The UK GDPR is the main general framework for personal data.
It sets principles for processing, lawful bases, transparency duties and individual rights such as access, rectification, erasure, restriction and objection. The exact right available depends on the processing and statutory conditions.
In consumer disputes, accuracy and access often matter most.
A SAR can expose what personal data is held and how it is used. Rectification can be relevant where factual personal data is inaccurate. Neither right automatically decides the underlying contract, debt or service dispute.
Read it with the Data Protection Act 2018.
The UK framework is not complete if the UK GDPR is read in isolation. The DPA 2018 contains important supplementary rules, exemptions, enforcement provisions and special regimes.
Escalation and compensation are separate.
If the organisation does not resolve a data-protection complaint, the ICO can consider regulatory compliance. If you seek compensation for material or non-material damage, that may require a separate negotiated or court remedy. Do not assume an ICO complaint itself awards damages.
The controller should be able to explain its decision.
Ask for the lawful basis, purpose, source, retention logic and recipients where relevant. If exercising a right, identify the data and the outcome requested. Since June 2026, data-protection complaints to organisations also sit within a statutory complaint-handling framework, including acknowledgement requirements.
A right is not automatically absolute just because it exists in the UK GDPR.
Rights have conditions and exceptions. Erasure does not mean every record must be deleted on request. Objection has different effects depending on the lawful basis and purpose. Access can be restricted by exemptions in the DPA 2018. The useful question is not “do I have a right?” but “are the statutory conditions for this right met in these circumstances?”
For consumers, rights are usually triggered by a specific problem.
| Problem | Right/rule to consider |
|---|---|
| “What data do you hold about me?” | Subject access |
| “This record is wrong.” | Accuracy principle and rectification |
| “Stop using this while accuracy is disputed.” | Restriction, where the conditions are met |
| “Delete this data.” | Erasure, subject to conditions/exceptions |
| “Why are you using my data?” | Transparency and lawful basis |
| “A significant decision was made entirely by a system.” | Current automated-decision safeguards under the amended framework |
The UK GDPR is the core personal-data rulebook, but not the whole rulebook.
It governs principles such as lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security and accountability, alongside lawful bases and individual rights. In practice it must be read with the Data Protection Act 2018 and amendments made by the Data (Use and Access) Act 2025.
Official sources
Check the current source material.
- UK GDPR text ↗
- ICO: Subject access requests ↗
- ICO: UK GDPR guidance ↗
- ICO: DUAA data-protection changes ↗
ConsumerWise provides general information rather than individual legal advice. Check current rules, dates and eligibility against the official source before acting.