General Data Protection Regulation
(GDPR)
The UK GDPR (retained in domestic law following Brexit) is the principal data protection law governing how organisations collect, use, store, and share personal data. It requires organisations to have a lawful basis for processing personal data, to be transparent with individuals about how their data is used, and to uphold individuals' data rights. Breaches can result in significant fines from the Information Commissioner's Office (ICO).
The UK GDPR (retained in UK law post-Brexit, alongside the Data Protection Act 2018) regulates how organisations collect, use, store, and share personal data. Organisations must have a lawful basis for processing (consent, legitimate interests, contract, legal obligation, vital interests, or public task) and must tell individuals how their data is used via a privacy notice. Data subjects have rights including access (subject access request — SAR), erasure ('right to be forgotten'), rectification, restriction, and portability. The Information Commissioner's Office (ICO) enforces UK GDPR and can impose fines of up to £17.5 million or 4% of global annual turnover (whichever is higher) for the most serious breaches. Personal data breaches that risk individuals' rights must be reported to the ICO within 72 hours of becoming aware of them. Public authorities, and organisations whose core activities involve large-scale monitoring or large-scale processing of special category data, must appoint a Data Protection Officer (DPO).
What it means in practice. UK GDPR is built on six principles and one overarching duty: you must be able to demonstrate compliance, not merely assert it. In practice that means knowing what personal data you hold, why you hold it, on what lawful basis, who you share it with, and how long you keep it. For individuals, the practical value of the regime is the set of rights it hands you — most importantly the right to ask any organisation what it holds about you and to have inaccurate data corrected or unlawfully held data deleted.
A worked example. Chris suspects a former employer is circulating an inaccurate account of why he left. He makes a subject access request by email, giving enough detail to identify himself. The employer must respond within one month, free of charge, providing a copy of his personal data along with the purposes of processing, the recipients, and the retention period. The disclosure reveals an internal note containing a factual error about his sickness record. He exercises the right to rectification, and because the note was shared with a recruitment agency, the employer must tell that recipient about the correction too.
Common pitfalls. Consent is over-used: it is only one of six lawful bases, it must be freely given and as easy to withdraw as to give, and it is usually the wrong basis for employment data because the power imbalance undermines it. Organisations also wrongly treat the right to erasure as absolute — it does not apply where the data is needed for a legal obligation or the establishment or defence of legal claims. And the 72-hour breach notification deadline runs from awareness, not from the point you finish investigating.
How it relates to other terms. The organisation deciding why and how data is processed is the data controller, and a supplier acting on its instructions is a processor. Enforcement sits with the Information Commissioner's Office. The regime is more fully described under UK GDPR and works alongside the Data Protection Act 2018, while requests for information held by public bodies about anything other than yourself go through freedom of information instead.
What to do next. Read our UK GDPR for individuals guide to see which rights apply to you, then use making a subject access request to get a copy of your data. If your information has been lost or disclosed without authority, read your rights after a data breach before contacting the ICO.
Related terms
Related guides
UK GDPR Rights for Individuals
The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018) give individuals in the UK eight legally enforceable rights over how organisations collect, store, and use their personal data. These rights apply whether the data is held by a business, public body, or online platform.
6 min
Data Subject Access Requests
A Subject Access Request (SAR) is a formal request you can make to any organisation asking them to provide a copy of all personal data they hold about you and information about how it is used. It is one of your most powerful rights under UK GDPR and is entirely free in most cases.
6 min
When a Company Has a Data Breach: Notification and Next Steps
A personal data breach occurs when an organisation accidentally or unlawfully destroys, loses, alters, discloses, or gives access to your personal data without authorisation. This guide covers the organisation's duty to tell you and to tell the regulator, and what you should do in the days afterwards to limit the damage. If you have already decided you want to complain to the ICO or claim compensation, go straight to <a href="/complaints-ombudsmen/data-breach-complaints">data breach compensation and ICO complaints</a>.
6 min