Skip to content
We Sort.

Data protection (myth?)

Guessed, sold, and quietly unenforceable

In March 2026 a company emailed me at an address I had never given to anyone. Because I run a catch-all domain, I could prove it was unique — so I asked where they got it.

  • March 2026 — unsolicited email arrives; I ask how they obtained the address

  • April 2026 — traced back through four companies, each pointing to the next

  • May 2026 — the original source admits the address was never obtained at all. It was inferred from company size and sector, then added to a database I'd only be removed from if I objected to a notice they couldn't prove they'd sent

  • June 2026 — a second broker names around 30 organisations my details were sold to, and confirms it assesses "legitimate interest" across whole datasets, never individuals

  • July 2026 — questions about transfers outside the UK deflected to a generic policy page

  • August 2026 — two complaints filed with the regulator

Claude was invaluable throughout: explaining which parts of UK GDPR actually applied, drafting the access requests, reading the disclosure pack, and — most usefully — telling me where I was overreaching and should drop a weaker argument.

This has taken over four hours (so far…) of unpaid time across nearly five months. The regulator can't award compensation, rarely fines on a single complaint, and is currently allocating cases within 40 weeks.

The rules exist. Enforcing them is unpaid work — and most people will never know they were listed.

cb-2x2-01
s-2x2-01
ht-2x2-01
cb-2x2-01