The GDPR has been part of UK law since 2108. What impact has it had, and where is there still work for UK based organisations to do? Overall there has been a significant step forward in the application of the GDPR principles. In the early says there was a lot of work done to comply with the GDPR. This was largely driven by the unfounded fears of large fines. However progress has slowed somewhat since 2018. Our experience is that there is more work do to to achieve compliance. Overall there are both positives and negatives in terms of how well personal data is being managed.

Privacy by default and by design is not systematically applied
A key aim of the GDPR is to get organisations to factor personal data into planning and design activity. In sort, treat data much as they do money, people and other resources. Today still a lot of organisations think about GDPR compliance at the end of project, product or service design. For example when working with clients as Data Protection Officer we often got told about marketing activity a company had decided to do. But, we were asked to check if it was GDPR compliant after the decision had been made and the campaign designed. This can lead to a duplication of work if things need to be changed or processes redesigned.
In addition there is not as much thought as there should be, when starting any kind of data processing activity, about data security, limiting access, data deletion etc. and identifying learning / continuous improvement in terms of data privacy.
While this may read as a bit abstract, particularly as GDPR compliance is patchy and data breaches widespread, it is as if organisations were saying there is no point in designing and implementing financial controls as some level of fraud is inevitable. No successful organisation would dream of operating in that way.
Organisations are not fully abiding by the Principles of GDPR
What are the 7 principles of GDPR? They set out that data must be used:
- lawfully, fairly and transparently
- only for the purposes specified
- only for a limited period
- safely and securely
- in the smallest amount possible
- accurately
The GDPR also sets out that data processors are accountable for demonstrating compliance with these principles (the so-called accountability principle)
There are still major issues across all sectors for organisations in terms of:
- disposing of personal data that they no longer need or use;
- ensuring the personal data they have is accurate and up to date;
- or only processing the minimum necessary data.
This will and does cause headaches for organisations. when people exercise their data rights, or if there is a data breach. For example, in our experience, subject access requests are presenting a major problem for some organisations because of the sheer volume of information that they retain, unintentionally, in emails, archives and old electronic files. A viable programme of data audit and deletion based on a robust retention schedule would be enormously beneficial.
Organisations are (rightly) moving away from consent as a lawful basis
Many organisations defaulted in 2018 to consent as the lawful basis for data processing. Over time they have begun to understand that consent is just one of six lawful bases, and each of them are equal. There is now a greater appreciation that consent as a lawful basis has its limits and is only appropriate in limited circumstances. The GDPR meaning of lawful basis is much better understood, and organisations are getting more sophisticated in finding the right one.
Legitimate interests has in particular come to the fore as a lawful basis. This is partly because it is the most flexible lawful basis when others cannot be applied.
People are increasingly asserting their GDPR rights, but inconsistently
Many people know about the right of access – if you asked someone “what is a subject access request” they would probably be able to answer. We have a long-standing tradition of giving patient access to medical records, for example. More rarely people exercise their rights to data deletion (the “right to be forgotten”) or data rectification. We have seen limited evidence that people are exercising their other rights, such as in relation to profiling or automated decision making.
This may be in part because people are generally not aware of these rights. The right of access – what most will know as making a subject access request – is a long standing right. It has had much more time to embed in the pubic consciousness. However, without any kind of public information.
People and organisations are also not aware of how GDPR rights apply to or can be exercised by children.
Sign Up Here:
Under the GDPR people’s data processed for anything other that purely personal activity falls within the scope of the Data Protection Act 2018. What is personal data? “Anything that by itself or in combination with other data could lead to a person being identified” is the GDPR definition. This is very broad. So, in short, who does GDPR apply to? Virtually all organisations in all sectors. However, our own analysis suggests that there is a widespread lack of awareness about the need to abide by the rules. This is particularly true of new, small businesses founded over the last three years. To explore this we looked at 5,000 limited companies started in 2021. We found that less than 8% had paid the ICO (information commissioner) fee – despite not doing so if you need to being a criminal offence. Most had no, or fundamentally inadequate, privacy notices on their websites. Overall we estimate that c. 40% of organisations are significantly or wholly non-compliant with the GDPR, In addition to comply organisations must take reasonable technical and organisational measures to ensure they meet the data privacy principles. Yes there are still basic mistakes that are easily avoided and lead to enforcement action by the ICO, such as this case involving an email sent CC instead of BCC, leading to a fine. Even less attention payed to special categories of personal data, and the particular lawful bases and protections for processing data of this type. Special category data is sensitive. It relates to health, characteristics such as race or gender, or other data needing special care. Lack of awareness is, we think, partly down to a failure to raise awareness of core tasks such as ICO registration, which most businesses need to have. The Data Protection Act 2018 replaced the 1998 Act. However even today there are still references to 1998 in documentation that we see, be it in the form of contracts, privacy statements on websites or marketing emails. For us this is a big red flag, as it shows that people are either unaware of the current legislation or haven’t made the effort to update their processes to take it into account. Our advice is if you see a reference to the 1998 Act in any documentation you should challenge it. There is a big chance the organisation you are dealing with cannot be complaint with current rules. It won’t understand lawful basis, people rights and so on. For the ICO GDPR meant a step-change in their regulatory role. Our experience is that it has placed a major burden on the ICO’s resources. The ICO is also the regulator for the Privacy and Electronic Communications Regulations, and the Freedom of Information Act. GDPR is not the only thing they oversee. There is huge amount of enforcement action that the ICO undertakes. This is not limited to GDPR fines. They provide advice and support, reach out to businesses that aren’t on the ICO register, and so on. This means that there is unlikely to be any new awareness campaigns or resources from the regulator. The ICO does an excellent job, with great resources on their website. Unless people and organisations become aware of the need to comply, or their rights they won’t do what they need to do. Overall it looks as if the journey to GDPR compliance has slowed, if not stalled. This is for a number of reasons as set out above. This is unfortunate because the risks of not abiding by data protection legislation are real. Data being used improperly, or businesses seeing a competitive advantage in bending the rules are the risks people face in a regulatory environment that is reactive rather the proactive. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.
There is still a lack of awareness among both businesses or individuals
There are still references to the Data Protection Act 1998 around

The ICO has had a huge burden to manage
GDPR at 4: Where We Are
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: