What the Data Brokers Know About You: A UK Director Investigation

Case Study

What the Data Brokers Know About You: A UK Director Investigation

This week the podcast asked what attackers can learn about UK SMB directors from public sources. I want to ask a related but distinct question: what does the documented record tell us about what commercial data brokers actually hold, on what legal basis, and what the regulator has done about it?

This is not speculation. This is the ICO’s own findings, the tribunal record, and the published enforcement history. The picture is not flattering to the industry or to the regulatory response.

The ICO’s 2020 Investigation

In October 2020, the ICO published the results of a two-year investigation into data protection compliance in the direct marketing data broking sector. The investigation focused on three credit reference agencies that also operate as data brokers: Experian, Equifax, and TransUnion.

The ICO’s findings were unambiguous. Between the three agencies, the data of almost every adult in the UK was, in some way, being screened, traded, profiled, enriched, or enhanced to provide direct marketing services. The ICO described “widespread and systemic data protection failings across the sector” and “significant data protection failures at each company.”

The processing, the ICO found, took place largely without the knowledge of the individuals concerned. Consent claimed by some parties in the data supply chain was often found to be invalid. The agencies were using personal data to create aggregated profiling models applied at postcode level, generating new or previously unknown inferences about people from combined datasets.

For a typical UK adult, including a small business director, the documented profile categories include: name, address, age band, household composition, financial indicators, property information, directorship data, employment signals, interest segments, and marketing classifications. This is not a thin dataset. It is a structured commercial product built from multiple sources without the active participation of the people it describes.

What Sources Feed the Profile

The sources documented in the ICO investigation and subsequent tribunal proceedings include: the open electoral register, credit reference data, public registers including Companies House, marketing lists, commercial partnerships, survey data, and purchase behaviour datasets.

For a director, the combination is particularly pointed. Companies House provides business identity and structure. The open electoral register provides residential address correlation. Credit reference data provides financial profile indicators. Marketing lists and commercial partnerships add interest and lifestyle segments.

None of these sources required the director to consent to their data being processed in this way. The legal basis relied upon was, in most cases, legitimate interests. The question of whether those interests were properly balanced against individual rights was precisely what the ICO enforcement action sought to test.

The Experian Appeal and Its Consequences

The ICO issued an enforcement notice against Experian in October 2020. Equifax and TransUnion withdrew non-compliant services and avoided further formal action. Experian challenged the enforcement notice.

On 20 February 2023, the First-tier Tribunal ruled substantially in Experian’s favour, rejecting the ICO’s position on transparency, fairness, and lawful basis for most of the challenged processing. On 23 April 2024, the Upper Tribunal dismissed the ICO’s appeal on all five grounds in Information Commissioner v Experian Ltd [2024] UKUT 105 (AAC). In May 2024, the ICO confirmed it would not pursue a further appeal to the Court of Appeal.

The consequence is significant. The most substantial enforcement action the ICO has taken against a UK data broker did not result in a finding that the processing was unlawful at the scale the ICO alleged. It did not result in a monetary penalty. And it did not establish clear precedent requiring the industry to fundamentally change its practices.

The market drew its conclusions.

The Comparative Enforcement Gap

The ICO has not imposed a monetary penalty on a UK data broker as of the date of this investigation. In the same period, EU data protection authorities have taken a different approach. France’s CNIL fined Criteo €40 million in 2023. The Dutch Authority for Personal Data fined Clearview AI €30.5 million in 2024, with a daily non-compliance penalty of €5.1 million. Spain’s AEPD fined Informa D&B €1.8 million in 2025.

The enforcement posture matters because it shapes industry behaviour. An industry that has watched the most significant UK enforcement action result in a tribunal ruling in its favour, followed by an ICO decision not to appeal further, has received a clear signal about regulatory appetite.

The ICO has since been restructured as the Information Commission under the Data (Use and Access) Act 2025. It has enhanced investigatory and enforcement powers. Whether those powers will be applied differently to the data broker sector is an open question that only enforcement action will answer.

What Directors Are Entitled to Know

Under UK GDPR, any individual has the right to submit a subject access request to any data controller, including a data broker. The controller must respond within one month, providing details of what personal data is held, the purpose of processing, the legal basis, the sources from which the data was obtained, who has received it, and how long it is retained.

The right to erasure under Article 17 applies where, among other grounds, the individual objects to processing based on legitimate interests and the controller cannot demonstrate compelling legitimate grounds that override those interests, or where the data is no longer necessary for the purpose for which it was collected.

In practice, exercising these rights against data brokers requires knowing which brokers hold data, submitting individual requests to each, and repeating the process when data reappears from refreshed upstream sources. The individual remedy is real. It is also labour-intensive and fragmented.

The Questions That Remain

Several questions the documented record does not yet answer with precision.

How many UK data broker audits has the ICO completed since 2018? The published enforcement record does not provide a clear count.

How many erasure requests submitted to UK data brokers are complied with fully, partially, or refused? No aggregated public data exists on this.

How frequently does data reappear in broker databases following a confirmed erasure, and from which specific upstream sources? This is anecdotally well-documented but not systematically measured.

These are not hostile questions. They are the questions that would allow individuals, advisers, and policymakers to assess whether the individual remedy framework is functioning as intended. The fact that they cannot be answered from publicly available data is itself a transparency problem.

What to Do With This Information

The documented position, for a UK SMB director, is this.

Commercial data brokers hold structured profiles that combine business register data, electoral address data, financial indicators, and marketing segments. This processing has been found to lack adequate transparency in some significant cases. The regulatory response, while genuine, has not resulted in a changed market.

Individual rights exist and are worth exercising. Subject access requests and erasure requests are the available personal remedies. They should be submitted to the brokers that demonstrably hold your data, tracked carefully, and repeated as required.

The systemic remedy requires regulatory action at scale. That has not yet materialised in the UK to the degree that would change market behaviour.

How to Turn This Into a Competitive Advantage

For MSPs and advisers, the documented enforcement record is a client conversation tool. Understanding the Experian tribunal outcome, the ICO’s post-2024 posture, and the DUAA’s changes to the regulatory landscape is specialised knowledge most advisers do not have. Being able to brief a client on what brokers hold, what rights they have, and what the realistic enforcement environment looks like is a differentiated service.

For business owners, demonstrating awareness of the data broker ecosystem and active management of your director exposure profile signals security governance maturity that goes beyond technical controls. It belongs in supplier questionnaires, due diligence responses, and client-facing security documentation.

How to Sell This to Your Board

The documented ICO finding is the starting point: between Experian, Equifax, and TransUnion, the data of almost every adult in the UK was being processed for marketing purposes without their knowledge. That includes your directors. That is not a theoretical risk assessment. That is a regulatory finding.

The Experian tribunal outcome tells the board that regulatory intervention has not changed the market. Individual action is what is available now. Assigning ownership of that action to a named person, with a review date, is basic governance.

The Data (Use and Access) Act 2025 introduced new mandatory complaints handling requirements from 19 June 2026. Your organisation needs to comply. That is a concrete deadline for a governance action.

What to Do This Week

  1. Search your name and company on the major UK people-search sites. Note which platforms hold your data prominently.
  2. Submit a subject access request to the top three results using the ICO template letter.
  3. Review the ICO’s published guidance on the data broking sector and confirm your understanding of the erasure rights available to you.
  4. Set a calendar reminder to follow up on each SAR at the 28-day mark, giving three days before the legal deadline.
  5. If any broker fails to respond within 30 days, report to the ICO and document the complaint reference number.
SourceArticle
ICOGuidance for the data broking sector
Privacy InternationalUK regulator takes enforcement action against data brokers
Privacy InternationalQ&A on UK regulator’s action on data brokers
ICORight to erasure guidance
ICOYour right to get your data deleted
GOV.UKData Protection Act 2018
GOV.UKCyber Security Breaches Survey 2025/2026

Filed under

  • smb-security
  • uk-business
  • data-protection
  • compliance-failure
  • executive-security
  • business-risk
  • public-sector-security