Data protection (myth?)
Guessed, sold, and quietly unenforceable
In March 2026 a company emailed me at an address I had never given to anyone. Because I run a catch-all domain, I could prove it was unique — so I asked where they got it.
March 2026 — unsolicited email arrives; I ask how they obtained the address
April 2026 — traced back through four companies, each pointing to the next
May 2026 — the original source admits the address was never obtained at all. It was inferred from company size and sector, then added to a database I'd only be removed from if I objected to a notice they couldn't prove they'd sent
June 2026 — a second broker names around 30 organisations my details were sold to, and confirms it assesses "legitimate interest" across whole datasets, never individuals
July 2026 — questions about transfers outside the UK deflected to a generic policy page
August 2026 — two complaints filed with the regulator
Claude was invaluable throughout: explaining which parts of UK GDPR actually applied, drafting the access requests, reading the disclosure pack, and — most usefully — telling me where I was overreaching and should drop a weaker argument.
This has taken over four hours (so far…) of unpaid time across nearly five months. The regulator can't award compensation, rarely fines on a single complaint, and is currently allocating cases within 40 weeks.
The rules exist. Enforcing them is unpaid work — and most people will never know they were listed.