If Your Legal Rights Only Work When You Have Stamina, Who Are They Really For?

Opinion

If Your Legal Rights Only Work When You Have Stamina, Who Are They Really For?

UK GDPR was written with universal intent. Every adult in the UK has the right to know what personal data organisations hold about them. The right to correct it. The right to erase it. The right to object to its processing.

Every adult. The word was deliberate. This was supposed to be a right for everyone, not a right for people who happen to know what a data broker is.

I want to be honest about what happened.

The Gap Between the Words and the Reality

The rights are real. They exist in statute. The ICO has template letters. The process is documented. Anyone can, in principle, exercise these rights against any data broker.

In practice, exercising those rights requires: knowing which data brokers exist and hold your personal data, finding their individual removal or opt-out routes, understanding the difference between suppression and deletion, submitting the request in a form the broker accepts, providing identity verification without handing over more data than necessary, tracking the one-month response deadline, sending a chaser on day 28 before the deadline passes, reading the response and determining whether it is legally adequate, challenging an inadequate response, submitting an ICO complaint if the broker ignores or improperly refuses, and repeating the entire sequence every 90 days when data reappears from refreshed upstream sources.

That is not a right. That is an unpaid part-time job that never ends, assigned to the person whose rights were violated in the first place.

Who Can Actually Do This

Let me be precise about who can sustain the rights exercise process indefinitely.

People who know what a data broker is, or are willing to learn. People who have time outside work and family responsibilities. People who have the confidence to write formal requests to companies and challenge their responses. People who are comfortable navigating the ICO complaints process. People who will not abandon the effort when the data reappears for the third time.

That profile systematically advantages the educated, the digitally literate, the English-fluent, the time-rich, and the persistent. It disadvantages the person who used their home address as their company’s registered office because nobody told them not to, has never heard of the ICO, does not know what Article 17 means, and has a business to run.

And that second person is exactly the one most likely to be exploited by the exposure the system created.

The Deliberate Friction Argument

I am going to make a claim that some people will find uncomfortable.

The friction in the data rights exercise process is not an accident of poor implementation. It is a predictable consequence of a design that balanced commercial data economy interests against individual rights and came down, in practical terms, more on one side than the other.

Friction benefits the organisations doing the processing. If the rights exercise process is laborious, most people will not start it. Of those who do, many will abandon it when data reappears. The fraction who persist to the point of meaningful reduction in their commercial profile is small.

I am not arguing that the law was written in bad faith. I am arguing that the outcome, a data rights framework that functions primarily as a personal exercise in administrative endurance rather than a structural check on commercial data processing, was predictable from the design choices that were made.

What Would Actually Work

Three structural changes would make UK data rights genuinely universal rather than theoretically available.

First, meaningful transparency requirements on brokers that allow individuals to easily identify which companies hold their data, from which sources, and what they have done with it. Not a privacy notice on a website they will never find. Actual discoverability.

Second, a prohibition on reprocessing data after a confirmed erasure request from an upstream source that the broker continued to use. If you remove my data and then reacquire it from the same source, you have not honoured the erasure. You have just reset the clock.

Third, a funded public awareness campaign. Not a government website. An active campaign that tells every UK director that their data is probably in commercial profiles, explains what that means, and walks them through the exercise of their rights in plain English.

None of those things is technically difficult. None requires new legislation beyond existing powers. All of them would cost money and face commercial resistance.

The One Thing I Am Asking

If you read this, use one piece of it.

Opt out of the open electoral register. Contact your local council. It takes ten minutes. It costs nothing. It removes your home address from the commercially available version of the register that feeds broker databases.

One action. Ten minutes. Free. No tracking spreadsheet. No ICO complaint. No repeated follow-up.

The rest of the system will continue operating as described. But that one action is within everyone’s reach, regardless of stamina.

How to Turn This Into a Competitive Advantage

For advisers and MSPs, the stamina argument is a client conversation about realistic expectations. Being the adviser who explains this honestly, rather than selling a solution that creates false confidence, is a differentiator.

For business owners, active management of data rights, even imperfect management, demonstrates governance seriousness that can be documented and shared with clients and partners.

How to Sell This to Your Board

The law gives directors data rights. Exercising those rights is laborious in ways that systematically disadvantage people without time and confidence. The business should manage those rights on behalf of its directors, not leave each director to navigate the process individually. Assign ownership. Fund the time. Review at 90 days.

What to Do This Week

  1. Opt out of the open electoral register. Contact your local council. Ten minutes. Free.
  2. Check Companies House for home address exposure. Start the suppression process if applicable.
  3. Submit erasure requests to the top two or three broker sites appearing for your directors.
  4. Contact your trade association and ask what position they have on director data exposure.
  5. Set a 90-day calendar reminder to recheck search results for your directors.
SourceArticle
ICOYour right to get your data deleted
ICOElectoral register opt-out
ICOGuidance for the data broking sector
Privacy InternationalUK regulator takes enforcement action against data brokers
GOV.UKData Protection Act 2018

Filed under

  • smb-security
  • uk-business
  • compliance-failure
  • data-protection
  • business-risk
  • executive-security
  • public-sector-security