Public information Reform UK Data Rights

Data Protection Myth-Busters

Twelve common claims about UK GDPR that are partly or wholly wrong, and what the law actually says.

People sometimes assume a request has been mishandled when the law actually permits the processing in question. We publish this list so you can check the position yourself, with direct references to UK GDPR.

Each entry has a stable web address. Use the link icon to copy it for sharing or citing in a complaint.

  1. Myth 1 of 12

    “You must delete all my data if I ask.”

    What the law actually says

    The right to erasure is not absolute. We may retain data where required for legal obligations, regulatory purposes, or legal claims.

  2. Myth 3 of 12

    “Contacting 16/17-year-olds is illegal.”

    What the law actually says

    Individuals aged 16-17 may appear on the Electoral Register (attainers register) and can be contacted lawfully for democratic engagement.

    General data-protection principle. No single Article cited.
    Copy link to this entry
  3. Myth 4 of 12

    “You must respond within 30 days or you've broken the law.”

    What the law actually says

    The law allows one calendar month, which may be extended by up to two further months for complex requests.

  4. Myth 5 of 12

    “If you contacted me, you must hold lots of data about me.”

    What the law actually says

    We often do not retain records of individual mailings. Data may have been used from publicly available sources at a specific point in time.

    General data-protection principle. No single Article cited.
    Copy link to this entry
  5. Myth 6 of 12

    “This is a data breach.”

    What the law actually says

    Not all errors are breaches. A breach involves unauthorised access, loss, or disclosure of personal data.

  6. Myth 7 of 12

    “You can't use publicly available data.”

    What the law actually says

    Public data (including the Electoral Register) can be used lawfully where a valid lawful basis applies.

    General data-protection principle. No single Article cited.
    Copy link to this entry
  7. Myth 8 of 12

    “GDPR stops political parties contacting people.”

    What the law actually says

    Data protection law supports a balance between privacy and democratic engagement. Political communication is a recognised lawful activity.

    General data-protection principle. No single Article cited.
    Copy link to this entry
  8. Myth 9 of 12

    “If I object, you must stop everything immediately.”

    What the law actually says

    Objections are considered carefully, but processing may continue where compelling legitimate grounds exist.

  9. Myth 10 of 12

    “You must prove exactly where you got my data from.”

    What the law actually says

    We explain data sources at a category level (e.g. Electoral Register). We may not retain records of specific extraction instances.

    General data-protection principle. No single Article cited.
    Copy link to this entry
  10. Myth 12 of 12

    “If I complain, you're automatically in breach.”

    What the law actually says

    Complaints are reviewed seriously, but they do not automatically indicate unlawful processing.

    General data-protection principle. No single Article cited.
    Copy link to this entry

Wording is verbatim from our Compliance source. If you believe an entry is wrong or out of date, email [email protected].