The legal framework
Protection rests on the Data Protection Act 2020, brought into operation with a transition period ending in 2023, and enforced by the Information Commissioner. The Act follows the GDPR structure closely, with eight standards and registration of data controllers. These statutes follow the familiar pattern: lawful basis, purpose limitation, security, and rights of access, correction and objection.
Key points
| Rights | Access, correction, objection, and erasure under the more recent statutes |
|---|---|
| Registration | Data controllers must often register with the regulator |
| Breach notification | Required under most of these Acts |
| Cross-border transfers | Permitted subject to adequacy or safeguards |
| Regulator | Office of the Information Commissioner |
| Sectoral rules | Telecommunications and financial regulators impose additional confidentiality duties |
| Phased implementation | Obligations were brought into force in stages |
| Data protection officer | Required for certain organisations |
| Offences | Unlawful obtaining and disclosure are offences |
In practice
- Write to the organisation first, citing the relevant statutory right; keep proof of the date.
- Set out clearly what you want: a copy of your data, deletion, or an end to marketing.
- If there is no adequate reply within the statutory period, complain to the regulator — it is free.
- For dating, health and fertility apps, ask specifically about third-party sharing and overseas transfers.
- Check which obligations were in force when your incident occurred.
- Complain to the Office of the Information Commissioner in writing.
Cost and coverage
Complaints to the regulator are free.
Recent changes
Digital lending applications that harvest contact lists have become the most common subject of enforcement across the region, alongside unsolicited marketing.
Where to go
- Office of the Information Commissioner — complaints and guidance.
- Telecommunications regulator for mobile and SMS abuse.
- Consumer protection body for related commercial disputes.
Worth knowing
Where a foreign platform is involved, the GDPR often applies in parallel if the company operates in Europe. Complaining in both places at once is legitimate and frequently faster. Because the Act was phased in, the obligations that applied depend on the date. Establish that before framing the complaint.
Official sources and links
- UN Human Rights Office — ratified treaties and country reviews
- ILO NATLEX — national legislation database
