DeleteMe and Incogni: Are Data Removal Services Worth It for UK Users?
DeleteMe and Incogni are not scams.
Let us be clear about that upfront, because the episode title tempts people toward the wrong conclusion. These services exist. Some provide a genuine function. The people who run them are not criminals.
But there is a more interesting story here. A paid subscription market has emerged to help people exercise legal rights they already own for free. That market exists because those rights are difficult, repetitive, and frustrating to exercise in practice. And for UK users specifically, a significant part of the difficulty is that the biggest services were built around the US data broker ecosystem, not the UK one.
This is Episode 4 of The Open Book Problem. The practical one.
Why These Services Exist
Broker removal is tedious. Genuinely tedious.
You need to know which brokers exist. You need to find their removal routes. You need to make the request. You need to verify identity. You need to track the response. You need to check whether the data returns. Then you need to do it again for the next broker, and the one after that, and again in three months when data reappears.
So the product is not really privacy. The product is not having to do a miserable administrative task yourself. That is a legitimate service. Time has value. Delegation has value. A central dashboard tracking multiple requests has value.
The problem for UK users is the coverage gap.
The Coverage Gap
Most major removal services grew from the US market. That makes commercial sense. The US people-search ecosystem is enormous, aggressive, and largely self-regulated. Services like DeleteMe built their broker lists around that ecosystem.
UK users should not assume US coverage translates to UK exposure sources. It does not.
A UK director’s exposure profile is different. Companies House. The open electoral register, commercially licensed for broker use. UK credit reference relationships. UK marketing lists. UK people-search sites. Local directories. Professional body listings. Sector-specific registries. Charity registers where applicable.
If a service’s primary broker list is US-focused, a UK director may see limited practical benefit. You may be paying in US dollars to solve the wrong country’s problem.
Before subscribing, ask the service directly: which UK-specific data brokers are included in your automated removal list? If the answer is vague, the service is not designed for you.
The Upstream Problem
There is a more fundamental issue, and it applies regardless of which service you choose.
The biggest sources of UK director exposure are not data brokers. They are public records: Companies House and the open electoral register.
No paid removal service can change your Companies House records. No subscription can opt you out of the open electoral register. Those require direct action through official Government channels, and they require it first. If your home address is still publicly listed at Companies House as a service address or registered office, a data removal subscription is treating the symptom while the cause continues producing data.
Think of it this way. A data broker holds a copy of information that originally came from a public source. Removing the broker copy is useful. But if the source continues to publish, the broker’s next database refresh may repopulate your record. The data removal service then removes it again. And again. That is why the business model is effectively a recurring subscription rather than a one-time fix.
The business model is not Delete Me. It is Please Keep Deleting Me While The System Keeps Republishing You.
Fix the upstream sources first. Then address downstream broker copies.
What DIY Looks Like
A structured DIY approach works through priority order rather than trying to clear the entire internet simultaneously. Here is the sequence that makes sense for UK directors.
Step one: fix official sources. Check Companies House. Change any live records that include home addresses as service addresses or registered offices. Apply for home address removal or suppression where eligible. Opt out of the open electoral register at your local council.
Step two: search for yourself. Use search engines to find your name, company name, address, and director profile. Include variations. Note every site that appears with your personal data in the first three pages. That is your priority list.
Step three: submit subject access and erasure requests. Use the ICO’s template letters. Keep copies. Set calendar reminders for the response deadline (one month under UK GDPR).
Step four: track everything. Date sent. Which broker. Response deadline. What they said. Whether data was removed. Whether it reappeared. A simple spreadsheet is sufficient. Without a record, you lose the thread.
Step five: recheck at three to six months. The data broker machine is not a filing cabinet. It is a system that keeps refreshing from upstream sources. One pass through is not sufficient.
The Two-Hour Test
Before purchasing any removal service, run the two-hour test.
Spend thirty minutes searching your name, company, address, and director profile across search engines and visible broker sites.
Spend thirty minutes checking your Companies House entries and electoral register position.
Spend thirty minutes identifying the top results that actually display your data.
Spend thirty minutes submitting the highest priority correction or removal requests yourself.
After two hours, you will know whether your exposure is primarily upstream (official records requiring direct action), primarily downstream (broker copies addressable with free Article 17 requests), or both.
That tells you whether a paid service would add genuine value or solve a problem that free routes already address.
The False Confidence Risk
The bigger risk with paid removal services is not wasted money. It is false confidence.
A director pays for a subscription. The dashboard shows a satisfying number of removals. The percentage bar moves reassuringly. They assume the threat is handled.
But the same director may still have home address exposure at Companies House, an open electoral register listing, unnecessary detail on LinkedIn, job adverts that expose internal systems, weak payment verification controls, and old login portals nobody has decommissioned.
The digital garden looks tidy because someone swept the patio while the shed is on fire.
Data removal reduces attacker context. It does not stop impersonation attempts when enough context remains from other sources. You still need verification controls, MFA hardening, payment approval processes, and staff with explicit permission to slow down and check.
What a Good Service Would Prove
A good removal service should demonstrate its work with evidence, not soothing percentages.
It should show which brokers were checked, which records were found, which requests were sent, which brokers responded, what changed, and what did not.
For UK users specifically, it should explain which UK sources are not addressable through broker opt-outs, and which require official government processes instead. That explanation should be clear enough to embarrass the marketing department if they tried to bury it.
If a service turns uncertainty into a green tick without explaining what it checked, that is a dashboard designed for anxiety management rather than genuine privacy improvement.
The Priority Order for UK SMB Directors
For a UK SMB director, the priority order is:
- Companies House home address exposure. Fix and suppress where eligible.
- Open electoral register opt-out.
- Obvious people-search results for your name and address that appear in the first three search pages.
- Domain registration privacy settings and old technical records.
- LinkedIn and job advert hygiene.
- Broker removal requests, starting with the services that demonstrably hold your data.
A paid service may be useful at step six. Steps one through five are not addressable by subscription. They require your direct action.
How to Turn This Into a Competitive Advantage
For MSPs and advisers, this is a differentiated service offer. Walk a client through the two-hour test. Help them fix their Companies House records. Opt them out of the open electoral register. Audit their LinkedIn and job adverts. Submit their priority erasure requests.
Most competitors either ignore this entirely or try to sell a subscription product. Neither addresses the upstream problem. Being the adviser who actually fixes the source rather than polishing the symptoms is a concrete value proposition.
For business owners, being able to demonstrate that you have audited and reduced director exposure is increasingly relevant in security-conscious procurement. If a client asks what you do to protect your organisation against impersonation fraud and social engineering, having a documented answer that goes beyond “we have anti-virus” is a differentiator.
How to Sell This to Your Board
Three points that land:
The subscription market exists because the underlying system is broken. When private companies charge monthly fees to help people exercise statutory rights, that is evidence that those rights are not working as intended. That is a governance context worth understanding before spending money on a partial solution.
Paid services do not address the highest-priority UK exposure sources. Companies House and the open electoral register require direct action. If the board approves a removal subscription without addressing upstream sources first, it is funding a recurring cost that does not solve the root problem.
The two-hour test costs nothing. It tells you exactly where your exposure sits and what it would take to address it. That is the right starting point for a budget conversation, not a vendor’s pricing page.
What to Do This Week
-
Run the two-hour test. Search yourself as an attacker would. Document what you find.
-
Check Companies House. Identify any home addresses in live records and start the process of correcting or suppressing them.
-
Opt out of the open electoral register. Contact your local council. It takes ten minutes.
-
Submit priority erasure requests. Use the ICO’s template letters for the brokers that appear prominently in search results for your name and address.
-
If you use a paid service, check their UK coverage list. Ask them directly which UK brokers are covered, whether Companies House-derived exposure is addressable, and what evidence they provide that removals were completed.
Listen to the full episode: The Open Book Problem, Episode 4: The Subscription Scam That Is Not Quite a Scam.
Next in the series: Episode 5, The Fix That Actually Exists. The full cast returns to close the series. Corrine ranks the exposures by actual attack risk. I provide the thirty-day action plan. Mauven makes the policy argument. Lucy summarises the accountability questions that remain unanswered. And Noel tries to be constructive.