Sets the core principles, individual rights and accountability duties for most general personal-data processing.
Core regime Read the UK GDPRSupport UK data protection compliance when personal data moves.
My MX Data gives UK organisations a controlled route for exchanging files that contain personal information. Named-user access, configurable conditions and detailed activity records can support appropriate technical and organisational measures, while legal responsibility remains with the organisation.
Supplements the UK GDPR and contains additional provisions, exemptions and separate regimes for law-enforcement and intelligence processing.
Primary UK Act Read the ActAmends the UK GDPR and Data Protection Act 2018. Its data-protection changes are now in force, including the organisational complaints duty.
Current amendments Read the amendmentsWhere data-protection control weakens
Policies do not protect personal data unless daily sharing follows them.
Risk often appears when personal information leaves a system of record and moves through email attachments, public links or loosely controlled folders.
The recipient becomes unclear
Open links and forwarded attachments can move beyond the person who was meant to receive the information.
The purpose becomes detached
A file can remain available after the task, request or relationship that justified the exchange has ended.
The evidence becomes fragmented
Privacy and security teams may have to reconstruct events from inboxes, screenshots and separate spreadsheets.
The seven UK GDPR principles
Use controlled file exchange to support the principles in practice.
My MX Data does not decide whether processing is lawful or which purpose, retention period or disclosure is appropriate. It can support selected controls once personal information must be exchanged.
Lawfulness, fairness and transparency
Keep the sender, recipient and exchange context visible. The organisation must still identify a lawful basis and provide appropriate privacy information.
Purpose limitation
Create access around a defined exchange and review whether continued availability remains compatible with the original purpose.
Data minimisation
Share the files needed for the task instead of exposing broad folders or unnecessary datasets.
Accuracy
Use version visibility to reduce confusion over copied attachments. The organisation remains responsible for checking whether personal data is accurate and up to date.
Storage limitation
Use expiry and review controls to support retention decisions, without treating platform settings as a substitute for a documented retention policy.
Integrity and confidentiality
Use named access, AES-256 encryption and the quantum secure patented ASR methodology to add protection to sensitive exchanges.
Accountability
Keep detailed activity records that can help demonstrate which controls were applied, while recognising that records alone do not prove compliance.
A controlled personal-data exchange
Keep purpose, access and evidence connected through the handoff.
Personal information should not become ungoverned when it leaves a business system. My MX Data provides a controlled exchange route between known users.
Define the purpose
Record why the information needs to move, who owns the request and which recipient is authorised to act.
Limit the information
Select the relevant file or dataset instead of opening an entire folder or circulating a broader record set.
Apply access conditions
Tie access to the named recipient and use expiry, password or download conditions appropriate to the risk.
Record the exchange
Keep delivery and recipient activity connected to the file so the organisation has a clearer factual record.
Review continued need
Consider whether access and retention remain justified when the task, request or relationship changes.
Support for individual-rights workflows
Coordinate a rights response without treating the platform as the decision-maker.
My MX Data can provide a controlled route for identity evidence, internal collection and secure disclosure. It does not determine the scope of a request, apply exemptions or guarantee that every relevant record has been found.
Receive and assign
Record the request, date and responsible owner within the organisation's rights-handling process.
Verify proportionately
Where identity evidence is necessary, exchange it through a controlled route rather than ordinary email.
Coordinate the search
Share relevant material with authorised teams while the organisation conducts reasonable and proportionate searches.
Review and disclose
Apply legal review, redaction and exemption decisions before releasing the approved response securely.
Incident and complaint readiness
Respond from a reliable record, not assumptions.
When a disclosure is questioned or an incident is suspected, teams need to establish which file moved, who had access, which controls applied and what risk the event creates for people.
Certain personal-data breaches must be reported to the ICO without undue delay and, where feasible, within 72 hours of awareness. From 19 June 2026, organisations must also provide a clear complaints route, acknowledge data-protection complaints within 30 days and respond without undue delay. See the ICO breach guidance and complaints guidance.
Practical outcomes
Strengthen the file-exchange controls behind your wider programme.
My MX Data supports selected controls and evidence around personal-data exchange. It complements, rather than replaces, governance, legal review, records management and staff training.
A clearer chain of accountability
Connect each sensitive exchange to its sender, purpose, recipient, conditions and resulting activity.
Fewer uncontrolled copies
Use a defined exchange route instead of repeated attachments and anonymous public links.
Explore encrypted file sharingStronger access discipline
Give information to named users under conditions that can be reviewed or withdrawn.
Explore corporate file sharingEvidence that remains usable
Keep file activity close to the exchange so privacy, security, legal and audit teams can work from the same facts.
Explore platform featuresEssential reads
Practical guidance for handling personal data with more control.
Explore focused guidance on recognising sensitive files, responding to subject access requests and keeping a credible record of file activity.
What Makes a File 'Sensitive'? A Practical Guide
A harmless-looking spreadsheet can become sensitive once names, pricing or project details appear. Learn how to classify risk before a file leaves your organisation.
Read the guideHow to Handle Subject Access Requests Without Losing Control
See how to locate the right data, protect third parties and preserve evidence of what was reviewed and shared during a subject access request.
Read the guideBuilding a File Audit Trail: Why It's Crucial for Modern Compliance
A credible audit trail should show who accessed a file, what happened next and which details remain available when a review or investigation begins.
Read the guideUK data protection, explained
Clear answers for privacy, legal and security teams.
My MX Data supports selected data-handling controls. Your organisation remains responsible for its lawful basis, transparency, rights decisions, retention, incident assessment and wider compliance programme.
The Data Protection Act 2018 is a central part of the UK data-protection framework. It supplements the UK GDPR, provides additional rules and exemptions, and contains separate regimes for areas including law-enforcement and intelligence processing. The current text is available on legislation.gov.uk.
No. They work together. The UK GDPR contains the main principles, rights and obligations for most general processing. The Data Protection Act 2018 supplements that regime and addresses additional matters, exemptions and specialised processing.
The Act amended the UK GDPR, Data Protection Act 2018 and related legislation. Its data-protection provisions are now in force. Changes include clarification that organisations make reasonable and proportionate searches for subject access requests and a statutory complaints-handling duty. Review the ICO's DUAA summary.
No single product can guarantee compliance with the Data Protection Act 2018 or UK GDPR. My MX Data can support technical and organisational measures around named access, protected exchange and activity records. Compliance also depends on lawful purpose, governance, contracts, retention, transparency and staff behaviour.
No. The UK GDPR does not require every item of personal data to be encrypted in all circumstances, but encryption is identified as an example of an appropriate technical measure. Organisations must assess what is appropriate to the risk. See the ICO encryption guidance.
It can support controlled collection, review and disclosure of files connected to a request. It does not automatically identify every relevant record, decide whether an exemption applies or calculate the legal response. Those decisions remain with the organisation.
A breach must be reported when it is likely to result in a risk to people's rights and freedoms. Notification must be made without undue delay and, where feasible, within 72 hours of awareness. Not every incident is reportable, but every incident should be assessed and documented appropriately.
Since 19 June 2026, organisations must provide a clear way for people to complain about how their personal information is used, acknowledge the complaint within 30 days, investigate appropriately, keep the complainant informed and communicate the outcome without undue delay.
Put controlled sharing into practice
Give personal data a clearer route through your organisation.
See how My MX Data can support named access, protected exchange and more usable activity records within your wider UK data-protection programme.