Skip to content

UK GDPR

The UK's retained version of the EU General Data Protection Regulation, which continues to govern personal data processing in the UK after Brexit. Sits alongside the Data Protection Act 2018. Eight individual rights including the right to access (SAR), rectification, erasure ('right to be forgotten'), restriction, portability, object, and rights related to automated decision-making.

UK GDPR (formally the retained Regulation (EU) 2016/679) imposes obligations on data controllers and processors: lawful, fair, transparent processing; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality. Six lawful bases for processing (consent, contract, legal obligation, vital interests, public task, legitimate interests). Special category data requires additional protection. Individuals can exercise rights without charge; the controller has 1 month to respond. Breaches notifiable to ICO within 72 hours where high risk. The retained Regulation is amended by the Data Protection Act 2018 and by subsequent domestic data protection legislation.

In practice, the rights are not absolute and each one carries conditions, which is why organisations so often refuse them. Erasure, for example, applies where the data is no longer necessary, where consent is withdrawn and there is no other lawful basis, or where you successfully object — but not where the organisation needs the data to comply with a legal obligation or to establish or defend a legal claim. Knowing the condition you are relying on turns a request that can be brushed aside into one that has to be answered.

Worked example: Ola asks a retailer to delete her account and stop sending marketing emails. The retailer must stop the marketing immediately and unconditionally, because the right to object to direct marketing is absolute. It may lawfully refuse to erase everything, because it has to keep transaction records for tax purposes. The right answer is therefore partial: marketing data deleted, order history retained for the statutory period, and the account closed. Ola asks the retailer to confirm in writing what has been kept, under which lawful basis, and for how long — which is itself information she is entitled to.

The misconceptions are widespread. Consent is only one of six lawful bases and is usually the weakest, so an organisation does not always need your consent to process your data. There is no general right to be forgotten by search engines or anyone else; it is a qualified right applied case by case. Employers can process employee data without consent, relying on contract or legitimate interests. And a data breach is not automatically compensable — you need to show damage or distress, and you claim that in court rather than through the regulator.

UK GDPR is enforced by the Information Commissioner's Office, supplemented by the Data Protection Act 2018, and exercised most often through a subject access request. Read our guides to your UK GDPR rights, subject access, and the right to erasure.

Official guidance Back to glossary