Stop Paying Americans to Fix a Problem British Regulators Created

Opinion

Stop Paying Americans to Fix a Problem British Regulators Created

Let me be precise about what I am criticising and what I am not.

I am not criticising DeleteMe or Incogni for existing. They saw a genuine problem, a privacy ecosystem so opaque and labour-intensive that ordinary people cannot navigate it, and built a service that addresses part of it. Incogni even had its claims independently verified by Deloitte in August 2025. That is more accountability than most of the industry shows.

What I am criticising is the system that made these services necessary in the first place.

What the Market Is Actually Telling You

A subscription market exists when a legitimate need is not being met by free alternatives. When the product being sold is a service to help people exercise rights they theoretically own for free, the market is telling you something specific about those rights.

It is telling you that the rights exist on paper but are difficult to exercise in practice. It is telling you that the organisations processing your data have designed their opt-out and removal processes to be friction-heavy by default. It is telling you that the regulator has not made those opt-out processes easier, or enforced minimum standards for how quickly and completely they work.

And it is telling you that someone has noticed this gap and decided to charge for filling it. That is rational behaviour on the part of the services. It is not acceptable behaviour on the part of the system that created the gap.

The Dollar Problem

A meaningful proportion of UK users paying for data removal services are paying in US dollars to a company headquartered outside the UK, to exercise rights under UK law, against processing that the UK’s own regulator has the powers to address.

That is a remarkable sentence. Read it again.

You are paying a foreign company to help you use a domestic legal right because the domestic enforcement environment has not made the underlying rights easy enough to exercise yourself. The commercial gap that DeleteMe and Incogni fill is, in a direct and specific sense, a consequence of the ICO not having moved fast enough or hard enough to change market behaviour.

I am not saying the ICO has done nothing. It investigated Experian, Equifax, and TransUnion in 2020 and found systemic failings. It issued an enforcement notice. It appealed when Experian challenged it. Those are real actions.

What I am saying is that those actions did not change the market enough to make subscription removal services unnecessary. The market grew. The services thrived. The regulatory gap remained commercially viable.

The Correct Use of These Services

If you are a UK director with limited time and a real privacy problem, paying for a well-evidenced removal service as part of a broader approach is not irrational. Time has value. Recurring cycles have value. Incogni’s Deloitte-verified 60 to 90-day re-submission cycles are more systematic than most individuals will manage manually.

But these services should be layer two, not layer one.

Layer one is fixing the upstream official sources. Companies House address suppression. Electoral register opt-out. These are free, they address the highest-priority sources, and no subscription service can do them for you.

Layer two is systematic broker removal, which is where a paid service may provide genuine value if it covers the specific UK brokers that actually hold your data.

If you skip layer one and go straight to a subscription, you are paying monthly to chase a problem whose primary source is still active and still feeding downstream databases.

What Actually Needs to Change

Three things. I have said some of these before. I will keep saying them until they are either implemented or someone explains why they cannot be.

The ICO, now the Information Commission under the DUAA 2025, needs to impose meaningful monetary penalties on commercial data brokers when they fail to comply with erasure requests. One monetary penalty, in a publicly visible case, against a well-known broker for systematic non-compliance, would change the commercial calculation for the entire sector.

Companies House needs to make address suppression a prominently advertised default option in the company formation process, and reduce the friction of the suppression application for existing directors. The current process costs £30, requires an administrative precondition, and is unknown to most of the directors who need it.

The government needs to fund a public awareness campaign telling UK directors what their data rights are and how to exercise them. Not a website. An actual campaign that reaches the people who need it.

None of that requires new legislation. All of it is within existing powers and budgets. None of it is happening at the pace or scale required.

The Question Worth Asking Publicly

UK GDPR is regularly described in government and regulatory communications as a world-leading data protection framework. The retention of EU adequacy in December 2025 is cited as evidence that UK data protection standards remain robust.

Here is the question that deserves a direct answer: if UK GDPR is a world-leading framework that adequately protects individual data rights, why is there a profitable, growing commercial industry built around helping people exercise it?

The existence of that market is not a sign of innovation. It is a sign of failure. The failure is in the design of rights that require administrative endurance to exercise, in the enforcement posture that has not changed market behaviour at scale, and in the public awareness gap that means most directors do not know what rights they have let alone how to use them.

I am not being hostile to the ICO. I am describing a gap between the law’s stated ambitions and the practical reality for the people it was supposed to protect. That gap has a commercial value. Someone is profiting from it. That is what markets do.

The answer is not to cancel your subscription. The answer is to fix the system so that subscriptions become a convenience rather than a necessity.

How to Turn This Into a Competitive Advantage

For MSPs and advisers, the regulatory failure argument is the correct framing for a director data governance conversation. The law exists. The rights exist. The enforcement gap means that individual action is the practical tool rather than an optional extra. Being the adviser who helps clients exercise those rights systematically, rather than pointing them at a subscription service and hoping for the best, is a meaningful differentiator.

For business owners, taking the structural problem seriously enough to act on it individually, while also raising it collectively through trade bodies and professional associations, is the correct combination. Individual action protects your directors now. Collective pressure improves the system for everyone.

How to Sell This to Your Board

The board argument is that the regulatory framework has not provided adequate market-level protection. That is a documented position, not an opinion. The business therefore needs to manage director exposure actively as a governance matter, regardless of what the regulator eventually does. The cost is time. The benefit is reduced attack surface for impersonation fraud. That is a straightforward risk management conversation.

What to Do This Week

  1. Complete the two-hour test from Thursday’s guide if you have not already.
  2. Fix Companies House and electoral register exposure through official channels.
  3. If considering a subscription service, complete the five-question checklist from Friday’s guide before paying.
  4. Raise the issue with your trade body or professional association. Ask what their position is.
  5. Write one sentence to your MP summarising the problem: data rights that require stamina to exercise are not universal rights. Ask what they think should change.
SourceArticle
ICOGuidance for the data broking sector
Privacy InternationalUK regulator takes enforcement action against data brokers
noybCouncil of State upholds Criteo’s €40m GDPR fine
Companies HouseRemove your home address from the Companies House register
ICOElectoral register opt-out
GOV.UKData Use and Access Act 2025 guidance

Filed under

  • smb-security
  • uk-business
  • compliance-failure
  • data-protection
  • business-risk
  • vendor-risk
  • public-sector-security