The legal framework
Protection rests on the Data Protection Act 2011, only partially proclaimed, so that some provisions are in force and others are not. Full commencement has been pending for years, which leaves significant gaps in enforceable rights. These statutes follow the familiar pattern: lawful basis, purpose limitation, security, and rights of access, correction and objection.
Key points
| Rights | Access, correction, objection, and erasure under the more recent statutes |
|---|---|
| Registration | Data controllers must often register with the regulator |
| Breach notification | Required under most of these Acts |
| Cross-border transfers | Permitted subject to adequacy or safeguards |
| Regulator | Office of the Information Commissioner |
| Sectoral rules | Telecommunications and financial regulators impose additional confidentiality duties |
| Partially proclaimed | Only the general principles and the Commissioner's office are in force |
| Private sector | Substantive obligations on private organisations are not yet operative |
| Freedom of Information Act | Applies to public authorities and is fully in force |
| Constitutional motion | The realistic route for serious privacy breaches |
In practice
- Write to the organisation first, citing the relevant statutory right; keep proof of the date.
- Set out clearly what you want: a copy of your data, deletion, or an end to marketing.
- If there is no adequate reply within the statutory period, complain to the regulator — it is free.
- For dating, health and fertility apps, ask specifically about third-party sharing and overseas transfers.
- Use the Freedom of Information Act where a public authority holds the records.
- For private sector breaches, take advice on a constitutional or common law claim.
Cost and coverage
Complaints to the regulator are free.
Recent changes
Digital lending applications that harvest contact lists have become the most common subject of enforcement across the region, alongside unsolicited marketing.
Where to go
- Office of the Information Commissioner — complaints and guidance.
- Telecommunications regulator for mobile and SMS abuse.
- Consumer protection body for related commercial disputes.
Worth knowing
Where a foreign platform is involved, the GDPR often applies in parallel if the company operates in Europe. Complaining in both places at once is legitimate and frequently faster. The unproclaimed status of most of the Act is the central fact here. Do not assume rights that exist on paper are actually in force.
Official sources and links
- UN Human Rights Office — ratified treaties and country reviews
- ILO NATLEX — national legislation database
