UK GDPR Explained: Data Protection, Privacy and Your Rights

two hand on laptop on desk

Be confident about Data Protection, Privacy and the GDPR

“Data Protection” is a specific legal framework governing how organisations collect, use, store, share and delete personal data, referred to in legal terms as ‘processing’.

“Privacy” is a broader concept. It is about a person’s right to control their personal life, communications and personal information and to be free from unwanted intrusion.

GDPR Legislation

GDPR, or to use its full name the “General Data Protection Regulations”, were introduced in May 2018 while the UK was still part of the European Union. It became more UK-centric when we left the EU and is now a separate piece of legislation known as the UK GDPR.  The GDPR remains across Europe.

As GDPR was first introduced in 2018, the UK updated the older Data Protection Act 1998 and introduced the Data Protection Act 2018.

The UK GDPR and Data Protection Act 2018 are separate laws but intended to be read and applied together in relation to data protection.

Privacy in the digital world is covered by the “Privacy and Electronic Communications Regulations 2003” (PECR). PECR is closely related to data protection but is not itself part of the UK GDPR or the Data Protection Act 2018. Instead, it sits alongside them and provides additional rules for electronic communications and marketing.

These laws focus on data, as their names or acronyms suggest. But not all data – only Personal Data.

Personal Data

Personal Data is any information relating to an identified or identifiable natural person (“data subject”) or in plain English, information which identifies or relates to a living individual – it doesn’t apply once you die!

GDPR Basics

Let’s concentrate on the UK GDPR and the very basics. Individuals (“data subjects” in the legislation) have legal rights. Organisations, businesses and even sole traders (“data controllers” in the legislation) who process data subjects’ personal data have a legal requirement to justify why they need to process it by way of what is called a “lawful basis” and they also must adhere to the “data protection principles” which are:

  • Lawfulness, fairness & transparency – Process personal data legally, fairly, and openly.
  • Purpose limitation – Only collect data for specific, legitimate purposes.
  • Data minimisation – Collect only the data that is necessary.
  • Accuracy – Keep personal data accurate and up to date.
  • Storage limitation – Keep data only for as long as needed.
  • Integrity & confidentiality (security) – Protect data against unauthorised access, loss, or damage.
  • Accountability – Be able to demonstrate compliance with all the principles above.

Before delving into any lawful basis, it’s important to know that Personal Data are divided into two meaningful groups: 1. general Personal Data, like name, address, date of birth etc. and 2. Special Category Personal Data.

Processing Special Category Personal Data (which is sensitive information such as health, race, religion, sexual orientation, genetic and biometric data) is specifically not allowed (banned) unless a specific lawful basis applies.  And data controllers cannot just rely on a Special Category lawful basis for processing this type of data, they must also have a lawful basis under the general personal data category.

Some of your GDPR Rights

Right to be informed

This is usually done by way of a “privacy notice” on the organisation’s (“data controller”) website.  If there is no privacy notice, or you contact the organisation by phone, letter or otherwise they have a legal duty to inform you, the data subject, about their processing of your personal data – either there and then, by referring you to the website privacy notice or otherwise within 30 days.

Every data controller is bound by the UK GDPR if they process personal data electronically and generally if they use manual paper records in a filing system or chronological manner.  The legislation even informs them what they have to tell you, the data subject, about in the privacy notice. Long gone are the days they could cobble together an online template.

Right to Access

Using a Subject Access Request, a data subject can ask an organisation (“data controller”) about their processing of Personal Data.  Beware, there is often a myth that you will receive every email you were sent/received or were copied into, along with other information.  Wrong!

An organisation is only bound to provide confirmation that it processes the individual’s data, a concise and accessible copy of the Personal Data itself, details on the processing purposes, categories of data, and information about organisations with which the data is shared. They may include a schedule showing the end date for processing when the ‘purpose’ expires.

The response must be provided without delay and within one calendar month from the date the request is received (although this can be extended by up to two months for particularly complex requests).

Right to Complain

A new provision was introduced in June 2026, giving a statutory right to complain about an organisation has mishandled personal data or breached data protection laws.

By law, organisations must acknowledge the complaint within 30 days and resolve it without undue delay. They are required to keep the Data Subject updated on the progress and notify them of the final outcome.  Once the complaint has been finalised, the complaint can be escalated to the regulator, the Information Commission (Information Commissioner’s Office).  The regulator may refuse to consider any direct complaint if the Data Subject cannot prove that they have already raised a complaint with the organisation.

Think First!

So, there’s part of the law. However, it is important to consider Personal Data and what one is prepared to disclose in order to receive the ‘service’.  Remember, Special Category Personal Data, especially biometrics used in facial recognition, finger print or eye scans. You cannot change these, whereas you can easily change your password.

Does the organisation actually need all the information or are they collecting more than is needed to provide the service in order to satisfy their own data “greed”, to profile you in a more aggressive way?  Remember the purpose limitation and data minimisation requirements which organisations must obey!

Passwords

Passwords could soon be extinct, superseded with more reliable and secure methods, such as passkeys. But until they are, don’t use the same password for everything, adopt a password strategy ensuring you use a mix of capitals, numbers and special characters.  Use a password manager to store your passwords.

If you are in the UK; use a pound, without spending a penny and potentially save yourself thousands!  Yes, the £ symbol isn’t on 86% of keyboards across the globe, they have the $ – so perhaps include that in your password, too.

About the author

Nigel Hellwell head short white man in 50s smiling at camera white shirtNigel Hellewell MBCS is a data protection practitioner and has written this guest blog post.

Data Protection Advice, Guidance and Training: https://enaych.com/

WordPress Website Security and Data Protection Compliance: https://wpupdate.co.uk/about/

Legal Disclaimer

The information provided here is intended for general informational and educational purposes only. While every effort is made to ensure that the content is accurate and up-to-date, legislation, regulations and official guidance may change over time.

Nothing in this article constitutes legal advice and the content should not be relied upon as a substitute for obtaining advice from a qualified legal professional or other appropriately qualified adviser. Readers should always consult the relevant legislation, official government guidance or seek independent professional advice before making any decisions based on the information provided.

The author accepts no liability for any loss or damage arising from reliance on the information contained in this article.

More consumer rights help and advice

Black and white cartoon cow sitting at a laptop on the cover of How to Complain by Helen DewdneyCartoon cow logo on the cover of 101 Habits of an Effective Complainer book

 

See Top 20 Tips on how to complain effectively and books if you need more help. I also offer services to consumers.

 

 

You might also like
Newsletter Sign Up

If this site or a response from me has helped you, please consider buying me some chocolate (don’t like coffee!) to help me continue to provide this free advice. Thank you!

Share:

You must be logged in to post a comment.