Content Removal

UK GDPR Explained: Your Data Rights and How to Use Them

The UK GDPR is the UK's main data protection law. Learn who it covers, the rights it gives you, how the Data Protection Act 2018 and 2025 reforms fit in, and where to complain.

By Editorial Team 9 min read
London rooftops and chimneys softened by early morning fog

The UK GDPR is the United Kingdom’s version of the EU’s General Data Protection Regulation, kept in UK law after Brexit. Together with the Data Protection Act 2018, it controls how organizations collect and use personal data about people in the UK, and it gives you rights to see your data, correct it, have it erased, object to how it’s used, and complain. It’s enforced by the Information Commissioner’s Office (ICO), and parts of it are being updated by the Data (Use and Access) Act 2025.

This guide explains the UK GDPR for individuals: what it covers, what you can ask for, and where to go when an organization won’t cooperate. It’s general information, not legal advice.

What the UK GDPR is

When the UK left the EU, the GDPR was copied into UK law with changes needed to make it work on its own. The result is the UK GDPR. It sits alongside the Data Protection Act 2018 (DPA 2018), which fills in details and adds its own rules.

Law What it does
UK GDPR The core rules for most processing of personal data: principles, lawful bases, your rights, and duties on organizations.
Data Protection Act 2018 Adds exemptions (for example for journalism, legal proceedings and crime prevention), separate rules for law enforcement and intelligence services, criminal offenses, and the ICO’s powers.
Data (Use and Access) Act 2025 Amends both, with changes being brought into force in stages.
Privacy and Electronic Communications Regulations (PECR) Separate rules on marketing calls, texts, emails and cookies.

The UK GDPR is still very close to the EU GDPR. Many rights work the same way, which is why our guide to the GDPR right to erasure covers both.

Who the UK GDPR applies to

  • Organizations based in the UK that process personal data, including businesses, charities, public bodies and sole traders.
  • Organizations outside the UK that offer goods or services to people in the UK or monitor their behavior, such as an overseas online store or app aimed at UK users.

It generally doesn’t apply to individuals using data for purely personal or household purposes, like keeping an address book or sharing family photos privately. Processing by police for law enforcement and by the intelligence services is covered by separate parts of the DPA 2018 rather than the UK GDPR. If you’re dealing with a Canadian or Australian business that doesn’t target the UK, local law applies instead: see our guides to PIPEDA and the Australian Privacy Act.

“Personal data” means any information relating to an identified or identifiable living person: your name, email, location data, online identifiers, photos, recordings, and opinions about you. Some types, such as health, ethnicity, religion, sexual orientation and biometric data, get extra protection as special category data.

Your rights under the UK GDPR

The law gives individuals a set of rights. Not all of them apply in every situation, and most have exceptions.

  1. The right to be informed. Organizations must tell you what they collect, why, how long they keep it and who they share it with, usually in a privacy notice.
  2. The right of access. You can ask for a copy of your data and details of how it’s used. This is a subject access request; see our guide on how to make a data subject access request.
  3. The right to rectification. You can have inaccurate data corrected and incomplete data completed.
  4. The right to erasure. Sometimes called the right to be forgotten, it lets you ask for deletion on specific grounds, such as when the data is no longer needed or was processed unlawfully.
  5. The right to restrict processing. You can ask an organization to limit how it uses your data, for example while it checks whether the data is accurate.
  6. The right to data portability. In some cases you can get your data in a reusable format or have it sent to another organization.
  7. The right to object. You can object to processing based on legitimate interests or public tasks, and you have an absolute right to stop direct marketing.
  8. Rights around automated decisions. You have protections when significant decisions about you are made by automated means, including the right to ask for human involvement and to contest the decision.

Organizations must generally respond within one month. They can extend that by up to two further months for complex requests or several requests from the same person, but they must tell you within the first month. Most requests are free; an organization may charge a reasonable fee or refuse if a request is manifestly unfounded or excessive, and it must explain why.

You also have the right to complain to the ICO, and the right to go to court to seek compensation if you’ve suffered damage or distress because an organization broke the law.

What the Data (Use and Access) Act 2025 changes

The Data (Use and Access) Act 2025 amends the UK GDPR, the DPA 2018 and PECR. Its changes are being brought in gradually, so check the ICO’s website for what’s in force when you act. In general terms, changes that matter to individuals include:

  • Subject access requests. The Act confirms that organizations need to make reasonable and proportionate searches, and it lets the response clock pause while they wait for you to clarify a request.
  • Complaints to organizations. Organizations must have a process for handling data protection complaints. You’ll generally be expected to use it before going to the ICO.
  • Legitimate interests. A list of “recognized legitimate interests”, such as some crime prevention and safeguarding uses, lets organizations process data for those purposes with less balancing.
  • Automated decision-making. The rules are relaxed in some situations, while keeping safeguards such as the right to human review and to challenge a decision.
  • Cookies. Some low-risk cookies, such as certain analytics, may no longer need consent in the same way.
  • The regulator. The ICO is due to be restructured as the Information Commission, a body with a board, although its role in handling complaints continues.

Your core rights to access, correction, erasure and objection remain.

How to use your rights, step by step

  1. Find the right contact. Check the organization’s privacy notice for its data protection officer or privacy email.
  2. Make a clear request. Say which right you’re using, what data or processing it concerns, and how they can identify you. You don’t have to use legal wording, but naming the UK GDPR helps it reach the right team.
  3. Keep a copy and the date. The one-month clock generally starts when they receive your request, or once they’ve confirmed your identity if they reasonably need to.
  4. Respond to reasonable questions about your identity or what you’re looking for, without oversharing.
  5. Chase once if the deadline passes, pointing out the date and asking for a response.
  6. Use the organization’s complaint process if you’re unhappy, then escalate to the ICO.

A worked example

This is an illustrative scenario, not a real client.

Aisha, in Manchester, finds that an old online directory still lists her previous business with her home address and mobile number. The business closed years ago and she’s getting unwanted visits.

  1. She emails the directory’s privacy contact, asks for erasure under the UK GDPR, explains that the data is no longer needed for its original purpose, and objects to the ongoing processing.
  2. After a month with no reply, she sends a reminder with the date of her original request.
  3. The directory replies that it will remove the address but keep the business name, which was public. She accepts this.
  4. Because the page still shows in Google search results, she uses Google’s refresh outdated content tool once the listing changes.

Had the directory ignored her, her next step would have been a complaint to the ICO, as described in our guide on how to make an ICO complaint.

Not sure where to start?

Get a free audit of your search results and review profiles, with a prioritized fix list.

Get a free audit

Who enforces the UK GDPR: the ICO

The ICO is the UK’s independent data protection regulator. It handles complaints from individuals, gives guidance, and can take enforcement action against organizations, including reprimands, orders to comply, and fines for serious breaches.

For individual complaints, the ICO usually looks at whether the organization has met its obligations and may ask it to put things right. It doesn’t award compensation. If you want compensation, you’d need to go to court, and it’s worth talking to a lawyer first.

What the UK GDPR can and can’t do for your online reputation

The UK GDPR can be a useful tool for personal information online, but it has limits.

  • It can help with outdated or inaccurate personal data held by businesses, data brokers, directories and, in some cases, search engines, which can be asked to delist results about you.
  • It’s weaker against journalism and content published in the public interest, where exemptions for freedom of expression often apply.
  • It doesn’t cover purely personal posts by individuals, although platforms’ own rules might.
  • It isn’t defamation law. If something is false and damaging, see our guide to UK defamation law.

Search engine delisting in the UK follows the same general approach as the EU; our guide to the right to be forgotten explains how to ask Google to remove results.

Common mistakes to avoid

  • Assuming the EU GDPR still applies to UK-only organizations. For most UK processing, the UK GDPR is the law to cite.
  • Asking for everything at once without focus. Say what you need. A clear request is easier to answer and easier to enforce.
  • Going straight to the ICO. It will usually expect you to have raised it with the organization first.
  • Waiting too long to complain. The ICO generally asks for complaints within three months of your last meaningful contact with the organization.
  • Relying on pre-2025 guidance for deadlines or procedures without checking what has changed.

When to get help

You can use most UK GDPR rights on your own, for free. If personal information about you appears across many sites or in search results that won’t budge, our content removal service can help map out which requests to send and where. For compensation claims or court action, speak to a UK data protection solicitor.

Frequently asked questions

Is the UK GDPR the same as the EU GDPR?

Very close, but not identical. The UK GDPR is the UK’s own version, kept after Brexit and now being amended by the Data (Use and Access) Act 2025. The EU GDPR still applies to UK organizations that offer goods or services to people in the EU.

Who enforces the UK GDPR?

The Information Commissioner’s Office. It handles complaints from individuals and can take action against organizations, from reprimands to fines. The courts can also hear claims for compensation.

How long does an organization have to respond to a request?

Generally one month from receiving it. That can be extended by up to two further months for complex requests, and under the 2025 reforms the clock can pause while the organization waits for clarification you’ve been asked for.

Does the UK GDPR give me a right to be forgotten?

Yes, in the form of the right to erasure, but only on specific grounds and subject to exceptions such as freedom of expression and legal obligations. It can also support requests to search engines to delist results about you.

Did the 2025 reforms remove my rights?

No. Your main rights remain, including access, correction, erasure and objection. The reforms change how some requests are handled and give organizations more flexibility in certain areas. Check the ICO’s current guidance for details.

Editorial Team

The 123 Reputation Management editorial team writes practical guides on reviews, search results and online reputation.

Start with step 1

See what people see when they search for you.

Get a free, no-obligation reputation audit covering search results, review profiles and social mentions, with clear next steps.