Skip to main content

Companies are failing their customers on data rights

We sent the same legal data request to 15 companies. None answered it in full, and the right to be told about automated decisions was answered worst of all.

Background

Everyone in the UK has the right to ask a company for a copy of the personal data it holds about them, and to be told how that data is used. It is among the oldest rights in data protection law, and among the easiest to use. A single email is enough, and the company has 1 month to reply.

The right of access is set out in Article 15 of the UK GDPR. It gives a person two things: a copy of their personal data, and specific information about how the company uses it. That information covers:

  • the purposes the data is used for
  • the categories of data held
  • who the data is shared with
  • how long it is kept
  • where it came from, if not from the person
  • the person's rights to correct, delete, restrict or object
  • the right to complain to the Information Commissioner
  • whether the company makes solely automated decisions about someone, and the logic behind them

A company that answers the request in full provides a copy of the data and addresses each of these points.

That last point has become the most contested. Article 15(1)(h) covers a solely automated decision that carries a legal or similarly significant effect, along with the profiling behind it. In 2025 the Data (Use and Access) Act rewrote the law on automated decisions, replacing Article 22 of the UK GDPR with new Articles 22A to 22D that came into force in 2026. The change loosened the protection. A solely automated decision was restricted by default before. Now it is permitted more widely, subject to safeguards.

The same Act added a right for the person to complain to the company itself, alongside the long-standing right to complain to the Information Commissioner. A company answering an access request today should point the person to both.

These changes arrived while oversight of the regulator was itself in flux. The Information Commissioner had been sponsored by the Department for Science, Innovation and Technology. In July 2026, following machinery-of-government changes, that sponsorship moved to the Department for Digital, Culture, Media and Sport.

So the automated-decision right was weakened just as responsibility for the regulator changed hands. We wanted to know whether that right, and the wider right of access it sits inside, still works when a person actually uses it. This report is what we found when we tested it.

Key facts and findings

In July 2026 we sent the same subject access request to 15 companies, then scored each reply against the 10 things the law says a company must provide. We found:

  • None of the 15 companies answered the request in full.
  • 2 gave no substantive answer at all.
  • The automated-decision question was answered worst of the 10. Only 2 companies gave a clear account of the automated decisions they make.
  • Companies hold far more profiling than the law makes them disclose. In 4 cases the company shipped audience or segment profiling that its response did not describe.
  • The new right to complain to the company itself was the one most often missing altogether. 10 of the 15 left it out, and only 3 gave it in full.
  • Only 2 companies named the specific organisations they share data with. The rest gave broad categories, or nothing, though the request had asked for names.
  • 10 of the 15 provided a copy of the data.
  • Only 1 company stated the legal deadline without being asked.

What we did

On 22 July 2026 we sent the same subject access request to 15 companies. The wording was identical each time. It asked for everything the law says a company must provide: a copy of the person's data, the supplementary information set out in Article 15, and specific answers on automated decisions and profiling.

We chose the 15 to span the sectors where automated decisions and profiling matter most to consumers:

  • buy-now-pay-later lenders
  • the credit reference agencies
  • a credit app
  • a mobile network
  • streaming services
  • retailers and loyalty schemes
  • search and social media platforms
  • an artificial intelligence provider

We sent each request by the route the company offered - an email address where the company published one, or a web form or portal where it did not. Every request was made in the requester's own name. We scored every reply against the 10 requirements, marking each as answered in full, in part, or not at all.

Where a company sent a data package, we read the data as well as the covering letter. In several cases the data held profiling that the covering letter did not describe.

How each company scored

We scored all 15 companies the same way, requirement by requirement. 2 things stand out. Some requirements were met far more often than others. And no company answered them all.

Each result is one of:

  • In full: answered in the reply or the data
  • In part: answered only by pointing to a policy, or answered partly
  • Not answered: missing from both the reply and the data

For each requirement, this is how many of the 15 companies answered it in full, in part, or not at all:

Requirement

In full

In part

Not answered

Purposes

5

7

3

Data categories

5

8

2

Recipients

2

8

5

Retention

3

8

4

Rights

2

10

3

Complain to the company

3

2

10

Complain to the ICO

5

3

7

Data sources

5

5

5

Automated decisions

2

8

5

Copy of the data

10

3

2

Company by company

Klarna

Substantive reply that answered point by point, much of it by reference to its Privacy Notice. Admits Article 22 automated decisions and offers the logic on request, the most forthcoming answer on automated decisions in the study. But it used the person's accidental self-serve download to gate the request to 1 per 30 days.

Purposes

In part

Data categories

In part

Recipients

In full

Retention

In part

Rights

In part

Complain to the company

Not answered

Complain to the ICO

In part

Data sources

In part

Automated decisions

In full

Copy of the data

In full

Getting to the request

Before a person can make a subject access request, they have to work out how. That first step alone separated the companies.

For most, finding the route was quick. It took 14 seconds at Netflix, one link from the home page, and stayed under a minute for 11 of the 15. At the slow end, 4 companies ran past 90 seconds, and one of them, Credit Karma, sent the requester through a United States help centre before offering anything for the UK.

Then came the question of who to send it to. Most companies published a data-protection email. Meta and Google published none. Meta offered a form with fixed categories and no field for the request itself, so the request had to go through a second channel. Google gave no contact and no named data-protection officer, only a web form capped at 750 characters. Both are among the 4 companies that never gave a substantive answer. Meta went on to refuse the request outright, and Google sent only links. The barrier at the front door already pointed to the result behind it.

Where a form or a portal was the only way in, it shaped the request before anyone read it. Google's character cap left no room to set the request out in full. OpenAI pushed rights requests through a privacy portal and its in-account controls first, and Equifax opened a help-portal account the requester had never asked for.

Some companies answered a different question than the one asked. Klarna, Spotify, Netflix, Google, OpenAI and Equifax each offered a self-serve data download, or a shorter report, in place of the statutory request. A data download is not the Article 15 answer. It hands over a copy of the data and leaves the questions about how that data is used untouched.

Even a request addressed to a data-protection team did not always reach one. At Klarna, Experian, Credit Karma, Clearpay and Spotify it went to general customer support first, a detour before anyone who handles rights requests saw it.

None of this was the request itself. It was the friction in front of it, before the clock even started. And it had already done some of the sorting: the companies that made the route hardest to find were, more often than not, the ones that went on to answer least.

Starting the clock

The law gives a company 1 month to answer. The clock starts when the request arrives, or, where the company needs to check who the person is, when that check is done. That second option is a lever: ask for something more before the clock starts, and the month does not begin.

Most companies reached for it, and some asked for identity they already had. Experian wanted a customer number the request had given twice. Meta asked for proof of identity after the requester had used Meta's own logged-in form, the registered email on the account and a phone bill. Clearpay asked for 5 identity details, 4 of them already in the request.

TransUnion and Equifax had a fairer claim to ask. Neither holds a login for the person, so a name and address is most of what they have to match against. But TransUnion attached a threat with no basis in law: send the documents within 14 days, or the case is closed. Article 12(6) lets a company pause until identity is confirmed. It does not let the company close the request. Equifax rejected a proof of address because the requester had hidden the financial detail on it, detail that has nothing to do with proving where a person lives.

Other gates were simply invented. Amazon would not start until the requester had "confirmed" the request, a step the law does not call for. Google capped its form at 750 characters and gave no way to reply to the acknowledgement.

Then there was the deadline itself, and only one company stated it. Three named a date, 21 August 2026, cited the deadline correctly, and set out the further 2 months it could claim if the request proved complex. Sainsbury's at least named the month. Experian offered a "7-day service aim" in its place, which is not the legal deadline and does not replace it. Everyone else left the date unstated, and several never confirmed it even when the requester asked outright.

None of the delay was the requester's. Every reply to every request for information went back the same day. The clock was the company's to start, and most started it late.

What came back, and what didn’t

What arrived ranged from nothing at all to a printed bundle of more than 100 pages. But a thick response was not always an answer, and 2 companies sent no answer at all.

The clearest failures were the flat refusals. Meta turned the request down, then turned it down again when the requester challenged it. The reason it gave was that it could not confirm their identity, after they had proved it 3 ways. Credit Karma went further. It told the requester, 3 times, that it could find no account for them, using the very email the account is registered under, an account they logged into the same day. A company can refuse a request. Telling the person they do not exist, when they plainly do, closes it on a fiction.

Clearpay failed in a quieter way. The request reached no privacy team at all. It was handled first as an identity check, then as a technical fault, then as a complaint, and logged on an 8-week clock meant for financial disputes. When the requester objected, the reply bounced back from a mailbox that does not accept replies. Nothing was refused. There was simply no route to the right people.

Among the companies that did respond, the most common failure was a reply that looked complete and answered almost nothing. Netflix returned a sheet that listed every requirement and, against each, a link to a heading in its privacy policy, and nothing more. Klarna and Spotify did the same for most of the supplementary points. Google sent no data at all, just links to its self-service tools and its policy. Clearpay took it furthest, answering every requirement with the single line ‘please see our privacy notice’, and closing a data-rights request as a complaint with a referral to the Financial Ombudsman. This is the failure that survives a compliance check: it names every right and hands back the public policy the person could have read before asking.

At the other extreme, Amazon sent 5,579 files and 477 megabytes, and answered none of the supplementary requirements in writing. Volume is not the same as an answer. Half a gigabyte of data still left every question about how that data is used untouched.

A response, in other words, can look like compliance and carry very little. The most revealing gap of all was on automated decisions.

A narrow right, poorly answered

The law says a company must tell a person about the automated decisions it makes about them, the ones taken by the system alone that carry a legal or similarly significant effect, and explain the logic behind them. This is the newest of the requirements, and the most contested. It was also answered worst. Only 2 of the 15 companies gave a clear account of the automated decisions they make.

Most of the profiling a person is subject to sits outside that duty. Amazon's data held a file of 9 advertising segments it had sorted the account into. Spotify builds inference-based ad segments, Netflix keeps files of inferred interests, and Clearpay sorts customers by generation, age band and a customer tier. None of that is the automated decision the law reaches, so a company can hold all of it and still owe no account of it under this right. The profiling people generate is extensive. The slice of it the law makes visible is small.

Two companies simply answered. Klarna said plainly that it makes automated decisions under Article 22, named the processes, and offered to explain the logic behind any one of them on request. Sainsbury’s sent the profile itself: a "Customer Insight" sheet with marketing and household segments and a customer value score. Neither is the norm.

The 3 credit reference agencies share a script. Experian, Equifax and TransUnion each calculate a credit score automatically, and each says the decision that matters, whether to lend, belongs to the lender, not to them. Only TransUnion states what goes into the score. The others send the reader to a shared industry notice for the logic. It is a tidy division of labour: the agency runs the automated part, the lender owns the decision, and the person is left with a full account of neither.

The sharpest case is the company that did everything else right. Three gave the most complete response in the study on every other measure, and still said nothing about automated decisions, though its own privacy notice describes an automated credit check when a person takes out a monthly contract. The question is not part of the routine, even for the company that runs the routine best.

The one artificial intelligence company in the sample did no better. OpenAI gave one of the fuller written answers elsewhere, but on automated decisions it pointed to a policy that names no such decision, and said nothing about the account itself. Being an AI company did not make the AI question easier to answer.

The pattern holds across the sample. The answer a company gives on automated decisions is thin, and often thinner than the truth. This is the right the Data (Use and Access) Act loosened in February 2026, and the evidence here is that it was already the hardest of all to exercise.

Why this matters now

The right of access is the one tool a person has to see what a company does with their data. It is how someone would learn that a decision about them had been made by a machine, or that they had been sorted into a profile. We tested that tool across 15 companies, and it returned least on the very things it exists to expose.

The timing matters. The protection against solely automated decisions was the strongest right in this area, and the Data (Use and Access) Act 2025 loosened it. Until 2026 a decision taken by the system alone, with a legal or similarly significant effect, was restricted by default. Now it is allowed more widely, subject to safeguards. The law made room for more automated decision-making just as our study found that the right to be told about those decisions was answered worst of the 10.

Oversight changed hands at the same time. The Information Commissioner is the body a person turns to when a company ignores an access request. In July 2026 responsibility for the regulator moved from one government department to another, part of a wider reshaping of the centre of government. A right is only as good as the body that stands behind it, and that body was mid-transition as these requests went out.

The two shifts point the same way. More decisions about money, housing and work are being handed to automated systems, and the law now gives those systems more room. The check on that is meant to be transparency, a person's ability to ask what is decided about them and how. The evidence here is that the check is weak. Most of the companies most likely to run automated decisions, the lenders and the credit reference agencies, gave only a partial answer on automated decisions or none at all.

That is why this matters now. The right was already the hardest to exercise before the law made automated decisions easier to take. A protection that is weak on paper and weaker in practice will not hold the coming decade of automated decisions to account.

What needs to change

The failures in this study were not a one-off. They were routine, and they cluster where the law is weakest and newest. Five changes would make the right of access work as it is meant to:

  • Enforce the access right against the failures this study found, so a flat refusal, a false 'no account found', or a request that never reaches a privacy team carries a real consequence for the company.
  • Make clear that a self-serve data download does not answer an access request, so a company cannot hand over a copy of the data and leave every question about how it is used untouched.
  • Put both complaint routes in every access response, the company and the Information Commissioner, so the new right to complain to the company does not go unmentioned in the replies that should carry it.
  • Stop identity checks and extra confirmation steps being used to stop the clock, so the month to reply begins when the request arrives, not when the company decides.
  • Restore the transparency the Data (Use and Access) Act removed from automated decisions, so a person can still be told when a decision about them is made by a machine, and on what logic.

Conclusion

The right of access is the oldest and the simplest of the data rights. A person sends a single request, and the law gives the company a month to answer. We sent that request to 15 companies. Not one answered it in full.

The gaps were not random. The right failed most on the newest and least-settled duties, the account of automated decisions and the new route to complain to the company itself. These are the protections a person most needs as more decisions are handed to machines. They are the ones the replies served worst.

Most of this needs no new law. Enforced, the existing right would carry most of the weight. A refusal or a false 'no account' would meet a consequence. A self-serve download would stop counting as an answer. Both complaint routes would appear in every reply, and identity checks would no longer stall the clock. The exception is automated decisions. There, the transparency the Data (Use and Access) Act removed has to be put back, so a person can still learn when a machine decides something about them.

A right that many people never use still tells us something when it is tested. These companies made the simplest data request hard, and made the newest and most important parts of it hardest of all. The law already gives people this right. What they do not yet have is a company that reliably answers it.


Notes to editors

The sample

We sent the request to 15 companies, chosen to span the sectors where automated decisions and profiling matter most to consumers:

  • buy-now-pay-later lenders: Klarna and Clearpay
  • a credit app: Credit Karma
  • credit reference agencies: Experian, Equifax and TransUnion
  • a mobile network: Three
  • streaming services: Spotify and Netflix
  • search and social media platforms: Google and Meta
  • retailers and loyalty schemes: Amazon, Tesco and Sainsbury's
  • an artificial intelligence provider: OpenAI

The request

On 22 July 2026 we sent the same subject access request to all 15 companies, in the requester's own name. It asked for a copy of the person's data and for the supplementary information set out in Article 15 of the UK GDPR, with specific questions on automated decisions and profiling. The wording was identical each time.

The deadline and the window

The law gives a company 1 month to answer an access request, starting when the request arrives or, where the company needs to confirm who the person is, when that check is done. We recorded each reply against that deadline. Responses are tracked to 24 August 2026. Two companies, Clearpay and Google, replied only after the month had passed.

The scoring

We scored every reply against the 10 things the law says a company must provide:

  • the purposes it uses the data for
  • the categories of data held
  • the recipients it is shared with
  • how long it is kept
  • the person's rights
  • the route to complain to the company
  • the route to complain to the Information Commissioner
  • the sources of the data
  • the account of automated decisions
  • a copy of the data itself

Each was marked in full, in part, or not answered. Where a company sent a data package, we read the data as well as the covering letter, and scored a requirement as answered where either the reply or the data answered it.

Right of reply

On publication we invited each named company to respond to the findings about it. Replies we received are included in the report.

About us

The Centre for Digital Consumers is a non-profit that researches and defends the rights of consumers in the digital economy.

Media contact

For interviews or the underlying data, contact us.

Back to research

Report a problem with this page