UK GDPR statutory framework — Articles 12–22 and the eight individual rights
Material update as of June 2026 — Data (Use and Access) Act 2025 amendments now partially in force
The UK GDPR data subject rights framework, originally mirroring the EU GDPR's Articles 12–22, is now subject to phased amendments via the Data (Use and Access) Act 2025 (DUAA 2025). These include major procedural and operational changes affecting all eight individual rights, notably through the insertion of Article 12A (stop-the-clock mechanism), revisions to the response time regime, and expanded grounds for pausing deadlines on DSARs and other rights requests.
Legislative framework and structure (as of June 2026)
- Transposition and structure: Upon Brexit, Regulation (EU) 2016/679 was transposed to domestic law, and further amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 and the DUAA 2025. Chapter III (Articles 12–22) remains the cornerstone, setting out the recognized individual rights, subject to derogations and exemptions found in the Data Protection Act 2018 (primarily Schedule 2).
- Eight individual rights (Articles 13–22): The full rights, with current statutory text (as amended), are:
- Right to be informed (Articles 13–14)
- Right of access (Article 15)
- Right to rectification (Article 16)
- Right to erasure (Article 17)
- Right to restriction of processing (Article 18)
- Right to data portability (Article 20)
- Right to object (Article 21)
- Rights related to automated decision-making and profiling (Article 22)
DUAA 2025 reforms — effective dates and scope
- Stop-the-clock rule — New Article 12A: Effective in phases from February 2026, controllers may now pause the statutory one-month response clock while they confirm a requester’s identity or seek necessary clarification as to the scope of a request. The controller must promptly communicate the pause and resume the deadline when clarification is received. This applies to all rights requests under Articles 12–22. (See DUAA 2025 Sch. 10)
- Reasonable and proportionate search — Article 15(1A): Controllers’ search obligations are now explicitly subject to a “reasonable and proportionate” standard, codifying long-standing ICO guidance (commencement expected in 2026; practitioners should confirm in-force status for each provision).
- Retention of the eight rights: No rights have been removed, but the operational rules for processing requests—including clarification, fee, and response timing—are altered. Controllers must review and update internal protocols.
- ICO guidance and CJEU influence: UK courts and the ICO are not bound by post-Brexit CJEU judgments but continue to use EDPB/existing CJEU interpretations as persuasive. ICO guidance has been substantially refreshed in light of the DUAA 2025.
Exemptions and restrictions remain in Schedule 2 DPA 2018: Exemptions to rights, including those for crime, tax, legal privilege, research, and others, persist and continue to operate on a fact-specific, proportionality-tested basis.
Controllers should now reference new Articles 12A and 15(1A) in all privacy documentation and internal training, update response protocols to document and communicate justified pauses, and monitor commencement regulations for further phased amendments under the DUAA 2025.
This section was updated in June 2026 to reflect the phased commencement of the DUAA 2025 (notably new Article 12A, revised response deadlines, and the codified proportionate-search standard). Practitioners should check which amendments are in force as of the request date.
Source: Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (S.I. 2019/419) Source: Data Protection Act 2018 Source: Data (Use and Access) Act 2025, Part 5 and Schedule 10 (new Article 12A and amendments to Articles 12, 13, 14, 15) Source: ICO: A guide to individual rights
Subject access request fees — Article 12(5) UK GDPR and the manifestly unfounded or excessive test
The general rule: SARs are free of charge
Article 12(5) of the UK GDPR establishes that information provided under Articles 13 and 14 (transparency obligations) and any actions taken under Articles 15–22 and 34 (data subject rights and breach notification) must be provided free of charge. This means that controllers ordinarily cannot charge a fee to comply with a subject access request (SAR) made under Article 15, nor may they charge for providing supplementary information such as the processing purposes, categories of data, recipients, retention periods, or the source of data not obtained directly from the individual.
The abolition of routine SAR fees represents a significant shift from the Data Protection Act 1998 regime, which permitted a standard £10 fee (£2 for credit reference agency requests). The UK GDPR removed this permission, reflecting the policy that access to one's own personal data is a fundamental right that should not be subject to financial gatekeeping. Section 12 of the Data Protection Act 2018 confirms this position and empowers the Secretary of State to specify fee limits by regulation, though no such limits have been enacted as of May 2026.
Exceptions: when controllers may charge a reasonable fee
Article 12(5) UK GDPR creates two narrow circumstances in which a controller may charge a reasonable fee:
- Manifestly unfounded or excessive requests — Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, the controller may either:
- charge a reasonable fee taking into account the administrative costs of providing the information or taking the action requested; or
- refuse to act on the request.
- Further copies — Under Article 15(3) UK GDPR, where a data subject requests further copies of personal data following an initial request, the controller may charge a reasonable fee based on administrative costs.
The burden of demonstrating that a request is manifestly unfounded or excessive rests with the controller (Article 12(5), second sentence). Controllers must be able to explain their reasoning clearly to both the data subject and the Information Commissioner's Office (ICO) if challenged. The ICO emphasizes that controllers must have "strong justifications" and assess each request on a case-by-case basis — blanket policies deeming all requests from a particular individual or source excessive are not permitted.
What constitutes "manifestly unfounded"?
The ICO guidance interprets "manifestly unfounded" to mean that the request is obviously without merit or purpose. The inclusion of "manifestly" signals that the unfounded character must be clear and evident. A request may be manifestly unfounded if:
- The individual clearly has no genuine intention to exercise their right of access (for example, offering to withdraw the request in return for some benefit from the organization);
- The request is malicious in intent or made with the purpose of harassing the organization, with no real purpose other than to cause disruption;
- The request forms part of a broader pattern of vexatious or abusive conduct.
The test is not whether the request is inconvenient or time-consuming for the controller. If the individual has a legitimate interest in obtaining their data — even if their ultimate purpose is to use that data in litigation or to scrutinize the controller's compliance — the request is not manifestly unfounded. Pre-litigation "fishing" requests that seek personal data the individual is entitled to receive remain valid SARs, though controllers may apply relevant exemptions (such as legal professional privilege under Schedule 2, Part 2, paragraph 19 of the DPA 2018) to specific categories of information where the conditions are met.
What constitutes "manifestly excessive"?
The ICO guidance, updated in October 2020 and refined following the Data (Use and Access) Act 2025, explains that a request is "manifestly excessive" if it is clearly or obviously unreasonable. Controllers should assess whether the request is proportionate when balanced against the burden or costs involved in complying.
Factors controllers should consider include:
- Whether the request largely repeats previous requests and a reasonable interval has not elapsed since the last request. Repeated requests for the same information within a short period (for example, weekly or monthly SARs covering the same dataset when nothing material has changed) are more likely to be excessive. The ICO has noted that monthly requests may be excessive if the data has not changed and the individual has already received a complete response.
- The nature and context of the request. A single request covering a large volume of data is not automatically excessive simply because of its scope. If the controller processes substantial amounts of personal data about the individual (for example, years of employment records, extensive transaction histories, or comprehensive health data), the individual is entitled to request all of it, and the controller's obligation to maintain retrievable records supports this.
- The purpose and proportionality. If the volume of information requested is proportionate to the individual's legitimate interest in accessing it (for instance, preparing for litigation or verifying compliance), the request is less likely to be excessive.
- Repeated requests in different formats. Updated ICO guidance acknowledges that if an individual repeatedly requests further copies in different formats after already downloading data from a portal (and has not objected to using the portal), those subsequent requests may be treated as manifestly unfounded or excessive, allowing the controller to charge a fee or refuse.
Importantly, the 2025 Data (Use and Access) Act amendments to Article 12 introduced a "stop the clock" mechanism (new Article 12A) that allows controllers to pause the one-month response deadline when clarification is reasonably required. This reduces the need to rely on the "manifestly excessive" ground where the real issue is that the request is unclear or overly broad and the controller needs the data subject's help to narrow it. Controllers should first ask for clarification rather than immediately characterizing a broad request as excessive.
What is a "reasonable fee"?
Neither the UK GDPR nor the DPA 2018 defines "reasonable fee." Section 12(1) of the DPA 2018 empowers the Secretary of State to specify fee limits by regulation, but no regulations have been made. In practice, the ICO guidance states that a reasonable fee should:
- Be based on the administrative costs actually incurred in responding to the request (staff time at an appropriate hourly rate, costs of retrieval, redaction, and copying);
- Not be punitive or designed to deter the exercise of data subject rights;
- Reflect the actual burden of the specific request, not a blanket charge.
Controllers must notify the data subject of the fee before complying with the request. Under Article 12(5), the controller is not required to act on the request until the fee is paid. The one-month response deadline under Article 12(3) (as amended by the DUAA 2025 to refer to "the applicable time period" defined in new Article 12A) runs from the date the fee is received, not the date the request was made.
Third-party data and the protection-of-rights exemption
A related but distinct issue arises when personal data requested in a SAR contains information that would disclose another identifiable individual. Paragraph 16 of Schedule 2, Part 3 of the DPA 2018 provides that Article 15(1)–(3) UK GDPR does not oblige a controller to disclose information to the data subject to the extent that doing so would involve disclosing information relating to another individual who can be identified from the information, unless:
- The other individual has consented to the disclosure; or
- It is reasonable to disclose the information without the other individual's consent.
In determining reasonableness, controllers must consider all relevant circumstances, including any duty of confidentiality owed to the other individual, any steps taken to seek that individual's consent, whether the other individual is capable of giving consent, and any express refusal of consent. This is not a fee-related provision but an exemption that permits redaction or withholding of third-party personal data in appropriate cases. Controllers should apply this exemption carefully and on a case-by-case basis, redacting only the minimum necessary to protect the third party's rights.
ICO enforcement and the importance of documentation
Controllers who charge a fee or refuse a SAR on the grounds that it is manifestly unfounded or excessive must document their reasoning comprehensively. The ICO has enforcement powers under Part 6 of the DPA 2018, including the power to issue information notices, assessment notices, and enforcement notices, and may impose administrative fines under Article 83 UK GDPR for failure to comply with Chapter III rights. A data subject who is refused access or charged a fee may complain to the ICO or apply to the court for an order requiring compliance or for compensation (Article 79 and Article 82 UK GDPR).
The ICO's published case decisions show that assertions of "excessive" requests are scrutinized closely, particularly in employment or litigation contexts where the individual has a legitimate interest in the data. Controllers should not conflate "inconvenient" or "large in scope" with "excessive" — the test is whether the request is manifestly (obviously, clearly) excessive when balanced against the fundamental right of access.
Source: Article 12, UK GDPR (Regulation (EU) 2016/679 as retained in UK law) Source: Data Protection Act 2018, section 12 (fees) Source: Data Protection Act 2018, Schedule 2, Part 3, paragraph 16 (protection of rights of others) Source: ICO: A guide to subject access Source: Data (Use and Access) Act 2025, sections 75–78 (amendments to Article 12 and new Article 12A)
Right to erasure (Article 17 UK GDPR) — the seven grounds (as of 31 March 2026), five exceptions, and children's-data emphasis
Article 17 of the UK GDPR establishes the right to erasure (the "right to be forgotten"), entitling data subjects to require controllers to erase their personal data without undue delay where one of the statutory grounds applies.
Material update as of 31 March 2026: A seventh ground for erasure has been introduced by section 31 of the Victims and Prisoners Act 2024 (as commenced by SI 2026/317), expanding Article 17(1) from six to seven erasure grounds. This new ground applies when a data subject’s information was processed in connection with a "malicious allegation"—specifically where (1) personal data was processed as a result of an allegation made by a malicious person, and (2) the data controller has determined to take no further action in respect of the allegation. The definition of "malicious person" and evidentiary requirements are set in the 2024 Act and its guidance.
The seven grounds for erasure (effective 31 March 2026):
- No longer necessary (Art. 17(1)(a)) — Data are no longer needed for the purposes initially collected.
- Withdrawal of consent (Art. 17(1)(b)) — Data subject withdraws consent and there is no other lawful basis.
- Successful objection (Art. 17(1)(c)) — Data subject objects under Article 21 and there are no overriding legitimate grounds.
- Unlawful processing (Art. 17(1)(d)) — Processing was unlawful.
- Legal obligation to erase (Art. 17(1)(e)) — Erasure required by UK law.
- Children’s information-society services (Art. 17(1)(f)) — Data about children collected through online services; the ICO emphasizes the enhanced right here (see Recital 65 and ICO guidance).
- Malicious allegations ground (Art. 17(1)(g)) — new, effective 31 March 2026 — Personal data processed in the context of an allegation made by a malicious person, where the controller has decided no further action will be taken.
Exceptions and children’s data emphasis: Article 17(3) lists five exceptions: (a) freedom of expression/information; (b) compliance with legal obligation or public-interest task; (c) public health/public interest; (d) archiving/research/statistics (see new Article 84B, effective after DUAA 2025); and (e) establishment/exercise/defence of legal claims. Schedule 2 of the Data Protection Act 2018 provides additional UK-specific exemptions. Controllers must assess all exceptions and exemptions case by case and document any reliance on them.
Child data emphasis: The ICO continues to highlight that children’s data—especially where consent was originally provided by or for a minor online—warrants particular weight. The ICO's guidance and Recital 65 underscore the policy that child erasure requests should generally be honored unless a compelling countervailing reason applies.
Procedural and operational duties: Where erasure is required, controllers must also notify recipients (Art. 17(2) & Art. 19). Privacy operations, privacy notices, and internal policies should be updated to reflect the seventh ground as of March 2026.
Sources: Source: Article 17, UK GDPR (as amended) Source: Victims and Prisoners Act 2024, section 31 (amendment to Article 17) Source: Data Protection Act 2018, Schedule 2 (exemptions) Source: ICO: Right to erasure guidance Source: Data (Use and Access) Act 2025, section 66 (new Article 84B) Source: SI 2026/317: Commencement of Article 17(1)(g) ground
This section was materially updated in April 2026 to reflect the addition of Article 17(1)(g) effective 31 March 2026. The broken link for the Victims and Prisoners Act 2024, section 31 has been repaired to the current official location as of June 2026; there have been no material legal changes since the last revision.
Right of access (Article 15 UK GDPR) — confirmation of processing, copy of data, and the nine categories of supplementary information
Article 15 of the UK GDPR provides the right of access—commonly known as a subject access request (SAR)—entitling individuals to confirmation of processing, a copy of personal data, and nine categories of supplementary information about that processing. This remains a cornerstone right, with high volumes of enforcement activity and operational scrutiny from the Information Commissioner’s Office (ICO).
Material guidance update as of April–June 2026: While the underlying statutory text (Article 15, UK GDPR as retained) has not changed since the Data (Use and Access) Act 2025 (DUAA 2025), the ICO published substantially revised guidance in April 2026. Key operational changes include:
- The response period for SARs can now be paused ("stop-the-clock") where clarification from the requester is genuinely required, not only where a large volume of data is held. This reflects the full commencement of DUAA 2025, Sch. 10 and ICO implementation as of April–June 2026.
- Controllers must conduct a reasonable and proportionate search for personal data in response to Article 15 requests. Exhaustive, burdensome, or disproportionate searches are not required; the search should balance administrative cost, time, and complexity—as codified in Article 15(1A) and clarified in updated ICO guidance.
- Refusal notices and responses to SARs must expressly inform the requester of both the controller’s internal complaints procedure and the judicial remedy pathway. This reflects new statutory requirements (DUAA 2025, s. 103, in force 19 June 2026) and evolving ICO enforcement expectations.
Structure of the right (Article 15 provisions)
- Confirmation of processing: Controllers must state whether or not personal data on the requester is held. "No data held" is valid if a reasonable and proportionate search was conducted.
- Access to personal data: Where data is held, the controller must provide an intelligible copy. Article 15(3) requires provision of the personal data itself, not mere descriptions.
- Nine categories of supplementary information: Controllers must furnish the information set out in Article 15(1)(a)-(h) and 15(2), including: purposes; categories of data; specific recipients; retention period or criteria; rights of rectification, erasure, restriction, and objection; right to lodge a complaint with the ICO; source of data not collected from the data subject; existence of automated decision-making; and, if relevant, transfer safeguards for data sent overseas.
- Third-party and rights-of-others limitation: Data that would identify third parties must be redacted unless disclosure is reasonable or consent is obtained (see DPA 2018 Sch. 2, para. 16).
Current practice standard: Controllers must align privacy operations and internal training with these updated mechanics. Where clarification is sought, the statutory response period is paused until the requester responds. The proportionality provision limits the breadth of required searches—controllers must document their reasoning and be prepared to justify the scope if challenged. SAR refusal or fee notices must now set out internal complaint and judicial escalation routes.
Material guidance change: Section updated June 2026 to reflect the ICO’s April 2026 SAR guidance revision and the commencement of DUAA 2025 response-protocol amendments (stop-the-clock, reasonableness standard, new notification duties) as of June 2026. Previous substantive law summary remains accurate, but all compliance teams should review SAR handling procedures accordingly.
Source: Article 15, UK GDPR (Regulation (EU) 2016/679 as retained in UK law) Source: Data (Use and Access) Act 2025, Schedule 10, paragraphs 5 and 6 (amendments to Article 15 and new Article 12A) Source: Data Protection Act 2018, Schedule 2, Part 3, paragraph 16 (protection of rights of others) Source: ICO: Right of access guidance (updated April–June 2026)
Right to object (Article 21 UK GDPR) — absolute direct-marketing right, compelling-legitimate-grounds test for Article 6(1)(e)/(f) processing, and automated objection mechanisms
Article 21 of the UK GDPR establishes the right to object, which entitles data subjects to require controllers to stop processing their personal data in specified circumstances. The right operates on three distinct levels, each with different procedural requirements and controller obligations. The right to object to direct marketing (including profiling for direct marketing) is absolute — controllers must cease processing immediately and have no grounds to refuse. The right to object to processing based on legitimate interests (Article 6(1)(f)) or public task (Article 6(1)(e)) is not absolute — controllers may continue processing if they demonstrate compelling legitimate grounds that override the data subject's interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defence of legal claims. The right to object to processing for scientific or historical research purposes or statistical purposes is limited to cases where the processing is not necessary for the performance of a task carried out for reasons of public interest. Article 21 is one of the most frequently invoked data subject rights in practice, and the Information Commissioner's Office (ICO) emphasizes that controllers must train staff across all customer-facing functions to recognize and escalate objections, particularly given that objections may be made verbally, in writing, or to any part of the organization.
The three-tier structure of Article 21 UK GDPR
Article 21 creates three distinct objection rights, each tied to a specific lawful basis or processing purpose and each with a different controller obligation:
1. Right to object to legitimate-interests or public-task processing (Article 21(1) and (3))
Article 21(1) UK GDPR provides that the data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on point (e) or (f) of Article 6(1) (public task or legitimate interests), including profiling based on those provisions. The Data (Use and Access) Act 2025 (DUAA), which received Royal Assent on 19 June 2025, amended Article 21(1) by inserting the word "clearly" before "on grounds relating to his or her particular situation" with effect from 5 February 2026. This amendment requires that the grounds relating to the data subject's particular situation must be clearly stated, reinforcing the obligation on data subjects to provide specific reasons for their objection rather than blanket or unsubstantiated demands.
Article 21(3) UK GDPR imposes a corresponding obligation on controllers: where a data subject objects under Article 21(1), the controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims. This is a balancing test. The burden of proof shifts to the controller once the objection is received — the controller must affirmatively demonstrate that its grounds are compelling and that they override the individual's interests. The ICO guidance states that "compelling" sets a high bar; controllers must show that their interests are sufficiently important and that continued processing is necessary and proportionate to achieve those interests. Vague assertions of business need or general efficiency are insufficient. Controllers must document their reasoning comprehensively, weighing the nature and sensitivity of the data, the impact on the individual, the controller's purpose, and any less intrusive alternatives.
The legal-claims exception within Article 21(3) permits continued processing when necessary for the establishment, exercise, or defence of legal claims, even when the controller cannot demonstrate compelling legitimate grounds unrelated to the claim. This exception is interpreted broadly and includes potential claims (not yet filed or threatened) provided the applicable limitation period has not expired and retention is necessary and proportionate. The ICO guidance notes that this exception is commonly invoked in employment contexts (unfair dismissal, discrimination claims) and contract disputes, where controllers routinely retain personal data for the duration of the limitation period (typically six years for contract claims, three years for personal injury or discrimination claims from the date of knowledge).
2. Right to object to direct marketing (Article 21(2) and (3))
Article 21(2) UK GDPR provides that where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing. Article 21(3) provides that where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes. This is an absolute right — there are no exemptions or grounds for refusal (Article 21(2) and ICO guidance). Controllers must stop processing immediately upon receiving an objection, regardless of the lawful basis originally relied upon (consent, legitimate interests, or any other basis). The ICO guidance states: "If someone objects, you must stop using their personal information for direct marketing. There are no reasons that you can use to refuse their objection."
What constitutes "direct marketing"?
The UK GDPR does not define "direct marketing," but Recital 47 (which remains part of UK law following the transposition of the EU GDPR) states that processing for direct marketing purposes "may be regarded as carried out for a legitimate interest." The ICO's Direct Marketing Guidance (updated periodically, most recently in 2024) defines direct marketing as the communication (by whatever means) of advertising or marketing material which is directed to particular individuals. This includes:
- Selling or promoting products or services (commercial marketing);
- Promoting aims or ideals (charities, political parties, advocacy organizations);
- Profiling to select individuals for the above purposes, including the building and refinement of marketing profiles.
The ICO has clarified that online targeted advertising (behavioral advertising, programmatic ad targeting on social media and websites) constitutes direct marketing for the purposes of Article 21(2). In its submissions to the court in O'Carroll v Meta (2024, settled before trial), the ICO stated that "online targeted advertising should be considered as direct marketing" because the UK GDPR "applies in a technologically neutral manner, including to online activity." The ICO's position is that targeted advertising directed at groups of people (based on their profiles, browsing behavior, or demographic characteristics) falls within the scope of direct marketing, and individuals therefore have an absolute right to object to the collection and processing of their data for such purposes. This position has significant implications for social media platforms, ad-tech providers, and any controller that builds user profiles for advertising purposes.
3. Right to object to research or statistical processing (Article 21(6))
Article 21(6) UK GDPR (as amended by section 70(5) of the Data (Use and Access) Act 2025) provides that where personal data are processed for scientific or historical research purposes or statistical purposes, the data subject, on grounds relating to his or her particular situation, shall have the right to object to processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out for reasons of public interest. This is a limited right — if the controller can demonstrate that the research or statistical processing is necessary for a public-interest task (for example, government statistical surveys, public-health monitoring, or archival preservation mandated by law), the objection can be refused. The ICO guidance (updated May 2025 following the DUAA amendments) advises that controllers relying on the public-task basis for research should differentiate between research carried out solely as a task in the public interest and research carried out in the exercise of official authority. Article 21(6) creates an exception only for the former; the ICO recommends that controllers consider each objection on its merits and go through the Article 21(1)/(3) balancing exercise rather than refusing the objection outright unless the public-interest necessity is clear.
How to recognize an objection — no formal wording required
The ICO guidance emphasizes that an objection to processing can be made verbally or in writing (including by email, social media, telephone, or in person) and can be made to any part of the organization. A request does not have to include the phrases "objection to processing," "right to object," or "Article 21 of the UK GDPR" — as long as it is clear that the individual is asking the controller to stop processing their personal data for a specified purpose, it is a valid objection. This presents a practical challenge: any employee who regularly interacts with individuals (customer service, sales, account management, HR) may receive a valid verbal objection. Controllers must implement internal processes to identify and escalate objections to a central point for action and tracking. The ICO recommends maintaining a policy for recording details of objections received verbally, particularly those made by telephone or in person, to ensure the controller can demonstrate compliance and avoid processing data the individual has objected to.
A third party may make an objection on behalf of another person (for example, a solicitor, a relative, or a litigation representative), provided the third party can demonstrate authority to act on the data subject's behalf. Controllers may request evidence of this authority (a written authority signed by the data subject, a power of attorney, or parental responsibility documentation) before acting on the objection, but must not impose unnecessary barriers or demand disproportionate evidence. The one-month response clock runs from the date the controller is satisfied of the third party's authority, not the date of the initial objection.
Controller obligations when an objection is received
When a controller receives an objection under Article 21(1) (legitimate interests or public task), the controller must:
- Stop processing immediately (or within the one-month response deadline under Article 12(3), extendable by two months if complex) unless the controller can demonstrate compelling legitimate grounds that override the individual's interests or the processing is necessary for legal claims. Controllers should implement a temporary suspension of processing (akin to restriction under Article 18) while the compelling-grounds assessment is undertaken, particularly when the data subject has articulated specific harm or impact.
- Conduct and document a balancing assessment if the controller intends to continue processing. This assessment must weigh the controller's grounds (articulated with specificity — not merely "business efficiency" or "we have always done it this way") against the individual's particular situation, the nature and sensitivity of the data, the impact on the individual, and any less intrusive alternatives. The assessment must demonstrate that the controller's grounds are compelling (sufficiently important and pressing) and that they override (are weightier than) the individual's interests, rights, and freedoms. The ICO will scrutinize these assessments closely, particularly in employment, litigation, and profiling contexts where the individual has articulated specific harm (distress, reputational damage, or discriminatory impact).
- Notify the data subject of the outcome within one month (extendable by two months), explaining either that processing has ceased or, if the controller is refusing the objection, the compelling legitimate grounds relied upon, the individual's right to lodge a complaint with the ICO, and the individual's right to an effective judicial remedy (Articles 77, 78, 79 UK GDPR).
When a controller receives an objection under Article 21(2) (direct marketing), the controller must:
- Stop processing the data for direct marketing purposes immediately. This is non-negotiable; there is no balancing test or exception. Processing must cease upon receipt of the objection, and the controller must ensure that the individual's details are not processed for direct marketing in the future.
- Suppress the individual's details rather than erasing them entirely. The ICO guidance clarifies that objecting to direct marketing does not automatically mean the controller must erase the individual's personal data. In most cases it will be preferable to suppress their details — retaining just enough information (name, email address, postal address, or unique identifier) to ensure that their preference not to receive direct marketing is respected in future. Suppression involves placing the individual's details on a suppression list (also called a "do not contact" list) and clearly marking those records so that they are not used for direct marketing purposes. This ensures that if the controller subsequently acquires new direct marketing lists (from third parties or data brokers), it can screen those lists against the suppression list to avoid re-contacting individuals who have objected. The ICO states that because a suppression list is not used for direct marketing purposes (it is used to prevent direct marketing), there is no automatic right for individuals to have their information on such a list deleted. Controllers may rely on the legal-obligation or legitimate-interests lawful basis to maintain suppression lists.
- If the individual also requests erasure in addition to objecting to direct marketing, the controller must assess whether one of the Article 17(1) grounds for erasure applies (for example, the data are no longer necessary, consent is withdrawn and there is no other lawful basis, or the individual objects and there are no overriding legitimate grounds). If an erasure ground applies and no Article 17(3) exception applies, the controller must erase the data except for the minimal information necessary to maintain on a suppression list (name and contact details) to prevent future direct marketing.
Transparency obligation — Article 21(4) and Recital 70
Article 21(4) UK GDPR provides that at the latest at the time of the first communication with the data subject (when the controller first contacts the individual, whether for direct marketing or any other purpose), the right to object under Article 21(1) and (2) shall be explicitly brought to the attention of the data subject and shall be presented clearly and separately from any other information. Recital 70 emphasizes that this information should be presented in a clear and plain manner, enabling the individual to easily exercise the right. For direct marketing, this typically means including a prominent opt-out mechanism (an unsubscribe link in emails, a "STOP" keyword for SMS, a tick-box or preference-center link) in every direct marketing communication, and ensuring that the right to object is highlighted in the privacy notice in a way that is visually distinct from other rights. The ICO guidance states that controllers must avoid burying the right to object in dense legal jargon or long privacy notices; transparency builds trust and reduces complaints.
Automated means of objecting — Article 21(5)
Article 21(5) UK GDPR provides that in the context of the use of information society services (online services, apps, websites, social media platforms), the data subject may exercise his or her right to object by automated means using technical specifications. This provision permits the use of technical opt-out signals such as browser settings, preference signals (for example, the Global Privacy Control (GPC) signal, which is a standardized HTTP header and JavaScript API that enables users to signal their objection to the sale or sharing of their personal data), or "Do Not Track" mechanisms. The ICO has indicated that controllers offering online services should honor such automated signals where they are clear, user-initiated, and technically feasible, though the legal force of any particular signal depends on its standardization and adoption. The GPC signal has been recognized by the California Attorney General as a valid opt-out mechanism under the CCPA, and the ICO's guidance suggests that controllers should consider honoring it for UK GDPR objection purposes as well, particularly in the context of direct marketing and profiling. Article 21(5) was amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 to refer to "domestic law made before IP completion day implementing Directive 2002/58/EC" (the ePrivacy Directive), reflecting the UK's post-Brexit status.
Response timelines, fees, and manifestly unfounded or excessive objections
Controllers must respond to objections under Article 21 within one month of receipt (Article 12(3) UK GDPR), extendable by a further two months where necessary, taking into account the complexity and number of requests. The controller must inform the data subject of any extension within one month of the original objection, together with reasons for the delay. Objections are free of charge unless the objection is manifestly unfounded or excessive, in particular because of its repetitive character, in which case the controller may charge a reasonable fee based on administrative costs or refuse to act (Article 12(5)). The burden of demonstrating that an objection is manifestly unfounded or excessive rests with the controller, and the ICO requires strong justifications applied on a case-by-case basis. An objection is not manifestly unfounded simply because the individual's ultimate purpose is to scrutinize the controller's compliance or to prepare for litigation — such objections remain valid provided the individual has a genuine intention to exercise their right.
The Data (Use and Access) Act 2025 inserted new Article 12A into the UK GDPR, which allows controllers to pause the one-month response deadline when identity verification is reasonably required or when clarification is reasonably required to locate the personal data or understand what the data subject wants (and it is not reasonable to expect the controller to comply without that clarification). Controllers must notify the data subject promptly of the need for clarification, and the clock resumes when the clarification is received. Controllers should not abuse this mechanism by asking unnecessary or repetitive clarificatory questions; the ICO will scrutinize whether clarification was reasonably required or whether the controller was simply seeking to delay the response.
Exemptions and restrictions — Schedule 2 of the Data Protection Act 2018
Schedule 2 of the Data Protection Act 2018 lists exemptions that may restrict or disapply the listed UK GDPR provisions, including Article 21. The exemptions most relevant to the right to object are:
- Crime prevention and detection, and tax assessment and collection (paragraph 2, Part 1 of Schedule 2) — Article 21 does not apply to the extent that compliance would be likely to prejudice the prevention or detection of crime, or the assessment or collection of a tax or duty. This exemption is applied on a case-by-case basis and requires a causal link between ceasing processing (in response to the objection) and the identified prejudice. Controllers relying on this exemption must document the specific prejudice and demonstrate that it is likely to arise if processing ceases.
- Legal professional privilege (paragraph 19, Part 2 of Schedule 2) — Article 21 does not apply to personal data consisting of information in respect of which a claim to legal professional privilege could be maintained in legal proceedings. This protects confidential lawyer-client communications and litigation work-product from compelled cessation of processing in response to an objection.
- Research exemption (paragraph 27, Part 6 of Schedule 2) — Article 21(1) and (2) do not apply if processing is for scientific or historical research purposes or statistical purposes, the controller has implemented appropriate safeguards for the rights and freedoms of the data subject in accordance with Article 84B UK GDPR (as amended by the DUAA 2025, replacing the former Article 89(1) reference), and compliance with the right to object would prevent or seriously impair the achievement of the research objectives. This exemption is narrow and fact-specific. Controllers must demonstrate that ceasing processing would not merely inconvenience the research but would seriously impair or render impossible the achievement of the research objectives (for example, by skewing a longitudinal study, undermining the integrity of a clinical trial dataset, or preventing archival preservation mandated by law). The exemption does not apply to data collected directly from the data subject for the research.
Exemptions are not blanket; they apply only to the extent that compliance with the right would be likely to prejudice the specified purpose. Controllers bear the burden of demonstrating the applicability of an exemption and must document their reasoning comprehensively.
Enforcement and remedies
Failure to comply with Article 21 may result in an administrative fine under Article 83 UK GDPR. Infringements of the Chapter III rights (Articles 12–22) fall under the upper tier of fines: up to £17.5 million or 4% of total annual worldwide turnover of the preceding financial year, whichever is higher (Article 83(5)). Data subjects who are refused or believe a controller has failed to comply may lodge a complaint with the Information Commissioner's Office (Article 77) or apply to the court for an order requiring compliance or for compensation for material or non-material damage (Articles 79 and 82 UK GDPR). The ICO's enforcement powers under Part 6 of the DPA 2018 include the power to issue information notices, assessment notices, and enforcement notices compelling controllers to take remedial action. Published ICO case decisions show that assertions of compelling legitimate grounds are scrutinized closely, particularly in employment, litigation, and profiling contexts where the individual has articulated specific harm.
Source: Article 21, UK GDPR (Regulation (EU) 2016/679 as it forms part of UK law) Source: Data Protection Act 2018, Schedule 2 (exemptions from the UK GDPR) Source: ICO: Right to object guidance Source: ICO: Direct marketing guidance Source: Data (Use and Access) Act 2025, section 70 (amendment to Article 21)
Right to rectification (Article 16 UK GDPR) — correcting inaccurate data, completing incomplete records, and the Article 19 onward-notification duty
Article 16 of the UK GDPR establishes the right to rectification, which entitles data subjects to obtain from the controller without undue delay the rectification of inaccurate personal data concerning them. This right has two components: the right to have inaccurate personal data corrected, and the right to have incomplete personal data completed, including by means of providing a supplementary statement. Article 16 is closely linked to the accuracy principle in Article 5(1)(d) UK GDPR, which requires that personal data be "accurate and, where necessary, kept up to date" and that "every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay." The right to rectification imposes a specific obligation on controllers to reconsider the accuracy of data upon request, even when the controller took reasonable steps to ensure accuracy at the time of collection.
The two-limb right: inaccurate data and incomplete data
Article 16 UK GDPR provides that:
> "The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement."
The first limb addresses inaccurate personal data. The UK GDPR does not define "inaccurate," but the Information Commissioner's Office (ICO) guidance and case law interpret this to mean that the facts contained within the personal data do not conform to reality. Common examples include misspelled names, incorrect addresses, erroneous employment history, or inaccurate credit reference information. Inaccuracy is assessed objectively: if the data does not reflect the true factual position, it is inaccurate. However, the concept of accuracy can be complex when applied to opinions or historical records. The ICO guidance states that opinions are, by their very nature, subjective, and it can be difficult to conclude that the record of an opinion is inaccurate. As long as the record shows clearly that the information is an opinion and, where appropriate, whose opinion it is, it may be difficult to say that it is inaccurate and needs to be rectified. Controllers should distinguish between challenging the accuracy of a fact (which may be objectively wrong) and challenging the validity or fairness of an opinion (which is inherently subjective).
The second limb addresses incomplete personal data. The ICO guidance clarifies that data may be deemed "complete" for one purpose but "incomplete" for another, so controllers are only obliged to rectify data sets that are incomplete having regard to the purposes of the processing. The ICO provides the example of creditworthiness information: if a credit file records a refusal to pay but omits the fact that the reason was an incorrect delivery of goods, the record is incomplete because it gives a misleading impression for the purpose of assessing credit risk. The data subject may require the controller to complete the record by adding a supplementary statement explaining the context.
How to recognize a rectification request — no formal wording required
The UK GDPR does not specify how to make a valid rectification request. The ICO guidance emphasizes that an individual can make a request for rectification verbally or in writing (including by email, letter, social media message, telephone, or in person), and the request can be made to any part of the organization, not only to a specific person or contact point. A request to rectify personal data does not need to mention the phrase "request for rectification," "Article 16," or "UK GDPR" to be valid. As long as the individual has challenged the accuracy of their data and has asked the controller to correct it, or has asked the controller to complete incomplete data, this will be a valid request under Article 16. This presents an operational challenge: any employee who regularly interacts with individuals (customer service, sales, account management, HR) may receive a valid verbal rectification request. Controllers must implement internal processes to identify and escalate rectification requests to a central point for action and tracking. The ICO recommends maintaining a policy for recording details of requests received verbally, particularly those made by telephone or in person, to ensure the controller can demonstrate compliance.
A third party may make a rectification request on behalf of another person (for example, a solicitor acting for a client, a relative acting for an elderly or incapacitated individual, or a parent making a request for a child's data). The ICO guidance states that controllers are entitled to request evidence that the third party is entitled to act on the person's behalf — for example, a written authority signed by the data subject, a power of attorney, or parental responsibility documentation. Controllers may refuse to comply until satisfied that the third party has proper authority, but must not impose unnecessary barriers or demand disproportionate evidence.
The controller's assessment obligation — reasonable steps to verify accuracy
When a controller receives a rectification request, Article 16 imposes an affirmative obligation on the controller to take reasonable steps to satisfy itself that the data is accurate and to rectify the data if necessary. The controller must take into account the arguments and evidence provided by the data subject. What steps are "reasonable" depends, in particular, on the nature of the personal data and what it will be used for. The more important it is that the personal data is accurate, the greater the effort the controller should invest in checking its accuracy and, if necessary, taking steps to rectify it. The ICO guidance states that controllers should make a greater effort to rectify inaccurate personal data if it is used to make significant decisions that will affect an individual or others, rather than data used for trivial or low-impact purposes. For example, a controller should rigorously investigate and rectify inaccuracies in credit reference data, employment records used for background checks, or medical data used for clinical decisions, because errors in these contexts can cause substantial harm (denial of credit, loss of employment opportunities, or incorrect medical treatment).
The ICO guidance clarifies that a rectification request gives the controller an opportunity to reconsider the accuracy of data upon request, even if the controller originally took reasonable steps to ensure accuracy at the time of collection. This reflects the principle that personal data must remain accurate over time, and that data subjects are often best placed to identify errors in data about themselves. Controllers should not dismiss rectification requests simply because the data was accurate when originally collected or because the controller has relied on the data for a period of time. Changed circumstances (a name change following marriage, a change of address, updated employment status) or newly discovered evidence (proof that a debt was disputed or paid) may require rectification even when the original data was accurate at the time of recording.
Restriction of processing pending verification — Article 18 interplay
The ICO guidance, updated in 2025, emphasizes that as a matter of good practice, controllers should restrict the processing of the personal data in question while they are verifying its accuracy, whether or not the individual has formally exercised their right to restriction under Article 18 UK GDPR. Article 18(1)(a) UK GDPR provides that the data subject has the right to obtain restriction of processing where the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data. When processing is restricted, the controller is permitted to store the personal data but must cease further use of it (except with the data subject's consent, for the establishment, exercise, or defence of legal claims, for the protection of the rights of another person, or for reasons of important public interest — Article 18(2) UK GDPR). The ICO recommends that controllers implement a temporary suspension or flag on contested data to prevent it from being used for decision-making or disclosed to third parties while the accuracy assessment is ongoing. This minimizes the risk of harm to the data subject if the data is ultimately found to be inaccurate.
Response timeline, fees, and manifestly unfounded or excessive requests
Article 12(3) UK GDPR requires controllers to respond to rectification requests without undue delay and in any event within one month of receipt. The period may be extended by a further two months where necessary, taking into account the complexity and number of requests, provided the controller informs the data subject of the extension within one month of the original request, together with reasons for the delay. The ICO guidance states that the one-month period starts on the day after the request is received (it does not matter whether that day is a working day or not), and the deadline is the corresponding calendar date in the next month. If there is no corresponding date (for example, a request received on 31 January has a deadline of 28 or 29 February, depending on whether it is a leap year), the deadline is the last day of the month. If the deadline falls on a weekend or public holiday, the controller has until the end of the next working day to comply.
Rectification requests are free of charge unless the request is manifestly unfounded or excessive, in particular because of its repetitive character, in which case the controller may charge a reasonable fee based on administrative costs or refuse to act (Article 12(5) UK GDPR). The burden of demonstrating that a request is manifestly unfounded or excessive rests with the controller, and the ICO requires strong justifications applied on a case-by-case basis. The ICO guidance states that controllers must be able to demonstrate to the individual (and, if asked, to the ICO) why they consider the request manifestly unfounded or excessive. A request is not manifestly unfounded simply because the controller believes its data is accurate or because the individual's ultimate purpose is to prepare for litigation — such requests remain valid provided the individual has a genuine intention to exercise their right to rectification.
Refusing a rectification request — when controllers may (and must) say no
Controllers are not obliged to rectify data in every case. A controller may refuse a rectification request if, after taking reasonable steps to investigate, it is satisfied that the personal data is accurate and complete. The ICO guidance emphasizes that controllers should inform the data subject if they are not going to amend the data, and should explain clearly why they believe the data is accurate. The controller must also inform the data subject of their right to lodge a complaint with the ICO and their right to seek a judicial remedy (Articles 77, 78, and 79 UK GDPR). If the controller refuses to rectify the data, the ICO recommends as a matter of good practice that the controller record that the data subject has challenged the accuracy of the data and the reasons why. This ensures that if the data is subsequently disclosed (for example, in a subject access request response or to a third party), the controller can demonstrate that it considered the challenge and explain its decision.
Disputed facts and opinions — special cases
Two categories of rectification request present particular difficulty: disputed facts and opinions.
Disputed facts arise when the data subject and the controller each believe their version of the facts to be accurate, but the versions conflict. For example, an employer's disciplinary record may state that an employee was absent without authorization on a specific date, but the employee asserts they had prior approval. The ICO guidance does not prescribe a single approach, but emphasizes that controllers must conduct a reasonable investigation, weigh the evidence on both sides, and document their reasoning. If the controller cannot definitively resolve the dispute, it may be appropriate to add a supplementary statement to the record (using the "incomplete data" limb of Article 16) reflecting the data subject's contested account, rather than simply deleting or replacing the original entry. This preserves both accounts and acknowledges the dispute.
Opinions are inherently subjective. The ICO guidance states that as long as the record shows clearly that the information is an opinion and, where appropriate, whose opinion it is, it may be difficult to say that it is inaccurate and needs to be rectified. For example, a performance review that records a manager's opinion that an employee's work quality is "below expectations" is not inaccurate simply because the employee disagrees with the assessment, provided the record makes clear it is the manager's opinion and is dated and attributed. However, if the record of the opinion is factually wrong (for example, it attributes an opinion to the wrong person, or records an opinion that was never expressed), the record itself is inaccurate and must be corrected. The ICO guidance suggests that in some cases, the appropriate remedy may be to add the data subject's own statement to the record, providing their perspective on the opinion, rather than to delete or alter the original opinion.
Historical records and audit trails — the "accurate record of a mistake" issue
A related issue arises when personal data records a historical mistake that has since been corrected. For example, a bank may have initially recorded an incorrect account balance, then corrected it the following day. The historical record shows the mistake; the current record is accurate. The ICO guidance states that it "may be possible to argue" that the record of the mistake is accurate as a record of what was believed or recorded at the time, even though the underlying fact was wrong. Controllers must balance the accountability principle (Article 5(2) UK GDPR), which requires that processing be transparent and auditable, against the individual's right to rectification. In many cases, the appropriate approach is to retain the historical record with an annotation explaining that it was an error and has been corrected, rather than deleting the historical entry entirely. This preserves the audit trail (particularly important for financial services, healthcare, and public-sector controllers subject to regulatory record-keeping obligations) while ensuring that anyone reviewing the record understands the correction. The ICO emphasizes that controllers should apply this approach carefully and on a case-by-case basis; it is not a blanket justification for refusing to rectify demonstrably inaccurate data.
The Article 19 onward-notification duty — telling recipients about the rectification
When a controller rectifies personal data, Article 19 UK GDPR imposes a corresponding obligation to communicate the rectification to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. A "recipient" is defined in Article 4(9) UK GDPR as a natural or legal person, public authority, agency, or other body to which the personal data are disclosed, whether a third party or not. The definition includes controllers, processors, and persons who, under the direct authority of the controller or processor, are authorized to process personal data. The ICO guidance emphasizes that controllers must contact each recipient and inform them of the rectification (or completion) of the personal data, unless doing so is impossible (for example, the recipient no longer exists or cannot be identified) or involves disproportionate effort (for example, the data was disclosed to hundreds of recipients in bulk, and tracing and notifying each would require resources entirely out of proportion to the benefit). The ICO clarifies that "disproportionate effort" is a narrow exception and controllers must be able to justify it on a case-by-case basis.
If the data subject asks the controller to identify the recipients, the controller must inform the individual about those recipients (Article 19, second sentence). Controllers should therefore maintain records of disclosures (as part of their general Article 5(2) accountability obligation and, where applicable, their Article 30 records of processing activities) to enable them to comply with the Article 19 notification duty and to respond to requests for recipient information.
Exemptions and restrictions — Schedule 2 of the Data Protection Act 2018
Schedule 2 of the Data Protection Act 2018 lists exemptions that may restrict or disapply the listed UK GDPR provisions, including Article 16. The exemptions most relevant to the right to rectification are:
Crime prevention and tax (paragraph 2, Part 1 of Schedule 2) — Article 16 does not apply to the extent that compliance would be likely to prejudice the prevention or detection of crime, or the assessment or collection of a tax or duty. This exemption is applied on a case-by-case basis and requires a causal link between rectifying the data and the identified prejudice. For example, a law-enforcement agency may refuse to rectify data forming part of an ongoing criminal investigation if doing so would tip off the suspect or undermine evidence gathering. Controllers relying on this exemption must document the specific prejudice and demonstrate that it is likely to arise if the data is rectified.
Immigration control (paragraph 4, Part 1 of Schedule 2, as amended by S.I. 2024/342) — The immigration exemption historically permitted the Secretary of State to restrict Article 16 (along with other listed GDPR provisions) where compliance would be likely to prejudice the maintenance of effective immigration control or the investigation or detection of activities that would undermine it. Following the Court of Appeal's judgment in R (3million and Open Rights Group) v Secretary of State for the Home Department [2023] EWCA Civ 1474, the Data Protection Act 2018 (Amendment of Schedule 2 Exemptions) Regulations 2024 (S.I. 2024/342), which came into force on 8 March 2024, inserted detailed safeguards into new paragraph 4A of Schedule 2. Notably, paragraph 4(2) of Schedule 2 expressly excludes Article 16 (right to rectification) from the immigration exemption, meaning that the right to rectification cannot be restricted on immigration-control grounds. This is a significant change and reflects the Court of Appeal's emphasis on the fundamental nature of the right to accurate data. Controllers processing personal data for immigration purposes (including the Home Office, UK Visas and Immigration, and Border Force) must comply with Article 16 rectification requests and cannot invoke the immigration exemption to refuse them.
Legal professional privilege (paragraph 19, Part 2 of Schedule 2) — Article 16 does not apply to personal data consisting of information in respect of which a claim to legal professional privilege could be maintained in legal proceedings. This protects confidential lawyer-client communications and litigation work-product from compelled rectification. The privilege applies only to legally privileged communications (advice privilege or litigation privilege); it does not extend to general legal or regulatory correspondence that is not privileged.
Research exemption (paragraph 27, Part 6 of Schedule 2) — Paragraph 27 of Schedule 2 provides an exemption from Article 16 if processing is for scientific or historical research purposes or statistical purposes, the controller has implemented appropriate safeguards for the rights and freedoms of the data subject in accordance with Article 84B UK GDPR (as amended by the Data (Use and Access) Act 2025, replacing the former Article 89(1) reference), and complying with the right to rectification would prevent or seriously impair the achievement of the research objectives. This exemption is narrow and fact-specific. The ICO guidance states that controllers must demonstrate that rectifying the data would not merely inconvenience the research but would seriously impair or render impossible the achievement of the research objectives. An example is archived records of enduring historical value, which are generally not altered after the archiving organization receives them because doing so would undermine the integrity of the historical record. The research exemption does not permit a blanket refusal of all rectification requests; controllers must assess each request on a case-by-case basis and apply the exemption only to the extent necessary to prevent the identified prejudice.
Exemptions are not blanket; they apply only to the extent that compliance with the right would be likely to prejudice the specified purpose. Controllers bear the burden of demonstrating the applicability of an exemption and must document their reasoning comprehensively.
Enforcement and remedies
Failure to comply with Article 16 may result in an administrative fine under Article 83 UK GDPR. Infringements of the Chapter III rights (Articles 12–22) fall under the upper tier of fines: up to £17.5 million or 4% of total annual worldwide turnover of the preceding financial year, whichever is higher (Article 83(5)). Data subjects who are refused rectification or believe a controller has failed to comply may lodge a complaint with the Information Commissioner's Office (Article 77) or apply to the court for an order requiring compliance or for compensation for material or non-material damage (Articles 79 and 82 UK GDPR). The ICO's enforcement powers under Part 6 of the DPA 2018 include the power to issue information notices, assessment notices, and enforcement notices compelling controllers to take remedial action. The ICO has emphasized in published guidance that the right to rectification is a fundamental safeguard for the accuracy principle and that controllers who routinely refuse rectification requests without proper investigation risk regulatory intervention.
Source: Article 16, UK GDPR (Regulation (EU) 2016/679 as it forms part of UK law) Source: Article 19, UK GDPR (notification obligation regarding rectification or erasure) Source: Data Protection Act 2018, Schedule 2 (exemptions from the UK GDPR) Source: ICO: Right to rectification guidance Source: Data Protection Act 2018 (Amendment of Schedule 2 Exemptions) Regulations 2024 (S.I. 2024/342)
Right to restriction of processing (Article 18 UK GDPR) — the four triggers, operational effect, and notification duty
Article 18 of the UK GDPR establishes the right for individuals (data subjects) to require controllers to restrict processing of their personal data in specific circumstances. This right—often misunderstood as temporary “freezing” rather than deletion—has become operationally significant in disputes, pre-litigation scenarios, and whenever accuracy or lawful basis is in question. Controllers must understand how to recognize a valid restriction request, what operational steps are required, what processing is actually permitted once restriction applies, and the onward notification duty to recipients.
The four triggers for restriction under Article 18(1) A data subject may obtain restriction where one of these conditions exists:
- Contested accuracy (Article 18(1)(a)): Where the individual contests the accuracy of the data—restriction applies for a period enabling the controller to verify accuracy. Usually invoked in tandem with a rectification request. The controller should halt further processing (but may continue to store data) until the dispute is resolved. (See also Article 16 and ICO rectification guidance.)
- Unlawful processing, refusal of erasure (18(1)(b)): Where processing is unlawful but the data subject opposes erasure and requests restriction instead. Practical examples include evidentiary disputes, employment or litigation circumstances where deletion would prejudice the individual’s position.
- No longer needed, but for legal claims (18(1)(c)): Where the controller no longer needs the data for original purposes, but the data subject needs it for the establishment, exercise, or defence of legal claims. Restriction ensures data remains available for the individual’s legal interests.
- Objection pending verification (18(1)(d)): Where the data subject objects to processing under Article 21, and processing is pending verification of whether legitimate grounds override those of the data subject. This “pause” applies until the balancing test is complete.
Operational duties during restriction
- Storage only: Restricted personal data may be stored, but not otherwise processed except with the individual’s consent, for legal claims, for protecting others’ rights, or for important public interest reasons (Article 18(2)). Routine use, disclosure, or secondary processing must cease. In practice, restriction is usually implemented by a “flag” or “hold.” ICO guidance recommends clearly marking records to ensure that systems and staff prevent further processing, without deleting the data.
- Duration: Restriction persists until the underlying ground is resolved (accuracy verified, legal dispute concluded, erasure grounds no longer apply, or balancing test complete). Controllers must document their rationale for lifting or maintaining restriction, given the potential for complaint and ICO scrutiny.
Notification duty — Article 19 When restriction is applied, controllers must communicate this to all recipients to whom personal data has been disclosed, unless impossible or disproportionate effort is involved. On request, controllers must inform the data subject of these recipients. This supports accountability and prevents downstream processing.
Remedies and enforcement Refusal to restrict, or failure to comply with operational limits, may expose controllers to complaints, enforcement, or fines (upper-tier penalty under Article 83(5), up to £17.5 million or 4% of total annual worldwide turnover). Data subjects are entitled to lodge a complaint with the Information Commissioner’s Office (ICO) or seek judicial remedy (Articles 77, 79 UK GDPR; Part 6 DPA 2018). Controllers must carefully document all rationale and communications when restriction is applied, maintained, or lifted.
Exemptions Schedule 2 of the Data Protection Act 2018 may restrict or disapply Article 18 in specific cases (notably crime/tax, legal privilege, research). These exemptions are applied case by case with justification.
Source: Article 18, UK GDPR (Regulation (EU) 2016/679 as it forms part of UK law) Source: Article 19, UK GDPR (notification obligation regarding rectification or erasure or restriction) Source: ICO: Guide to individual rights
Right to data portability (Article 20 UK GDPR)—scope, limitations, and operational requirements
The right to data portability set out in Article 20 of the UK GDPR (retained from the EU GDPR) gives individuals the right to receive their personal data in a portable format and to have that data transmitted to another controller, where technically feasible. Data portability is intended to give data subjects more control over their digital lives, particularly in online services—but its scope is intentionally narrow and defined.
Scope and applicability Article 20 applies only where all three of the following are true:
- The processing is based on consent (Article 6(1)(a) or 9(2)(a)) or contract (Article 6(1)(b));
- The processing is carried out by automated means (i.e., not paper files);
- The data is "provided by the data subject". According to ICO guidance, this covers data the individual knowingly gives to the controller (such as by completing a web form), and data "observed from the activities of the individual" (such as transaction history, site usage, or location data collected by GPS). It does not include data that has been inferred or derived by the controller, such as algorithmic profiles or analytics results (ICO guidance).
Contents and format of portability Controllers must provide the data:
- In a structured, commonly used, machine-readable format. ICO guidance lists CSV, JSON, and XML as common examples but not mandatory or exhaustive formats.
- Free of charge except where a request is manifestly unfounded or excessive (Article 12(5)).
- Within one month of the request (extendable by two further months for complex or multiple requests—Article 12(3)).
- On request, transmit the data directly to another controller if technically feasible; there is no obligation to adopt compatible systems, only to transmit where reasonably possible.
- Assess whether fulfilling the request would adversely affect the rights and freedoms of others (Article 20(4)), for example if the dataset contains third-party personal data, in which case redaction or refusal may be justified.
Exemptions and limits
- The right does not apply to processing based on legitimate interests, legal obligation, or public task.
- Schedule 2 of the Data Protection Act 2018 allows exemptions, especially for crime, taxation, legal claims, professional privilege, and certain research purposes (DPA 2018 Schedule 2).
Remedies and ICO enforcement Failure to comply can result in complaints to the ICO or court proceedings. The maximum fine for infringements of Chapter III rights (including Article 20) is £17.5 million or 4% of annual worldwide turnover, whichever is higher (Article 83(5) UK GDPR). Actual penalties are fact specific and determined by the ICO on a case-by-case basis.
Source: Article 20, UK GDPR (Regulation (EU) 2016/679 as it forms part of UK law) Source: ICO: Right to data portability guidance Source: Data Protection Act 2018, Schedule 2 (exemptions from the UK GDPR)
Article 22 UK GDPR — rights related to automated decision-making, profiling, and 2025 DUAA reforms
Update as of May 2026 — new binding ICO statutory code duty for AI and automated decision-making now in force under SI 2026/425
On 16 April 2026, the UK finalized the Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision‑Making) Regulations 2026 (SI 2026/425), which takes legal effect on 12 May 2026. This regulation places a statutory duty on the Information Commissioner (ICO) to issue a legally binding code of practice governing the processing of personal data in connection with AI and automated decision-making (ADM) under the DPA 2018. The Code, once published, will apply across sectors, have direct legal force, and set forth requirements for the use of AI and ADM alongside existing Article 22 and DPA rules. Organizations and processors must monitor for release of this binding Code and prepare to update privacy and governance protocols in line with its requirements. This is a major development: it goes beyond the prior ICO guidance by imposing a regulatory code with legal status, effective from 12 May 2026. (Source: SI 2026/425, Reg. 1–2)
---
Article 22 of the UK GDPR gives individuals the right not to be subject to a decision based solely on automated processing—including profiling—if that decision produces legal or similarly significant effects. (Art. 22, UK GDPR)
Scope and triggers of Article 22
- Article 22 applies when a decision about a person is made by automated means alone (no meaningful human involvement) and the outcome has legal or comparably significant effects (such as credit refusal, dismissal, or automated benefit allocation). (Art. 22(1), ICO ADM guidance)
- "Solely automated" means no genuine review by a human empowered to change the outcome; token or after-the-fact review does not remove a decision from Article 22's scope. (ICO guidance)
Permitted bases (Article 22(2)) and required safeguards (22(3)–(4)) Decisions solely on automation with such effect are only lawful if:
- necessary to enter or perform a contract with the data subject;
- expressly authorised by UK law with safeguards; or
- based on explicit consent from the data subject.
When relying on these, controllers must ensure affected individuals:
- can obtain human intervention;
- can express their point of view;
- can contest the decision.
If special-category data (e.g. health, ethnicity) is involved, stricter rules apply under Article 22(4).
DUAA 2025 and Article 22C for non-sensitive data (commencement from 2026) Section 76 of the Data (Use and Access) Act 2025 inserts Article 22C into UK GDPR (scheduled to commence in 2026—practitioners must confirm which parts are now in force). Article 22C creates an alternative, statutory regime for significant, solely automated decisions about non-special-category data—removing the need to rely solely on contract, law, or consent, provided the controller:
- gives advance notice to data subjects;
- provides a simple mechanism to seek human intervention, express their view, and contest the decision;
- implements documented technical and organizational measures for fairness and transparency. (DUAA 2025, s.76)
Article 22C does not apply to special-category data, which remains under stricter safeguards.
Enforcement and best practice (current law and new rules)
- All organizations must update privacy notices (Arts. 13–14 UK GDPR) to reflect current ADM practices, legal bases, and available rights.
- Controllers must maintain records of their ADM logic and ensure genuine human review where required. (ICO guidance)
- ICO is currently mandated to consult on and publish the binding Code on AI/ADM as required by SI 2026/425; its provisions will be enforceable and supplement statutory obligations under Article 22 and the DUAA 2025 regime.
This section was updated in May 2026 to incorporate the duty imposed on the ICO to prepare a statutory, binding Code of Practice on AI and Automated Decision-Making under SI 2026/425 (in force 12 May 2026). Controllers should track ICO publications and prepare for binding requirements distinct from guidance and internal policies.
Source: Article 22, UK GDPR (Regulation (EU) 2016/679 as retained in UK law) Source: Data (Use and Access) Act 2025, section 76 (new Article 22C) Source: SI 2026/425: Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision‑Making) Regulations 2026 Source: ICO: Guidance on automated decision-making and profiling
Right to lodge a complaint with the ICO and pursue judicial remedy (Articles 77–79 UK GDPR)
The enforcement pathway for data subject rights under the UK GDPR is anchored in Articles 77, 78, and 79, which guarantee individuals (data subjects) a free statutory right to lodge a complaint with the Information Commissioner’s Office (ICO)—the UK’s supervisory authority—and to seek a judicial remedy if unsatisfied by the ICO’s response or if a controller/processor fails to comply with their rights.
Article 77: Right to lodge a complaint with the ICO
A data subject who believes their data-protection rights have been infringed—including delays, partial responses, or refusals in response to any Article 12–22 request—may file a written complaint with the ICO. The right applies regardless of the data subject's residence, provided the issue concerns personal data processed by a UK controller or processor. There is no requirement to exhaust internal complaints with the controller before complaining to the ICO, though the ICO encourages resolution with the controller first. Complaints may relate to refusals, excessive fee demands, alleged failures to respond within statutory timescales, or any infringement.
The ICO is obligated to inform the complainant of the progress and outcome of the complaint, including any possibility of judicial remedy via the courts (Article 77(2)). The Data Protection Act 2018, section 165, sets additional procedural rules, including the ICO’s power to refuse to act on manifestly unfounded, excessive, or repetitive complaints.
Article 78: Right to an effective judicial remedy against the ICO
If the ICO fails to respond, refuses to take an action, or does not inform the individual of the outcome within a reasonable period (usually within three months, per ICO service standards), the data subject may apply to a court for a remedy (typically the First-tier Tribunal in England and Wales or the Court of Session in Scotland). The right under Article 78 is autonomous and does not require the ICO to have issued a final decision.
Article 79: Right to an effective judicial remedy against controllers or processors
Separately, Article 79 provides that individuals have a right to bring proceedings in court against a controller or processor where they consider their data rights to have been infringed—including if the controller refuses a rectification, access, erasure, or other right. Proceedings may be brought in the civil courts; remedies include orders for compliance and compensation for material or non-material damage.
Update as of March 2026: The second paragraph of Article 79 UK GDPR has been formally deleted pursuant to the Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 (SI 2026/386), effective 26 March 2026. This was a placeholder or blank point and does not affect the rights or remedies afforded under the rest of Article 79.
Interaction with other rights
- Individuals do not need to wait for an ICO decision to bring a claim under Article 79; these are separate statutory routes.
- The ICO has discretion whether to take regulatory action, but must inform the complainant of any further remedies if the complainant is unsatisfied.
- Complaints may be made free of charge.
ICO procedures, response timelines, and best practice are set out in the ICO’s published complaint-handling guidance.
Source: UK GDPR Articles 77–79 as amended Source: SI 2026/386: Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 Source: ICO: Individual rights complaints procedure
UK Data Protection Act 2018 Schedule 2 exemptions — crime, tax, legal privilege, research, journalism, immigration and other restrictions on data subject rights
The Data Protection Act 2018 (DPA 2018) Schedule 2 forms the backbone of the UK-specific exemptions to data subject rights under the UK GDPR (Articles 12–22), and is critical for practitioners interpreting where rights may be limited or disapplied. Schedule 2 overlays and, in some instances, narrows the direct force of GDPR’s Chapter III rights. Most exemptions are not blanket, but apply only “to the extent that” compliance would prejudice specific protected interests. Invoking any exemption requires a fact-specific assessment and a well-documented rationale; the Information Commissioner’s Office (ICO) expects controllers to justify their reasoning in detail.
Key categories of exemption in Schedule 2 DPA 2018 include:
- Crime and taxation (Part 1, paragraph 2): Rights can be limited where compliance “would be likely to prejudice” the prevention/detection of crime, apprehension/prosecution of offenders, or the assessment/collection of tax/duty. This is the most widely-invoked exemption and often relevant to SARs in employment, litigation, or law enforcement contexts. The controller must show a causal link between compliance and the prejudice—mere inconvenience or speculative harm is insufficient.
- Immigration control (Part 1, paragraph 4, as amended by S.I. 2024/342): Allows restriction of rights where necessary for “effective immigration control” or to prevent activities undermining it. The 2024 amendments and Court of Appeal jurisprudence (R (3million v SSHD)) now require the Secretary of State to make a detailed, case-by-case proportionality assessment, explicitly considering human rights and the best interests of children.
- Legal professional privilege (Part 2, paragraph 19): Information covered by legal privilege is exempt from most data subject rights, including access, rectification, and erasure. This protects confidential communications and litigation material from disclosure or compelled correction.
- Journalism, academic, artistic, and literary purposes (Part 5): Rights can be restricted where necessary to protect freedom of expression and information, subject to detailed harm and public interest tests (see also section 124 DPA 2018).
- Research and statistics (Part 6, paragraph 27): Exempts rights if the data is processed for scientific/historical/statistical research, “appropriate safeguards” are in place (now referencing Article 84B post-DUAA), and compliance would seriously impair the research objectives. This exemption is tightly construed—the standard is not mere inconvenience.
- Third-party data (Part 3, paragraph 16): If compliance would disclose information about another identifiable individual, disclosure can be refused unless that individual consents or disclosure is otherwise reasonable in all circumstances.
Schedule 2 also details exemptions for confidentiality obligations, corporate finance, legal claims, regulatory functions, and more. Most invoke a proportionality or “likely to prejudice” test, requiring case-specific balancing. Controllers bear the burden of proof, should document each use, and must apply the exemption only as far as necessary.
For a full mapping of right-specific exemptions, refer directly to the Schedule 2 DPA 2018 text.
Source: Data Protection Act 2018, Schedule 2 (UK-specific exemptions from the UK GDPR) Source: ICO: A guide to the data protection exemptions
How to make a data subject rights request—channels, third-party requests, and identity verification under Article 12A UK GDPR
A data subject rights request (for access, rectification, erasure, restriction, objection, or portability) can be made to any UK controller under the UK GDPR and Data Protection Act 2018. As of June 2026, Article 12A—the Data (Use and Access) Act 2025 (“DUAA”) ‘stop-the-clock’ mechanism—is in force for all rights requests.
Accepted channels for requests (current law as of June 2026)
- Any individual (data subject) or their representative may make a rights request verbally or in writing—by email, letter, webform, phone, or even social media. No particular format or language is legally required; a clear statement is sufficient. (Article 12(1) UK GDPR, ICO subject access guidance)
- Requests made to any part of the organisation—whether or not to a dedicated DPO or privacy email—are valid and begin the statutory response period. The standard response deadline is one month from receipt. (Article 12(3) UK GDPR, ICO guidance)
Third-party requests and proof of authority (statutory rules at June 2026)
- A third party (e.g., parent, lawyer, agent) may make a request on a data subject’s behalf. The controller may require evidence of authority, such as written consent, power of attorney, or proof of parental responsibility. (ICO guidance)
- Controllers must not impose excessive requirements and can only pause the response period to verify authority or identity if they have “reasonable doubts as to the identity of the natural person making the request or, as the case may be, the identity and authority of the person making the request on behalf of the data subject.” (Article 12(6) UK GDPR)
Identity checks and the stop-the-clock (Article 12A now in effect)
- Since 5 February 2026, Article 12A allows controllers to “stop the clock” on the one-month response deadline if:
- they reasonably require confirmation of the requester’s identity or authority; or
- they reasonably require clarification as to the request’s scope, where it is not reasonable to comply without further information.
- The controller must promptly notify the requester when pausing the deadline, resume the clock upon receiving the requested information, and document the pause and its justification. (Article 12A(2)-(3) UK GDPR (as amended by DUAA 2025, in force); ICO guidance June 2026)
- These statutory mechanisms are in full force as of June 2026, following the ICO’s confirmation of the DUAA’s general commencement.
Best practice (ICO guidance as of June 2026)
- Organisations should publish clear contact points and train all staff to recognise valid rights requests.
- Any identification or authority information collected must only be used for handling the request and must be proportionate to the risk/sensitivity involved.
- The statutory response period is one month (extendable to three months for complex/multiple requests); under Article 12A, the deadline does not run while clarification or identity/authority confirmation is outstanding and properly notified.
Summary Controllers must accept requests via any reasonable channel, avoid excessive hurdles for ID or authority, and—under Article 12A—carefully document, notify, and justify any pause in the statutory deadline. The ICO routinely scrutinizes unjustified barriers or delays, and statutory sanctions (Article 83 UK GDPR, DPA 2018) apply for non-compliance.
Material change: This section was updated in June 2026 to reflect Article 12A’s commencement for all data subject rights requests on 5 February 2026 and ICO’s confirmation that all DUAA data protection procedural amendments are now operative.
Source: Article 12, UK GDPR (Regulation (EU) 2016/679 as retained in UK law) Source: Data (Use and Access) Act 2025, section 75 and Schedule 10 (new Article 12A, in force 5 February 2026) Source: ICO: Guide to individual rights and subject access requests—amended for DUAA 2025 commencement
Right to be informed — privacy notice content, timing, and disproportionate‑effort exemption (Articles 13–14 UK GDPR)
Material update as of February 2026 — Data (Use and Access) Act 2025 amendments in force
The United Kingdom's right to be informed, anchored in Articles 13 and 14 UK GDPR, was substantively amended by the Data (Use and Access) Act 2025 (DUAA 2025), with the relevant changes entering into force on 5 February 2026. This update reflects those statutory amendments and impacts controller obligations for privacy notices and the circumstances under which information may be withheld.
Key statutory amendments now in force
- Article 13 and 14 UK GDPR, as amended — The DUAA 2025 revised the legislative text governing transparency obligations when personal data is collected from (Article 13) or not from (Article 14) the data subject. Controllers must still provide all required privacy information at the point of data collection (or within one month if not collected from the individual) but must now do so under the amended statutory language.
- Article 12A introdued — DUAA 2025 inserts a new Article 12A, setting out additional grounds for withholding, delaying, or clarifying notifications, particularly regarding identity verification and scope clarification. This may interact with the right to be informed when operationalizing privacy notices to new or unknown data subjects.
- Disproportionate effort and research/statistics changes — For processing involving scientific or historical research or statistical purposes, exemptions from notification must now reference newly amended safeguards (notably Article 84B), with controllers required to keep records of their decision to rely on the disproportionate effort exemption.
What remains and what changed
- The core informational requirements in Articles 13 and 14 remain: controllers must present, at minimum, details on identity, contact, lawful basis, recipients, retention, rights, international transfers, and automated decision-making, with additional requirements under Article 14 if data is not collected from the data subject. Timing—immediately at collection, or within one month if indirect collection—remains unchanged in substance, but controllers must now reference the amended UK GDPR provisions.
- The disproportionate effort exemption for notification is narrowed for research/statistics, requiring explicit safeguarding and internal documentation.
Action points for practitioners (February 2026 and onward):
- Review and update privacy notices and internal processes to reference amended Articles 13 and 14, Article 12A, and the new requirements for documenting and justifying any reliance on the disproportionate effort exemption for research/statistics.
- Ensure all legal references in privacy notices, compliance checklists, and operational protocols point to the post-DUAA 2025 UK GDPR as amended and in force.
Primary sources: Source: Article 13 UK GDPR—information to be provided where personal data are collected from the data subject Source: Article 14 UK GDPR—information to be provided where personal data have not been obtained from the data subject Source: Data (Use and Access) Act 2025, effective 5 February 2026 (official factsheet and legislative text) Source: ICO: Guide to the right to be informed
Right to withdraw consent—Article 7(3) UK GDPR: practical requirements, effect, and controller obligations
The right to withdraw consent at any time is a foundational data subject right under the UK GDPR. Article 7(3) UK GDPR provides that "the data subject shall have the right to withdraw his or her consent at any time," and that withdrawing consent must be "as easy as giving consent." This right applies to any processing of personal data that is based on the data subject's consent under Article 6(1)(a) (or Article 9(2)(a) for special-category data), and has been retained post-Brexit in UK law.
Requirements under Article 7(3) UK GDPR
- Withdrawal must be as easy as giving consent: Controllers must ensure that the process for withdrawing consent does not involve more steps, friction, or complexity than the process for giving consent initially. For example, if consent was obtained via a single click or tap, withdrawal should be achievable through an equally accessible user interface, such as a clearly presented unsubscribe link or account settings toggle. Hiding withdrawal options in lengthy privacy notices or requiring users to call or write to invoke their rights does not comply ([ICO guidance, "How to obtain, record and manage consent"], see also Recital 42 UK GDPR).
- Effect of withdrawal: Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal. This clarifies that organizations do not have to "undo" processing that has already occurred, but must cease affected processing moving forward (Article 7(3), second subparagraph).
- Notification and clarity: At the time of obtaining consent, the controller must inform the data subject of their right to withdraw consent at any time and must do so in a manner which is clear, intelligible, and separate from other information (Article 7(3), Recital 42 UK GDPR, and ICO best practice).
- No detriment: Withdrawal must not be made unnecessarily difficult or have unjustified negative consequences for the data subject. Controllers may not penalize or deter withdrawal, for example, by denying access to a service unless consent is genuinely required for that service (see also EDPB Guidelines 05/2020, which the ICO treats as persuasive).
- Ongoing obligations: If processing is based on multiple lawful bases (e.g., both consent and legal obligation), only processing that relies on consent must cease. Responsibility falls on the controller to document the basis for each processing purpose and track which processing operations must stop when consent is withdrawn.
Operational steps for controllers
- Mechanisms: Controllers should offer clear mechanisms to withdraw consent—such as prominent unsubscribe links in emails, straightforward app settings, or a dedicated portal. Confirmation of withdrawal should be provided where possible.
- Record-keeping: Controllers must be able to demonstrate when and how consent was withdrawn, as part of their general accountability obligations (Article 5(2) and Article 7(1)).
- Third-party processors/recipients: Where personal data has been disclosed to others based on consent, controllers should inform third parties of the withdrawal "where possible" unless this requires disproportionate effort (Article 19).
Enforcement and ICO expectations
The UK Information Commissioner's Office will take action on complaints where withdrawal is obstructed, delayed, or inadequately signposted. Breaches may result in enforcement notices or administrative fines under Article 83(5) UK GDPR (upper tier).
Summary: The right to withdraw consent must be actionable, accessible, and respected in substance as well as form. Controllers must make it as easy to withdraw as to give consent, cease all consent-based processing upon withdrawal, and inform data subjects up front of this right.
Source: Article 7(3) UK GDPR (as retained in UK law) Source: ICO: Guide to the UK GDPR — Consent
What processing is allowed and required notification duties when data is restricted (Article 18(2)–(3), Article 19 UK GDPR)
When a restriction of processing is applied under Article 18 UK GDPR, the legal and practical boundaries of what a controller may do with the restricted personal data are precisely defined. This section provides an operational breakdown of the permitted processing, the role of consent and overriding interests, and the onward notification requirements under Article 19.
What is “restriction” under Article 18(2)?
Restriction of processing means that, apart from storage, no further use may be made of the restricted data except in narrow cases. Article 18(2) enumerates the only circumstances in which processing of restricted data is lawful:
- with the data subject’s consent;
- for the establishment, exercise, or defence of legal claims;
- for the protection of the rights of another natural or legal person;
- for reasons of important public interest of the United Kingdom.
In practice, this means that while the data remains “frozen” for the original or most processing purposes, it is not subject to an absolute ban. For example:
- Consent: A controller may process the restricted data for a new or ongoing purpose if the individual expressly consents, which must be freely given, specific, and informed as with any GDPR consent (Article 7).
- Legal claims: If litigation is anticipated or ongoing, the data can be used to pursue or defend legal rights—by either party.
- Protection of others’ rights: This is a catch-all, permitting processing necessary to safeguard the fundamental rights or freedoms of others (such as avoiding harm to other data subjects).
- Important public interest: This permits use if a statutory or substantial public-benefit ground is engaged, but is narrowly construed.
How must controllers operationalize restriction?
Data must typically be “flagged” or “held” in IT systems so that it is excluded from most processing activities, and only released for one of the exception purposes above. Controllers need strong internal controls—both to document the restriction status, and to ensure permitted exceptions are only acted on with appropriate rationale and record-keeping. The ICO expects a clear audit trail justifying any enabled processing under an Article 18(2) exception.
Onward notification duty — Article 19
When data is restricted, Article 19 UK GDPR obliges the controller to notify every recipient to whom the data has previously been disclosed, unless this is impossible or involves disproportionate effort. This allows downstream recipients (such as service providers or data processors) to implement the same restriction.
If the data subject requests, the controller must also inform them about those recipients. Proper maintenance of records of data disclosures is thus essential for compliance.
Remedies and enforcement
Non-compliance with these restrictions or the notification duty may result in complaints to the ICO or court, and is subject to upper-tier penalties under Article 83(5): up to £17.5 million or 4% of worldwide turnover.
Source: Article 18, UK GDPR (Regulation (EU) 2016/679 as incorporated in UK law) Source: Article 19, UK GDPR (notification obligation) Source: ICO: Right to restrict processing