Skip to content
Coverage

Data rights

UK GDPR and Data Protection Act 2018

NationalGBDerived or secondary source

United Kingdom

Rule id
data.uk-gdpr
Version
1.1.0
In force from
January 1, 2021
Last read against its sources
August 5, 2026
Countries bound
United Kingdom

In plain language

What this regime says.

UK GDPR gives you the same rights as the EU version, with a one-month deadline. The Data (Use and Access) Act 2025 added a proportionate-search standard, let controllers pause the clock while they seek clarification, and requires you to complain to the organisation before the ICO.

Who is covered

Anyone in the UK whose personal data is processed, and anyone whose data is processed by a UK controller.

What you get

The data, the correction, the deletion or the objection. Money is rare and needs proof of damage. A s. 167 court order to compel compliance is the strongest and least-used remedy.

Where claims go wrong

  • Ignoring a clarification or identity email. Under the DUAA that stops the clock, so the delay becomes yours rather than theirs.
  • Going to the ICO first. The route now runs through the organisation, with a 30-day acknowledgment.
  • Asking the ICO to get your data for you. It does not do that. DPA 2018 s. 167 does.
The official claim route

Authority

Every citation,
with its pinpoint.

A claim that cites “EU law” gets filed. A claim that cites Article 7(1)(c) gets answered. These are the exact coordinates this entry rests on.
  1. UK GDPR Arts. 15–21 and Data Protection Act 2018UK General Data Protection Regulation, read with the Data Protection Act 2018 (c. 12)URL verified 2026-08-05Arts. 12–22; DPA 2018 Parts 2 and 6
  2. UK GDPR Art. 12(3) — one month to respond, extendable by two further monthsRetained Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern IrelandURL verified 2026-08-05Art. 12(3)
  3. UK GDPR Art. 15 — right of accessUK General Data Protection RegulationURL verified 2026-08-05Art. 15
  4. Data Protection Act 2018, s. 167 — court order to comply with a data subject requestData Protection Act 2018URL verified 2026-08-05s. 167
  5. Data Protection Act 2018, s. 168 — compensation for material or non-material damage, including distressData Protection Act 2018URL verified 2026-08-05s. 168
  6. Data (Use and Access) Act 2025Data (Use and Access) Act 2025 (c. 18), Royal Assent 19 June 2025URL verified 2026-08-05

Sources

Where a figure is indexed, converted or published by a regulator rather than fixed in the instrument, the provenance is recorded separately. Anything marked as a modelled estimate is exactly that — a model, not a statutory number.

What it imposes

Clocks, defences and the ladder.

A rule module builds these while it evaluates, because a limitation period depends on which forum is open to you. What follows is the structure this regime produces — deliberately with no dates and no figures, because those belong to your facts rather than to the law.

The clocks it starts

  • UK GDPR and Data Protection Act 2018: deadline for the controller to respondArt. 12(3) UK GDPR: without undue delay and in any event within one month of receipt. The ICO treats "one month" as the corresponding date in the next month.UK GDPR Art. 12(3) — one month to respond, extendable by two further months — Art. 12(3)Response due
  • UK GDPR and Data Protection Act 2018: extended deadline if the controller notified an extensionTwo further months are available where the request is complex or you have made a number of requests — but the controller must tell you, and give reasons, within one month of receipt.UK GDPR Art. 12(3) — one month to respond, extendable by two further months — Art. 12(3)Response due

What it entitles you to, beyond money

  • Compliance with your access requestConfirmation that your data is processed, the Art. 15(1) information, and a copy of the data itself. Free. The Data (Use and Access) Act 2025 confirms that the controller need only carry out a reasonable and proportionate search — which is a standard you can hold them to, not just a limit on what you get.Art. 15

What the other side will say

Each of these is a refusal this regime lets a counterparty attempt, paired with the answer to it. Reading them before you write is worth more than any amount of polish on the letter itself.

"We carried out a reasonable and proportionate search"

high likelihood

The Data (Use and Access) Act 2025 requires only a reasonable and proportionate search. We searched our main system and found nothing further.

What answers it

Proportionate is not the same as minimal, and the controller has to be able to describe what it did. Ask, in writing, for: the systems searched, the systems NOT searched and why, the search terms and identifiers used, the date range covered, and whether backups, archived mailboxes, call recordings, CRM notes and third-party processors were within scope. Then name the systems you know they hold your data in — the ones you have interacted with. A search that omits a system you can prove exists is not proportionate.

Data (Use and Access) Act 2025

The clock stopped because they asked you something

high likelihood

We wrote to you asking for clarification on 3 March. The statutory period was suspended until you replied.

What answers it

Check two things. First, was the request for information the controller reasonably required — a genuine need to identify you or to narrow a genuinely unclear request — or a pro-forma stall sent to everyone? Second, did the clock restart when you answered? Reply in writing, dated, and restate the deadline as running from the date of your reply. If you already answered and they carried on treating the clock as stopped, that is a straightforward breach with a paper trail.

Data (Use and Access) Act 2025

The ICO bounces you back to the organisation

high likelihood

The ICO cannot look at this until you have raised it with the organisation and given them the chance to respond.

What answers it

This is now the intended route rather than a brush-off, so work with it rather than against it. Send a formal complaint to the organisation, using the word "complaint", to its data protection officer or privacy team. The organisation must acknowledge within 30 days. Diarise it. When it lapses, go back to the ICO with the complaint, the acknowledgment (or its absence), and the dates — a complaint with a documented failed internal stage is much stronger than one without.

Data (Use and Access) Act 2025

Endless identity verification

high likelihood

We cannot action your request until you verify your identity. Please send a copy of your passport, a utility bill, and a selfie holding your ID.

What answers it

A controller may use reasonable measures to verify identity, but it may only ask for information it actually needs and already holds a basis to check. Demanding a passport scan from someone whose account you identify by email address is disproportionate and is itself a data-minimisation problem. Offer to verify through the same channel you already use to log in, state that you consider the demand excessive, and note that the response clock is running.

"We hold no personal data about you"

high likelihood

A search of our systems returned no personal data relating to you.

What answers it

Ask for that in writing, signed, together with a description of the systems searched and the search terms used. A nil return is a substantive answer that the controller must stand behind, and it is frequently wrong: it usually means one production database was searched and backups, CRM, marketing, support tickets, call recordings, and third-party processors were not. Name the systems you believe hold your data, including any you have interacted with.

Blanket confidentiality or trade-secret refusal

medium likelihood

The information you have requested is commercially confidential / contains our trade secrets / is proprietary.

What answers it

Confidentiality and intellectual-property carve-outs are narrow and must be applied item by item, not as a blanket. The correct response is redaction of the protected element and disclosure of the rest, with a schedule explaining what was withheld and why. Ask for that schedule.

Refusal because the data mentions someone else

medium likelihood

We cannot disclose these records because they contain the personal data of other individuals.

What answers it

The presence of third-party data is a reason to redact, not to refuse. The controller must consider whether it can disclose with the third party removed, whether the third party has consented, and whether it is reasonable to disclose without consent. A blanket refusal on this ground is not a lawful answer.

"Your request is manifestly excessive"

medium likelihood

Your request is manifestly unfounded or excessive, so we are refusing it / charging a fee.

What answers it

The burden of showing that a request is manifestly unfounded or excessive is on the controller, and it is a high bar — the regulator guidance treats it as exceptional, not as a routine response to a broad request. Ask the controller to state, in writing, the specific grounds and the evidence for them. If you have made only one request, say so. A single, first, ordinary request is not excessive.

Where to take it next

  1. Written request to Sample ControllerSend it to the named data-protection contact or privacy team, in writing, and keep proof of the date. If the organisation has a designated Data Protection Officer, address it to them by title. Use the word "request" and name the right you are exercising.Claim directtypically 30 days
  2. Internal appeal / complaint to the controllerComplain to the organisation itself first, in writing, using the word "complaint" and addressing it to the data protection officer or privacy team. Under the Data (Use and Access) Act 2025 the organisation must acknowledge a data protection complaint within 30 days. Keep the date you sent it; the ICO will ask.Internal appealtypically 45 days
  3. County court order under DPA 2018 s. 167A court may order a controller to take the steps necessary to comply with your request. This is a compliance order, not a damages claim, and it is the right tool when the thing you want is the data. It can be brought in the county court, and the prospect of one concentrates minds far more than an ICO complaint does. Consider it where the data matters to something else — an employment dispute, a credit refusal, an insurance decision.Courttypically 180 days
  4. Compensation claim under DPA 2018 s. 168Compensation for material or non-material damage, expressly including distress. Bring it only where you can describe concrete harm. Lloyd v Google [2021] UKSC 50 means "they had my data and shouldn't have" is not by itself a claim.Courttypically 270 days
  5. Complain to the Information Commissioner's Office (ICO)the Information Commissioner's Office (ICO) takes complaints from individuals about a specific organisation's handling of a specific request. It is free. Attach your original request, proof of the date you sent it, and anything the organisation sent back.Regulatortypically 150 daysofficial page

Documents

What this regime can produce.

Every one of these is a document you send yourself, in your own name. Duesday never writes to anybody on your behalf and is never anyone’s agent.

The same claim type elsewhere

Other rights in the same countries

England & Wales — tenancy deposit protection (Housing Act 2004 ss. 213–215)GB-EAWSub-nationalUnited KingdomHousing Act 2004, s. 213Confidence: highEngland & Wales — unclaimed estates and bona vacantia (Administration of Estates Act 1925 s. 46)GB-EAWSub-nationalUnited KingdomAdministration of Estates Act 1925 (c. 23), s. 46(1)(vi)Confidence: mediumGreat Britain — Delay RepayGBNationalUnited KingdomNational Rail Conditions of TravelConfidence: mediumNorthern Ireland — tenancy deposit schemes (SR 2012/373, as amended 2023)GB-NIRSub-nationalUnited KingdomTenancy Deposit Schemes Regulations (Northern Ireland) 2012Confidence: mediumScotland — tenancy deposit schemes (SSI 2011/176)GB-SCTSub-nationalUnited KingdomTenancy Deposit Schemes (Scotland) Regulations 2011, reg. 3Confidence: highConsumer Credit Act 1974 s.75 (and s.75A) — creditor joint and several liabilityGBNationalUnited KingdomConsumer Credit Act 1974, s.75Confidence: highUK Consumer Contracts Regulations 2013 (and the not-yet-commenced DMCCA subscription regime)GBNationalUnited KingdomConsumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013 (SI 2013/3134)Confidence: highUK Privacy and Electronic Communications Regulations 2003GBNationalUnited KingdomPrivacy and Electronic Communications (EC Directive) Regulations 2003, regs. 19–24 and reg. 30Confidence: medium

Does this one reach your facts?

The engine runs every regime that could apply at once and reconciles them, rather than making you guess which page to read.

Not a law firm. Not legal advice. You send it yourself. This page describes a law; it is not advice about your situation and no outcome is promised.