UK tech experts · info@vividrepairs.co.uk
Vivid Repairs

ZeroYour rights, used

Your UK Privacy Rights in Practice

14 min readLast verified 21 July 2026

In short

UK GDPR and the Data Protection Act 2018 give you six practical rights over your personal data, and most people never use a single one. This piece explains when each right applies, how to phrase a request that gets answered, and what to do when an organisation ignores you. It also covers PECR, the separate law that governs marketing calls, texts and emails, including how the Telephone Preference Service fits in.

The two laws that protect you

Two pieces of legislation do most of the work here. The first is UK GDPR, the version of the EU's General Data Protection Regulation that was written into British law before Brexit and has stayed largely intact since. It sets out what organisations can and cannot do with your personal data, and it gives you a set of enforceable rights you can exercise at any time. The second is the Data Protection Act 2018, which sits alongside UK GDPR, fills in some gaps, and gives the Information Commissioner's Office (ICO) its powers of enforcement. Together they cover almost every organisation that handles your data in the UK, from the NHS to a small online retailer.

There is a third law worth knowing about: the Privacy and Electronic Communications Regulations 2003, usually called PECR. It does something slightly different. Where UK GDPR governs data broadly, PECR deals specifically with electronic marketing: the calls, texts, and emails that land uninvited. It has its own rules and its own teeth. We'll come to it in the final section, but it's worth holding in mind throughout, because many of the most annoying intrusions people experience, the nuisance calls, the spam texts, are PECR territory rather than pure UK GDPR territory.

Today's action: Bookmark the ICO's public-facing guidance pages. They're written in plain English and are genuinely useful as a reference when you're drafting a request.

The subject access request: see everything they hold on you

A Subject Access Request, or SAR, is your right to ask any organisation what personal data it holds about you, why it holds it, who it shares it with, and how long it plans to keep it. The organisation must respond within one calendar month. It must do so free of charge in almost all cases. And the response has to be substantive: a vague acknowledgement doesn't count.

When is a SAR the right tool? Use it when you want to understand the full picture. If you're curious about what a bank, insurer, employer, or data broker actually knows about you, a SAR is the place to start. It's also useful before you exercise any other right, because you can't ask for inaccurate data to be corrected if you don't yet know what the data says. If you're trying to understand how companies have been tracking your behaviour online, a SAR to a platform or ad network can be genuinely revealing.

How to phrase it: you don't need legal language. Something like this works well.

I am writing to make a subject access request under Article 15 of UK GDPR. Please provide me with all personal data you hold about me, the purposes for which you process it, the categories of data involved, any third parties you share it with, and the retention period you apply. Please also confirm whether you make any automated decisions about me using this data. My full name is [name], and I can be contacted at [email/address]. I am happy to provide further identification if required.

Send it to the organisation's data protection officer if one is listed on their website. If not, their general contact address is fine. Keep a copy and note the date you sent it, because the one-month clock starts then.

What to expect: a good response includes copies of your data in a readable format, a privacy notice or equivalent explanation, and details of any third-party sharing. Some organisations are excellent at this. Others send a bare minimum. The ICO's guidance is clear that a response must be intelligible, not just technically complete. If what you receive is so redacted or vague that it tells you nothing useful, that is grounds for a complaint.

  • Identify one organisation that holds significant data about you: your bank, your employer, or a major platform.
  • Send a SAR using the paragraph above, adapted with your own details.
  • Set a calendar reminder for 30 days so you know exactly when they're in breach if they haven't replied.

Erasure: what the right to be forgotten really delivers

The right to erasure, sometimes called the right to be forgotten, sounds more powerful than it is in practice. That's not a criticism of the law; it's just honest. Understanding the limits upfront saves frustration.

You can ask an organisation to delete your personal data when: you've withdrawn consent and there's no other legal basis for keeping it; the data is no longer necessary for the purpose it was collected; you've successfully objected to processing (more on that below); or the data was processed unlawfully in the first place. Those are real situations that come up regularly.

The limits are equally real. Organisations can refuse erasure if they need the data to comply with a legal obligation (a bank keeping transaction records for anti-money-laundering purposes, for example), to defend a legal claim, or to exercise a right of freedom of expression. Public health and scientific research have their own exemptions too. So if you ask a financial institution to delete seven years of account history, they will almost certainly decline, and they'll be within their rights to do so.

Where erasure works well: withdrawing from a mailing list and asking the company to delete your profile entirely; asking a data broker to remove your details from their database; requesting deletion of an old account you no longer use. Data brokers in particular are worth targeting with erasure requests, because their entire business model depends on holding your information, and UK GDPR gives you a genuine lever to pull against them.

How to phrase it:

I am writing to request erasure of my personal data under Article 17 of UK GDPR. I no longer consent to you holding or processing my data, and I am not aware of any overriding legal basis for you to retain it. Please confirm in writing when the deletion has been completed and whether any third parties to whom you have disclosed my data have been informed.

What to expect: a response within one month, either confirming deletion or explaining which exemption they're relying on to refuse. If they refuse, they must tell you why. That reason is then something you can challenge, either directly or via the ICO.

Today's action: Think of one account you haven't used in over a year. Send an erasure request today. If you're not sure what data they hold, send a SAR first.

The absolute right: stopping direct marketing dead

This is the one right in UK GDPR that has no balancing test. Every other right involves some weighing of competing interests. This one doesn't. Under Article 21(3), if you object to your data being used for direct marketing, the organisation must stop. Not probably should. Must. There is no legitimate interest they can invoke to override it.

Your right to object to direct marketing is the one absolute right in UK GDPR. The organisation must stop. There is no balancing test, no legitimate interest they can cite, no exemption. Just: stop.

Direct marketing covers more than you might think. It includes postal marketing, email, SMS, phone calls, and targeted advertising online where your data is being used to profile and target you specifically. If an organisation is using your personal data to decide which adverts to show you, you can object to that processing.

When is this the right tool? Any time an organisation is sending you marketing you don't want, or using your data to profile you for advertising purposes, and their standard unsubscribe process either doesn't work or doesn't go far enough.

How to phrase it:

I am writing to exercise my right to object to direct marketing under Article 21(3) of UK GDPR. Please cease all direct marketing communications to me immediately and remove my details from any marketing lists or profiling processes used for this purpose. Please confirm in writing that this has been done.

What to expect: compliance, and a written confirmation. If they continue to send marketing after this, they're in breach of UK GDPR, and that's a straightforward complaint to the ICO.

Today's action: If there's an organisation sending you marketing you've already tried to unsubscribe from, send the paragraph above. Keep the response as evidence.

Rectification, portability and automated decisions

Rectification

Article 16 gives you the right to have inaccurate personal data corrected. This matters more than it sounds. Incorrect data held by a credit reference agency can affect your ability to get a mortgage. Wrong information on an employer's records can affect a reference. Outdated health data can have clinical consequences.

When to use it: after a SAR reveals something wrong. The request itself is simple: state what data is inaccurate, what the correct version is, and provide any evidence you have (a document, a letter, a screenshot). The organisation has one month to respond.

One nuance worth knowing: if the data is a matter of opinion rather than fact, for example a manager's assessment of your performance, rectification doesn't force them to change their view. But you can ask for a note to be added to your record indicating that you dispute the accuracy.

Portability

The right to data portability under Article 20 lets you receive your personal data in a structured, commonly used, machine-readable format, and to transfer it to another organisation. In practice this applies to data you've actively provided (your account information, your usage history) where the legal basis for processing is consent or contract.

Where it's genuinely useful: switching energy suppliers, moving between financial platforms, or exporting your data from a social media account. Most major platforms now offer a data download tool, partly because of this right. The quality of what you get varies considerably.

Where it's limited: it doesn't cover data the organisation has derived or inferred about you, only data you provided. And there's no obligation on the receiving organisation to accept a transfer in any particular format.

Automated decisions

Article 22 gives you the right not to be subject to a decision that is based solely on automated processing and produces a significant effect on you. Think: a loan application rejected entirely by an algorithm, an insurance quote generated without any human review, or an automated recruitment screening tool that filters out your CV before a person sees it.

If you believe a significant decision about you was made solely by automated means, you can request human review of that decision. You can also ask the organisation to explain the logic involved. They don't have to reveal proprietary algorithms in full, but they do have to give you a meaningful explanation of how the decision was reached.

This right is underused, partly because people don't know it exists and partly because organisations don't always make it obvious when automated decision-making is happening. A SAR is a good way to find out.

Today's action: If you've recently been declined for credit, insurance, or a job, send a SAR and specifically ask whether any automated decision-making was used and what the logic was.

How to write a request that gets answered

The requests quoted above will work for most situations. A few practical points make them more effective.

Identify yourself clearly. Organisations are allowed to ask for enough information to confirm your identity before responding. Give your full name, the email address or account associated with your data, and an address if relevant. Don't hand over more than necessary: a copy of your passport is rarely needed for a routine SAR to a retailer, for example.

Cite the specific article. Including the UK GDPR article number (Article 15 for SARs, Article 17 for erasure, Article 21 for objection to marketing, and so on) signals that you know your rights and makes it harder for a less scrupulous organisation to fob you off with a vague response.

Use email and keep a record. Email creates a timestamp and a paper trail. If you use a contact form instead, take a screenshot confirming submission.

Be specific where you can. For a SAR, you can ask for everything, but if you're interested in a particular type of data (your call recordings, your credit file, your HR records) saying so helps. For erasure, name the specific data or account you want deleted.

Don't over-explain or over-apologise. You're exercising a legal right. A polite, direct paragraph is all you need. Long justifications can actually muddy the request.

Here is a general template structure you can adapt for any of these rights:

Element What to include
Opening line State the right you're exercising and the UK GDPR article number
Your identity Full name, account email or reference, postal address if relevant
The specific ask Exactly what you want: all data, deletion of a specific record, cessation of marketing, etc.
Confirmation request Ask them to confirm in writing when they've complied
Closing Polite sign-off; no threats needed at this stage
  • Draft your request using the structure above before you send it.
  • Email it to the organisation's data protection officer if listed, or their main contact address.
  • Note the date sent and set a reminder for 30 days.
  • Keep every response, even automated acknowledgements, in a dedicated folder.

When they ignore you: the escalation ladder to the ICO

Most organisations respond. Some don't, or they respond in a way that doesn't actually address your request. Here's what to do.

Step one: chase the organisation directly

If you haven't had a response within one month, send a follow-up. Reference your original request, the date you sent it, and note that the statutory deadline has passed. Keep it brief and factual. Sometimes requests get lost or misfiled, and a polite chase resolves it without escalation.

Step two: complain to the organisation formally

If the chase produces nothing, or if the response you received was inadequate, raise a formal complaint through the organisation's own complaints process. This matters because the ICO generally expects you to have tried to resolve the issue with the organisation first. A formal complaint also creates a record.

Step three: complain to the ICO

The ICO's online complaints process is straightforward. You'll need to explain what right you exercised, when you contacted the organisation, what response (if any) you received, and why you think it fell short. The ICO can investigate, issue reprimands, and in serious cases impose fines. For individuals, the most common outcome is that the ICO contacts the organisation and requires them to comply.

What the ICO does not do: it doesn't award compensation to individuals. If you want financial redress for damage caused by a data breach or unlawful processing, that requires a separate civil claim, either through the courts or via a law firm specialising in data protection. The ICO can, however, issue an enforcement notice that compels an organisation to act, and that notice can support a subsequent civil claim if you choose to pursue one.

One realistic note: the ICO handles a large volume of complaints and prioritises cases that have broader public interest implications or involve systemic failures. A single unanswered SAR from one individual may not result in a formal investigation, but it does get logged, and patterns of complaints against the same organisation do attract attention. Your complaint contributes to that picture even if it doesn't produce an immediate individual remedy.

Today's action: If you're already in a stalled situation with an organisation over your data, check the ICO's complaints page and start the process. It takes about fifteen minutes.

Marketing calls, texts and email: PECR, TPS and MPS

PECR sits alongside UK GDPR and specifically governs electronic marketing. The rules are stricter in some ways than general data protection law, and they apply to different situations.

Marketing emails and texts

Under PECR, organisations need your prior consent before sending you marketing emails or texts, unless you're an existing customer and the marketing relates to similar products or services you've bought from them before (the so-called soft opt-in). Consent must be freely given, specific, and informed. Pre-ticked boxes don't count.

If you receive marketing emails or texts you didn't consent to, you can report them to the ICO. The ICO has issued substantial fines under PECR for mass unsolicited marketing campaigns. For spam texts in particular, you can also forward them to 7726 (which spells SPAM on a phone keypad), which reports them to your mobile network and feeds into industry-level blocking systems.

Marketing phone calls

The Telephone Preference Service (TPS) is a free registration service that tells organisations you don't want unsolicited live marketing calls. Once registered, organisations are legally required to screen their call lists against the TPS register before dialling. If they call you after you've been registered for 28 days, they're in breach of PECR. You can register at tpsonline.org.uk and it costs nothing.

The Mailing Preference Service (MPS) does the equivalent for postal marketing. Less urgent for most people, but worth knowing about if unwanted post is a nuisance. Register at mpsonline.org.uk.

A few honest caveats about TPS. It works well against legitimate UK-based businesses. It does not stop nuisance calls from overseas operations or from organisations that simply ignore the register. If you receive a call after registering, note the date, time, and number, and report it to the ICO. Organisations that repeatedly breach TPS obligations do face enforcement action, though the ICO's resources mean not every complaint triggers an investigation.

Automated calls

Automated marketing calls (where a recorded message plays rather than a live person speaking) require explicit consent under PECR. They're not permitted under the soft opt-in. If you receive one without having consented, that's a clear PECR breach and worth reporting.

How PECR and UK GDPR work together

They're complementary. A company sending you marketing emails might be breaching PECR (by not having valid consent) and UK GDPR (by not having a lawful basis for processing your data) at the same time. Your Article 21 objection to direct marketing under UK GDPR applies alongside any PECR complaint. Use both levers if the situation calls for it.

  • Register with TPS if you haven't already: it takes two minutes and is free.
  • Forward unwanted marketing texts to 7726.
  • Report persistent email spam or unsolicited automated calls to the ICO via their online reporting tool.

The law gives you real tools here. They're not perfect, they don't stop every bad actor, and the ICO can't personally resolve every case. But pulling these levers, politely and consistently, does work. Organisations that receive SARs tend to tighten their practices. Companies that accumulate ICO complaints do face scrutiny. And you, at the end of this, know exactly what you're entitled to ask for and how to ask for it. That's not a small thing.

Last verified 21 July 2026. Settings move and companies change their terms, so every Vivid Zero guide is re-checked on a schedule and corrected the moment it drifts.

Questions people ask

How long does an organisation have to respond to a subject access request?
Under UK GDPR, an organisation must respond to a subject access request within one calendar month of receiving it. In complex cases they can extend this by a further two months, but they must tell you within the first month that they're doing so and explain why. If they miss the one-month deadline without explanation, that's a breach you can report to the ICO.
Can a company charge me for a subject access request?
In almost all cases, no. Subject access requests must be handled free of charge under UK GDPR. The only exception is if a request is manifestly unfounded or excessive, in which case the organisation can charge a reasonable fee or refuse to comply, but they must explain why. A straightforward first request should always be free.
What is the difference between unsubscribing from marketing and exercising my right to object?
Unsubscribing typically removes you from a mailing list but may leave your profile and data intact for other purposes. Exercising your Article 21 right to object to direct marketing under UK GDPR requires the organisation to stop all direct marketing processing and, if you also request it, to delete your data from marketing lists entirely. The right to object is legally stronger than a standard unsubscribe.
What can the ICO actually do for me if a company ignores my data rights?
The ICO can investigate the organisation, issue reprimands, and require them to comply with your request through an enforcement notice. What the ICO cannot do is award you financial compensation: that requires a separate civil claim. However, an ICO enforcement notice can support a civil case if you choose to pursue one, and repeated complaints against the same organisation do lead to formal investigations.
Does registering with the Telephone Preference Service stop all nuisance calls?
It stops calls from legitimate UK-based organisations that are required to screen against the TPS register. It does not stop overseas operations or organisations that deliberately ignore the rules. If you receive a call after registering (and waiting the 28-day bedding-in period), note the details and report it to the ICO. TPS is most effective against compliant businesses; it's not a complete solution for all nuisance calls.
Can I ask a company to delete all my data under the right to erasure?
You can ask, but the right to erasure has real limits. Organisations can refuse if they need the data to comply with a legal obligation, to defend a legal claim, or for certain public interest purposes. A bank, for example, is legally required to retain transaction records for a number of years. Where erasure works well is for marketing profiles, old unused accounts, and data held by brokers or aggregators where there's no overriding legal reason to keep it.
What is PECR and how is it different from UK GDPR?
PECR (the Privacy and Electronic Communications Regulations 2003) specifically governs electronic marketing: calls, texts, emails, and automated messages. Where UK GDPR covers personal data broadly, PECR sets stricter rules for direct marketing communications and requires prior consent in most cases. The two laws work together: a single marketing campaign can breach both simultaneously, and you can complain under both.
Do my data rights apply to automated decisions made about me, like a loan rejection?
Yes. Under Article 22 of UK GDPR, you have the right not to be subject to a decision based solely on automated processing that has a significant effect on you, such as a credit refusal or an insurance quote. You can request human review of such a decision and ask the organisation to explain the logic behind it. They don't have to reveal proprietary algorithms in full, but they must give you a meaningful explanation.

← All Vivid Zero guides