Most people only think about their legal privacy protections after something goes wrong: a company loses their details, refuses to delete an account, or sends marketing they never agreed to. Yet UK GDPR data protection rights exist before any of that happens, and they are enforceable. A recent explainer from The Complaining Cow walks through personal data, privacy, subject access requests, complaints and passwords. This post builds on that material and places it in the context of the wider UK policy debate over VPNs, encryption and online safety.
What UK GDPR Protects and What Counts as Personal Data
UK GDPR is the domestic version of the General Data Protection Regulation. It governs how organisations collect, use, store and share information about individuals. The Data Protection Act 2018 sits alongside it as national law that supplements the regime, and our guide to the Data Protection Act 2018 and its seven principles explains how the two fit together.
Personal data is, in simple terms, information that relates to an identifiable person. That covers the obvious items such as your name and address, but the idea is broader than many people assume. Anything that can be tied back to you can fall within scope when an organisation handles it. That is why the rules matter for everyday services, from shops and banks to apps and websites.
Passwords are also part of this picture. A password is not usually the data an organisation is protecting for its own sake, but it guards access to the personal data inside your accounts. When an organisation handles credentials poorly, the privacy consequences can follow quickly.
Your Core Rights: Access, Erasure and Complaints
Government guidance lists a set of rights for individuals. You can be informed about how your data is being used, access the personal data an organisation holds, have incorrect data updated, have data erased, and stop or restrict the processing of your data. Under Articles 16, 17 and 18 of UK GDPR, individuals can ask for rectification, erasure or restriction of processing.
Here is how these rights work in practice:
- Subject access requests: You can ask an organisation what personal data it holds about you. This is often the best first step, because it shows you what exists before you decide what to challenge.
- Rectification: If information is inaccurate or incomplete, you can ask for it to be corrected or completed.
- Erasure: Sometimes called the right to be forgotten, this lets you ask for your data to be deleted in the right circumstances. It is not an automatic override in every case.
- Restriction: You can ask an organisation to limit how it uses your data while a dispute is being resolved.
If an organisation ignores you or handles a request badly, you can complain. The usual route is to raise the issue with the organisation first, keep a written record, and then escalate to the data protection regulator if you are not satisfied. Keeping dates, copies and reference numbers makes any complaint easier to pursue.
Where VPNs and Encryption Fit Alongside Legal Rights
Legal rights and technical tools do different jobs. UK GDPR data protection rights give you leverage over organisations that already hold your information. A VPN, by contrast, encrypts your connection and masks your IP address from the sites you visit, which reduces what gets exposed in transit. Neither replaces the other.
A VPN cannot make a company delete the records it already holds, and a subject access request cannot stop your internet provider from seeing unencrypted traffic. Think of the law as your remedy after data is collected, and tools such as encryption, careful settings and strong, unique passwords as ways to collect less of it in the first place.
This distinction matters because UK policy debates increasingly place VPNs, encryption and online-safety rules in the same conversation. Understanding what your legal rights actually cover helps you judge claims made on either side of that debate, without assuming that one measure does the work of the other.
How UK Data Protection Law Could Change
The legal framework is not fixed. Reform UK has pledged to scrap GDPR as part of a wider plan to cut business red tape, replacing it with what the party calls a "light-touch" approach to data. We examined the details in our coverage of the Reform UK GDPR scrap pledge and its privacy impact.
A pledge is not a law, and nothing changes for your current rights until legislation is actually passed. Still, it is a useful reminder that the rights described above depend on political choices. If the framework were rewritten, the specific protections for access, erasure and complaints could look different, which is why it is worth knowing what you have today.
What This Means For You
You already hold practical tools under UK GDPR. You do not need to be a lawyer to use them: a clear, dated written request is often enough to start the process. Using your rights does not conflict with using privacy tools. The two approaches reinforce each other, and combining them gives you more control than relying on either alone.
Actionable Takeaways
- Make a subject access request to an organisation you suspect holds more of your data than it should.
- Ask for corrections when information about you is wrong, and request erasure when you no longer want an account or service.
- Keep written records of every request, reply and deadline in case you need to complain.
- Use strong, unique passwords for each account, since they protect the data your rights apply to.
- Treat VPNs and encryption as a complement to your legal rights, not a substitute.
To understand how the legal framework fits together, read our Data Protection Act 2018 explainer, and follow our Reform UK GDPR pledge coverage to see how UK GDPR data protection rights could shift in the future.




