Learn
Understand your digital footprint — and what you can do about it
Calm, plain-language guides to the personal information that already exists about you online, and the rights you can exercise yourself. Written and reviewed by OSINTA's founding lawyer.
Data subject access request (DSAR): How to ask what a company holds about you
A plain-language guide to the right that lets you ask any organisation for a copy of the personal data it holds about you — and how to use it yourself.
What is a digital footprint (and what it is not)
A calm, plain-language guide to the trail of information that already exists about you online — what it is, how to look at your own without alarm, and what you can actually do about it.
How to write a DSAR (the parts that actually matter)
A practical, plain-language how-to for writing a Data Subject Access Request — what to include, a step-by-step order, and a copy-paste template you can adapt in minutes.
DSAR vs the right to erasure — what is the difference?
A plain-language guide to two different UK GDPR rights that are easy to mix up: one lets you ask to SEE the personal data an organisation holds about you, the other lets you ask it to DELETE certain data — and how to choose which one you need.
A company refused or ignored my DSAR — what now?
A calm, practical guide to your next steps when an organisation pushes back on, or goes quiet on, your Data Subject Access Request — and the regulator you can turn to.
What counts as personal data under UK GDPR?
A plain-language definition of personal data under the UK GDPR — the obvious identifiers, the surprising ones like IP addresses and cookie IDs, and why it all matters for understanding your own footprint.
Your right of access under UK GDPR, explained
The right behind every DSAR, explained as a concept: what the right of access actually gives you, what you can ask an organisation for, what you should receive in return, and the limits that apply — anchored to the ICO's guidance.
The right to erasure: When a company must delete your data
A plain-language guide to the UK GDPR right to ask an organisation to delete personal data about you — the specific grounds that trigger it, the reasons a company can lawfully say no, and how the two fit together.
The right to rectification: Fixing inaccurate data about you
When an organisation holds something wrong about you, UK GDPR gives you a direct way to ask for it to be corrected or completed. Here is how the right works and how to use it calmly.
The right to object: Stopping certain uses of your data
A calm, practical guide to the UK GDPR right that lets you ask an organisation to stop using your personal data in certain ways — most commonly for direct marketing and profiling.
How to make a complaint to the ICO
A plain-language guide to raising a concern with the Information Commissioner's Office — when to complain, the step that comes first, and what the UK's data-protection regulator can and cannot do for you.
What is the ICO? The UK's data protection regulator
A plain-language explainer of the Information Commissioner's Office — the UK's independent authority for data protection — what it does, where it gets its powers, and why it is the home regulator behind a registered UK company like OSINTA.
Who is the data controller, and why it matters to you
Before you can ask an organisation what it knows about you, you need to know who is actually answerable. The data controller is that party — and identifying it is the first quiet step in any data-rights request.
What valid consent actually looks like
Consent is one of the most misunderstood ideas in data protection. Under UK GDPR it has a precise meaning — and most of the time, it isn't even the right basis at all.
Active vs passive digital footprint: What's the difference?
A calm, plain-language guide to the two kinds of trail you leave online — the one you create on purpose and the one left behind without you choosing — and why telling them apart makes your own footprint easier to understand.
How to audit your own digital footprint, step by step
A calm, self-only walkthrough for reviewing the information that already exists about you online — searching, reading, and deciding for yourself, one step at a time. No alarm, no rush, and nothing watching on your behalf.
What shows up when you search your own name
A calm, plain-language look at why your name turns up the results it does — the ordinary sources behind them, and how to read what you find without alarm.
What is a data broker, and what do they do?
A calm, factual explainer on the companies that collect and trade personal information — what they are, where their data comes from, and the rights you already have.
How data brokers obtain your data
A calm, factual look at where the information in a data-broker profile actually comes from — public records, everyday data sharing, and the consent you may have given without noticing — so the picture feels understandable rather than alarming.
How to calmly ask a data broker to stop using your data
A plain-language, do-it-yourself guide to writing your own request to a data broker — using your UK GDPR rights to object and to erasure — calmly, in your own words, and on your own terms.
How to stop unwanted marketing emails for good
A calm, practical walkthrough of the two rights that let you switch marketing off at the source — withdrawing consent and objecting — and how to make it stick.
What is the right to be forgotten?
A calm, plain-language look at a famous phrase that is widely misunderstood — what people usually mean by it, how it maps onto the real UK GDPR right to erasure, and where the popular idea and the actual right part ways.
Reducing your footprint in search engine results
A calm, self-only guide to making your own information harder to find in search results — the practical actions you can take yourself, step by step.
What to do after you get a data breach notification
A calm, step-by-step walkthrough for the moment an organisation tells you your personal data may have been exposed — what the notice means, and how to respond under UK GDPR.
Why no one can honestly guarantee your data is removed
A plain-language look at why a credible service promises a clear process and honest effort, not a guaranteed deletion — because the decision to erase always rests with whoever holds your data, not with the tool you use to ask.
The right to data portability, in plain English
Under UK GDPR you can ask an organisation for a copy of the data you gave it, in a format you can reuse or move elsewhere. Here is what that right covers, where its edges are, and how to use it calmly.
The right to restrict processing: Pausing how your data is used
A calm, practical guide to the UK GDPR right that lets you press pause on an organisation's use of your personal data while a question about it is sorted out — without asking for deletion.
Your rights around automated decisions and profiling
A calm guide to the UK GDPR rules on profiling and decisions made about you by software alone — when you can ask for a human to be involved, and how to question an outcome that affects you.
The right to be informed: What a privacy notice owes you
The quiet right behind every privacy notice, explained as a concept: what an organisation must tell you when it collects your data, what a good privacy notice should actually contain, and where to look when it does not, anchored to the ICO's guidance.
When a company can lawfully refuse your data request
Not every "no" is a breach of your rights. A calm look at the limited, lawful grounds an organisation can rely on under the UK GDPR to refuse or limit a data request — and how to tell a legitimate refusal from one you can challenge.
How long a company has to respond to your data request
A plain-language guide to the time limits under the UK GDPR: how quickly an organisation must answer a Data Subject Access Request, when the clock starts, when it can take longer, and what you can do if a deadline passes.
Are data subject requests free? Fees and exceptions
A calm guide to the cost of exercising your data rights — why a Data Subject Access Request is normally free, the narrow cases where a reasonable fee may apply, and what that means for you.
Proving your identity when you make a data request
When you ask an organisation for your own data, it has to be sure the request really comes from you. Here is what that verification step looks like, why it exists, and how to clear it smoothly.
Making a data request on behalf of someone else
A calm, plain-language guide to exercising someone else's UK GDPR rights for them — when you are allowed to, what proof an organisation will ask for, and how to make the request clearly.
What to do when a company's response is incomplete
You asked for your data and got something back — but it feels partial. A calm guide to spotting the gaps, asking for the missing pieces, and knowing when an absence is actually allowed.
Where companies get your personal data from
A calm, plain-language map of the everyday moments that hand a company your personal data — what you give directly, what is gathered quietly as you browse, and what arrives from elsewhere — so your own footprint feels understandable rather than mysterious.
What counts as an online identifier?
The hidden tags that follow you around the web — IP addresses, cookie IDs, advertising IDs and device fingerprints — explained calmly, with why they count as your own personal data under UK GDPR.
Cookies and online tracking, calmly explained
A plain-language guide to what cookies actually are, how online tracking works, and the simple choices you already have over both — written to inform, not to alarm, so you can decide for yourself how you want to browse.
What metadata in your photos and files reveals
A calm, plain-language guide to the quiet extra information tucked inside the photos and documents you share — what it can contain, why it travels with a file, and how to look at it without alarm.
Cleaning up old online accounts you no longer use
A calm, self-only guide to finding the accounts you have stopped using and closing them down properly — the practical steps you can take yourself, at your own pace.
Tidying your social media footprint
A calm, self-only guide to reviewing your own social accounts — the posts, profiles, and settings you can quietly tidy yourself, one step at a time.
How your email address links your data together
A calm, plain-language look at why a single email address quietly ties so many of your accounts and records together — and why understanding that link makes your own digital footprint far easier to read.
Managing your footprint after a name change
A new name rarely replaces the old one everywhere at once. Here is a calm, practical way to understand where your former name still appears and to update the records that matter to you.
The digital footprint of someone who has died
When a person dies, their accounts, photos, and scattered records do not simply switch off. This is a calm guide to what remains, who can act on it, and where data-protection law does and does not reach.
What is a people-search site?
A calm explainer of the websites that gather public and purchased records into a profile of you — and what that means for your own data rights.
Data broker vs data controller: What's the difference?
Two terms that sound alike but mean very different things under UK data protection law. Understanding the gap helps you see who is responsible for your information, and who to address when you want to exercise your rights.
What 'legitimate interest' means when a company holds your data
A calm, factual explainer on one of the lawful reasons an organisation can use your personal data without first asking you — what it means, when it applies, and the rights you keep when a company relies on it.
Opting out of having your data sold or shared
Many companies sell or share personal information about you. You can ask them to stop. Here is how the opt-out works, what it does and doesn't change, and where to begin.
Why your data sometimes reappears after removal
You asked a site to take your details down, and weeks later they are back. Here is the calm, mechanical reason why that happens, and what it actually means for your next request.
How you end up on marketing lists
The everyday moments that quietly add your name to someone's marketing list, explained calmly so you understand the path your details travel.
Credit reference agencies and your data, explained
What the UK's credit reference agencies hold about you, where that information comes from, and the rights you already have to see and question it.
What is special category data, and why it gets extra protection
Some details about you are treated as more sensitive than the rest. Here is what counts as special category data under UK GDPR, why the law sets a higher bar for using it, and how that shapes your own privacy choices.
Data controller vs data processor: Who's responsible?
Two organisations can both touch your data, yet only one is answerable for your rights. Knowing which is the controller and which is the processor tells you who to ask, and who actually carries the duties under data-protection law.
The six lawful bases for using your data, explained
Under UK GDPR, an organisation needs a valid reason before it can use your personal data at all. There are exactly six, and which one applies quietly shapes the rights you can use.
UK GDPR vs EU GDPR: What actually differs
Since Brexit, the UK keeps its own version of the GDPR. The two are still close cousins, but a few practical differences shape who you ask, which regulator helps, and how your rights are framed.
Data minimisation: Why companies should hold less about you
One of the UK GDPR's quiet but powerful principles: organisations should collect and keep only the personal data they genuinely need. Here is what data minimisation means, why it protects you, and how it shapes the questions you can ask about your own footprint.
How long companies are allowed to keep your data
There is no single universal expiry date for your personal data. A plain-language look at how retention works under UK GDPR — the storage limitation principle, why periods differ, and what you can ask about your own records.
Anonymisation vs pseudonymisation: Is it still your data?
Two words that sound similar but carry very different consequences for your rights. One takes data outside the rules; the other keeps your protections fully intact.
How to read a privacy notice without the jargon
Privacy notices are long, dense, and written by lawyers — but the parts that actually affect you are short and predictable. Here is how to find them in a few minutes.
What 'privacy by design' means for you
A calm, plain-language look at the idea that privacy should be built into a product from the start — not bolted on later — and why that quiet principle quietly shapes the choices made about your data every day.
What a data breach means for you, and what you're owed
A calm, plain-language explainer: what actually happens to your information in a breach, why the law treats it seriously, and the specific things an organisation owes you when its security fails.
What data an old employer can keep about you
When you leave a job, your employer keeps some of your records on purpose and is legally allowed to. Here is what usually stays, why, and the parts you can still ask to see or correct.
Getting an old address removed from online records
You moved years ago, but an old address still follows you around search results and people-search sites. Here is a calm, step-by-step way to ask the right sources to correct or erase it.
Getting your phone number off public listings
A calm, do-it-yourself walkthrough for finding where your phone number shows up in public listings and directories — and writing your own requests to have it taken down, in your own words and on your own terms.
What to do about a photo of you online you didn't consent to
A calm, step-by-step way to think about a photo of you that's been posted or shared without your agreement — what your data-protection rights cover, and the practical routes for asking for it to come down.
Dealing with outdated information about you in search results
A calm, self-only guide for when search results show an old job, a former address, a past name, or a story that no longer reflects you — and the steps you can take yourself to set the record straight.
Requesting your data from a Big Tech platform
A calm, step-by-step way to ask a large platform — your email provider, social network or search engine — for a copy of the personal data it holds about you, using the privacy tools they already offer.
Why you get spam calls, and how to reduce them
Spam calls rarely come from nowhere. Your number has usually circulated through forms, sign-ups, and lists. Here is how that happens, and the calm, practical steps that quietly shrink the flow over time.
Checking what a mobile app collects about you
A calm, self-only walkthrough for finding out what a phone app gathers about you — using the labels, settings, and policies already on your own device. You look, you read, and you decide; nothing here watches anyone or acts on your behalf.
Protecting your child's digital footprint
A calm, step-by-step way to understand what's online about your child and to route the data-rights requests that help you tidy it up.
What happens to your data when you close an account
Closing or deleting an account is not the same as erasing your data. Here is what usually happens behind the scenes, and how to ask for more under UK GDPR if you want to.
Keeping good records of your data requests
A calm, practical guide to logging the data requests you send — what to write down, why it matters, and how a simple record helps you follow up, escalate, or simply stay on top of things under UK GDPR.
Your data rights under the EU GDPR
A calm, factual walkthrough of the rights the EU General Data Protection Regulation gives you over your own personal data, and how to use them.
Your data rights in Turkey under the KVKK
A calm, factual look at what Turkey's personal data protection law gives you, who enforces it, and how to ask an organisation to act on your information.
Your data rights in California under the CCPA/CPRA
A calm, factual walkthrough of what California's privacy law gives you — the right to know, delete, correct, and limit how businesses use your personal information — and the regulator you can turn to if a request goes wrong.
Your data rights in Canada under PIPEDA
A calm, plain-language map of what PIPEDA lets you ask private organisations to do with your personal information — and who to turn to when you need help.
Your data rights in Australia under the Privacy Act
A calm, factual look at what the Privacy Act 1988 and the Australian Privacy Principles let you ask of the organisations that hold your personal information — and where the OAIC fits in.
Your data rights in Brazil under the LGPD
A calm, plain-English walkthrough of the rights Brazil's data protection law gives you over your own personal data — and the regulator who oversees them.
Which data protection law applies to you?
A calm guide to working out which data protection law and regulator cover your personal data — based less on where you live and more on where you are when your data is collected, and who is handling it.
Finding and complaining to your local data protection regulator
Almost every country has an independent authority that oversees how organisations handle personal data. Here is how to find the right one for where you live, and how to raise a concern with it when an organisation gets something wrong.
Asking a search engine to de-list a result about you
A calm, plain-language guide to what a de-listing request really does, when a search engine may agree, and how to make one yourself — without expecting the underlying page to vanish.
When the right to erasure does not apply
Erasure is a real right, but it is not unconditional. Knowing the lawful exceptions helps you read a refusal calmly and decide what to do next.
De-listing vs deletion: Why the page can still exist
A calm, plain-language look at two actions people often blur together — having a search result hidden under your name, and having the underlying data deleted. Knowing the difference tells you which request to make, and what each one can realistically change.
Erasure and backups: Is your data really deleted?
When an organisation agrees to erase your personal data, copies in its backups often do not vanish on the same day. Here is what "deleted" really means under the UK GDPR, why backups are treated differently, and what you can reasonably expect.
Self-service vs 'done-for-you' data removal: What's the difference?
A calm look at the two ways people approach their data-rights requests — one where you send and track your own, one where a service sends them for you — and what each model means for control, visibility, and trust.
How to spot privacy scare tactics and fear-selling
A calm guide to recognising the alarm-first language some privacy services use — the countdown clocks, scary totals, and "act now" prompts — so you can tell honest help from a sales push and make a steady, unhurried decision.
Staying in control of your own data decisions
Tools can lay out your options clearly. But the choice of what to act on, what to leave, and when to send a request always stays with you.
What to verify before trusting a privacy service
A calm, practical checklist for deciding whether a service that touches your personal data deserves your confidence — who is behind it, what it actually claims, and whether it leaves the decisions with you.