UK data-protection law is a framework of principles, lawful bases, individual rights and accountability duties - not just a rule about consent.
The UK GDPR and Data Protection Act 2018 remain the core data-protection framework. The Data (Use and Access) Act 2025 amended parts of that framework but did not replace it. All DUAA provisions affecting data protection were in force by 19 June 2026.
For consumers, the framework matters because it controls how organisations collect, use, share, retain, secure and correct personal data, and it gives enforceable rights such as access, rectification, erasure in qualifying cases, restriction and objection.
Key points
- An organisation needs a lawful basis for processing, but consent is only one possible basis.
- The data-protection principles include lawfulness/fairness/transparency, purpose limitation, data minimisation, accuracy, storage limitation and security.
- Special-category data has additional protections.
- Individual rights operate alongside exemptions and restrictions in the DPA 2018 and other law.
- The DUAA changed some procedures, including SAR searches, time-limit rules, automated decision-making and organisational complaint handling.
The principles are the foundation
The principles are not abstract slogans. They help test real disputes. If a company keeps an incorrect date of birth and then uses it to classify a customer incorrectly, the accuracy principle is directly relevant. If it keeps data for longer than necessary, storage limitation may be relevant. If it uses data for a purpose the person would not reasonably expect, fairness, transparency and purpose limitation can matter.
Lawful basis does not mean “they can do anything”
An organisation can sometimes process personal data without consent - for example where processing is necessary for a contract, legal obligation or legitimate interests. But it still has to comply with the other principles and any conditions applying to the particular data. A lawful basis does not excuse inaccurate, excessive or insecure processing.
The DPA 2018 supplies UK-specific rules and exemptions
The Data Protection Act 2018 supplements the UK GDPR and contains separate regimes for law-enforcement and intelligence processing. It also contains exemptions that can limit particular rights in defined circumstances. An organisation should identify the actual exemption and apply it to the relevant information rather than using “data protection” as a vague reason to withhold everything.
What the DUAA changed
The Data (Use and Access) Act 2025 clarified that SAR searches need only be reasonable and proportionate, introduced “stop the clock” rules for reasonably required clarification, changed automated-decision rules, and from 19 June 2026 requires organisations to operate a data-protection complaints process for qualifying complaints. Always check current ICO guidance because the regulator has been updating individual-rights material as these provisions came into force.
In practice
- Identify the specific data, processing activity and right/principle at issue.
- Do not frame every data dispute as “GDPR breach”; explain the concrete failure.
- Use SARs to obtain personal data, not as a substitute for every other disclosure process.
- Where accuracy is disputed, distinguish incorrect fact from a genuinely held opinion or allegation.
What to do
A practical next-step plan
- Identify the personal data and processing activity.
- Check the relevant principle, lawful basis or individual right.
- Write to the organisation with a focused request or complaint.
- Keep the response and evidence of consequences.
- Use the ICO route if the organisation does not resolve a data-protection complaint and the issue falls within the ICO’s remit.
Common traps
Things that often confuse the issue
- Consent is not the only lawful basis.
- A SAR does not entitle you to every document in unredacted form; the right is to your personal data plus supplementary information.
- An exemption is not a magic word - its scope and application matter.
- The UK GDPR should now be read alongside DUAA amendments and current ICO guidance.
Evidence worth keeping
Official sources
Check the rules behind this guide
- A guide to subject access - ICO
- Time limits for data-protection rights requests - ICO
- Accuracy principle - ICO
- Right to rectification - ICO
These are official or primary sources for this topic. Rules, scheme terms and deadlines can change, so check the live source before relying on a formal time limit or procedure.