Seven Years of UK GDPR. The Data Broker Market Has Never Been Bigger.
Here is the version of the GDPR story that does not appear in most compliance briefings.
UK GDPR came into force in 2018. It gave every adult the right to know what personal data organisations hold about them, the right to correct it, the right to erase it, the right to object to its processing.
It also gave the ICO the power to impose fines of up to £17.5 million or 4% of global annual turnover for serious breaches.
Seven years later, the ICO has not imposed a monetary penalty on a UK data broker.
The Record
In October 2020, the ICO published the results of a two-year investigation into data protection compliance in the direct marketing data broking sector. The finding was unambiguous: “widespread and systemic data protection failings across the sector.” Between Experian, Equifax, and TransUnion, the data of almost every adult in the UK was being screened, traded, profiled, enriched, or enhanced for direct marketing without most individuals knowing it happened.
The ICO issued an enforcement notice against Experian. Experian appealed. The First-tier Tribunal ruled substantially in Experian’s favour in February 2023. On 23 April 2024, the Upper Tribunal dismissed the ICO’s appeal on all five grounds. In May 2024, the ICO confirmed it would not pursue a further appeal.
No monetary penalty. No final ruling that the core processing was unlawful at the alleged scale.
In the same period, France’s CNIL fined Criteo €40 million in June 2023 for consent failures. That fine was upheld by France’s Council of State in March 2026. The Dutch Authority for Personal Data fined Clearview AI €30.5 million in 2024, with an additional daily penalty of €5.1 million.
Why This Matters for SMB Directors
The reason this enforcement history matters is direct. The commercial data broker market processes personal information on every UK adult, including every director of every small business in the country. That processing feeds the attacker reconnaissance picture. It links business identity to home address, financial indicators, household data, and marketing segments in ways that turn the Companies House register from a transparency tool into a targeting resource.
The regulatory framework was designed to give individuals control over that processing. The enforcement record, as it stands, has not produced the market-level change that framework was intended to create.
Individual data rights remain. Subject access requests. Erasure requests. Objection rights. The ICO has template letters. The new mandatory complaints handling requirement under the Data (Use and Access) Act 2025 adds another layer from 19 June 2026.
But individual rights exercised against a systemic problem, one at a time, by individuals who must first identify which brokers hold their data, are a limited substitute for enforcement that changes the market.
Episode 3: The Regulator Who Looked the Other Way
Today Lucy Harper joins me for Episode 3 of The Open Book Problem.
Lucy brings the accountability journalism angle. She is precise about what the ICO has and has not done, because overclaiming gives the regulator somewhere to hide. The stronger argument is the gap between the scale of the problem and the scale of the response.
We cover: the Experian case and what the tribunal outcome signals; why the EU enforcement comparison is relevant; the questions the public record cannot yet answer about ICO oversight of the data broker sector; and what the Data (Use and Access) Act 2025’s enhanced powers may or may not change.
This week’s companion content goes deeper. Tuesday examines the seven-year enforcement record in full. Wednesday, Mauven analyses what the Upper Tribunal judgment signals to the industry. Thursday, Graham gives the step-by-step process for submitting UK GDPR erasure requests that actually work. Friday, Lucy asks the six accountability questions the public record cannot yet satisfactorily answer.
Episode 3 is live now.
How to Turn This Into a Competitive Advantage
The enforcement gap is specialist knowledge that most advisers do not have. Being able to place a client’s data rights questions within the actual regulatory context, rather than citing GDPR provisions as if they automatically protect anyone, is a genuine competence marker.
For business owners, understanding the gap means being realistic about what the regulatory environment currently provides, and taking active steps accordingly rather than assuming the regulator is handling it.
How to Sell This to Your Board
The board-level point: the law contains rights and the regulator has powers. The enforcement record to date has not produced the market-level change those rights and powers were designed to create. Your board should not assume that the ICO is addressing this on your directors’ behalf. Active individual rights management is the practical posture until enforcement improves.
What to Do This Week
Listen to Episode 3. Then submit a subject access request to the data broker whose listing appears first when you search your own name and address. One request. Today. The ICO template letter takes ten minutes.