a machine-readable format, or have it transferred.
- Objection. Including an absolute right to object to direct marketing, which must be honoured.
- Rights around automated decisions, including significant decisions taken solely by automated means.
Making a request need not be formal. A clear written request identifying yourself and what you want is sufficient, and you do not have to use a template or cite the legislation.
Obligations on Organisations
- Know what you hold. Maintain records of processing activities, purposes and retention periods. Most compliance failures begin with not knowing what data exists.
- Be transparent. A clear privacy notice explaining what is collected, why, on what basis, who it is shared with and how long it is kept.
- Collect only what is needed, and keep it only as long as necessary. Indefinite retention is a common and avoidable breach.
- Keep it secure, with appropriate technical and organisational measures proportionate to risk.
- Handle requests within the deadline, and have a process rather than improvising.
- Report qualifying breaches to the ICO, generally within 72 hours of becoming aware, and notify affected individuals where the risk to them is high.
- Manage processors with written contracts setting out obligations.
- Assess high-risk processing through a data protection impact assessment before starting.
- Consider whether a data protection officer is required, and pay the ICO fee if applicable.
Marketing, Cookies and Electronic Communications
Direct marketing is governed by the Privacy and Electronic Communications Regulations alongside the UK GDPR, and the rules differ by channel. Email and text marketing to individuals generally requires consent, subject to a limited exception for existing customers in relation to similar products where an opt-out was offered. Live and automated calls have their own rules, and the Telephone Preference Service must be screened against.
Cookies and similar technologies generally require consent for anything beyond what is strictly necessary for a service the user requested. Consent banners that make refusing harder than accepting have been a repeated focus of regulatory attention.
Breaches and Complaints
If your data has been misused or exposed, the practical sequence is: complain to the organisation first, then to the Information Commissioner’s Office if unresolved. The ICO can investigate, require action and impose significant penalties, though it does not award compensation to individuals.
Compensation for distress or loss caused by a breach is pursued separately through the courts. Take advice on whether a claim is proportionate, as this area has seen courts discourage low-value claims.
Regulators, Advice and Regional Provision
Data protection is regulated UK-wide by the Information Commissioner’s Office, with offices including a base in Wales and operations across the nations. Public sector and health data governance arrangements differ between the nations, as devolved services are separately administered.
In the North West, data, technology and public sector coverage appears in the Manchester Chronicle and Liverpool Tribune. Yorkshire is covered by Leeds Angle, reporting from a significant digital and health data sector, plus Sheffield Voice and Bradford Daily.
Scotland, where public sector data governance operates through separate devolved structures, is covered by Glasgow Bulletin and Edinburgh Scope. Northern Ireland is reported by the Belfast Record.
Midlands technology and public sector matters appear in Birmingham Focus, Coventry Insight, Leicester Echo, Derby Digest and Nottingham Times. The Newcastle Brief and Hull Report cover the North East and Humber.
Southern coverage appears in Brighton Update, reporting from a substantial digital sector, plus Southampton Ledger, Plymouth Wire and Bristol Outlook. London’s technology and financial data sectors are covered by London Signals and Capital Outlook. Public sector data and benefits administration is followed via DWP UK Latest News, with technology industry reporting in Trade Mirror.
Frequently Asked Questions
How long does a subject access request take?
Generally one month from receipt, extendable for complex or multiple requests, with the individual informed of any extension.
Can an organisation charge me?
Subject access is generally free. A reasonable fee may be charged for manifestly unfounded or excessive requests, or for further copies.
Do small businesses have to comply?
Yes. Obligations apply regardless of size, although what is proportionate differs. Some requirements, including whether a data protection officer is needed, depend on the nature of the processing.
Is consent always required?
No, and this is the most common misunderstanding. Consent is one of six lawful bases, and often not the most appropriate one.
Further Reading
Technology, legal and regulatory reporting appears across News Notes, Local News Point, Weekly Journal and Trends Archive. Firms and technology businesses seeking coverage use agencies listed via Local PR Services, PR Directory and Press Hubs.
The Bottom Line
Personal data is broader than most people think, consent is only one of six lawful bases, and indefinite retention is one of the most common breaches.
Individuals should use the right of access — it is free, generally answered within a month, and requires no formal wording. Organisations should start by knowing what they hold and why, because every other obligation depends on that. And because the legislation was amended recently, work from current ICO guidance rather than older material.
This article is general information about the law in the United Kingdom and is NOT legal advice. It cannot take account of your circumstances, and acting on general information rather than advice about your own situation can be costly. The law differs between England and Wales, Scotland and Northern Ireland, and several areas covered here are subject to active reform, so provisions, thresholds, fees and time limits change. Figures and time limits cited were believed correct in general terms at the time of writing but must be verified against current official sources. For advice on your own position, consult a solicitor, an accredited adviser, Citizens Advice, or the relevant regulator or ombudsman. Time limits in legal matters are strict and missing one can end a claim permanently, so seek advice early.

