Data Protection Myth-Busters
Twelve common claims about UK GDPR that are partly or wholly wrong, and what the law actually says.
People sometimes assume a request has been mishandled when the law actually permits the processing in question. We publish this list so you can check the position yourself, with direct references to UK GDPR.
Each entry has a stable web address. Use the link icon to copy it for sharing or citing in a complaint.
-
Myth 1 of 12
“You must delete all my data if I ask.”
What the law actually says
The right to erasure is not absolute. We may retain data where required for legal obligations, regulatory purposes, or legal claims.
-
Myth 2 of 12
“You need my consent before sending me political mail.”
What the law actually says
Political parties can lawfully contact individuals using Electoral Register data without consent, typically under legitimate interests.
-
Myth 3 of 12
“Contacting 16/17-year-olds is illegal.”
What the law actually says
Individuals aged 16-17 may appear on the Electoral Register (attainers register) and can be contacted lawfully for democratic engagement.
General data-protection principle. No single Article cited.Copy link to this entry -
Myth 4 of 12
“You must respond within 30 days or you've broken the law.”
What the law actually says
The law allows one calendar month, which may be extended by up to two further months for complex requests.
-
Myth 5 of 12
“If you contacted me, you must hold lots of data about me.”
What the law actually says
We often do not retain records of individual mailings. Data may have been used from publicly available sources at a specific point in time.
General data-protection principle. No single Article cited.Copy link to this entry -
Myth 6 of 12
“This is a data breach.”
What the law actually says
Not all errors are breaches. A breach involves unauthorised access, loss, or disclosure of personal data.
-
Myth 7 of 12
“You can't use publicly available data.”
What the law actually says
Public data (including the Electoral Register) can be used lawfully where a valid lawful basis applies.
General data-protection principle. No single Article cited.Copy link to this entry -
Myth 8 of 12
“GDPR stops political parties contacting people.”
What the law actually says
Data protection law supports a balance between privacy and democratic engagement. Political communication is a recognised lawful activity.
General data-protection principle. No single Article cited.Copy link to this entry -
Myth 9 of 12
“If I object, you must stop everything immediately.”
What the law actually says
Objections are considered carefully, but processing may continue where compelling legitimate grounds exist.
-
Myth 10 of 12
“You must prove exactly where you got my data from.”
What the law actually says
We explain data sources at a category level (e.g. Electoral Register). We may not retain records of specific extraction instances.
General data-protection principle. No single Article cited.Copy link to this entry -
Myth 11 of 12
“You need consent to hold any personal data.”
What the law actually says
Consent is only one of six lawful bases. Many activities rely on legitimate interests or legal obligations.
-
Myth 12 of 12
“If I complain, you're automatically in breach.”
What the law actually says
Complaints are reviewed seriously, but they do not automatically indicate unlawful processing.
General data-protection principle. No single Article cited.Copy link to this entry
Wording is verbatim from our Compliance source. If you believe an entry is wrong or out of date, email [email protected].