Personal data must be accurate and, where necessary, kept up to date; accuracy is about the data, not whether you agree with every opinion.
Article 5(1)(d) requires personal data to be accurate and, where necessary, kept up to date, with reasonable steps taken to erase or rectify inaccurate data without delay. The purpose for which the data is used matters when deciding what level of accuracy is required.
Accuracy disputes can be especially serious where data drives debt collection, credit reporting, eligibility, fraud markers, account restrictions or automated decisions.
Key points
- Source and status of information should be clear.
- A controller should carefully consider accuracy challenges.
- Historical records can remain accurate if they accurately record what was said or believed at the time.
- An inaccurate factual field should not be preserved merely because it came from a legacy system.
Fact, allegation and opinion
“Customer paid on 4 May” is a fact capable of verification. “Customer was rude” may be an opinion. “A complaint alleged fraud” can be an accurate historical record of the allegation even if the allegation was false, provided the record does not misleadingly present it as established fact.
Purpose changes the stakes
A minor spelling error may be harmless in one database but serious if it causes records to be matched to the wrong person. Credit-reporting data requires particularly careful accuracy because third parties use it to make decisions.
Source disputes
If the controller obtained data from another organisation, it should record/source it appropriately and investigate a credible challenge. “That is what our supplier sent us” does not automatically discharge the controller’s own accuracy obligations.
In practice
- Identify the field, the correct value and the consequence of the error.
- Request rectification and restriction where appropriate.
- Ask who received the inaccurate data.
What to do
A practical next-step plan
- Capture the incorrect data.
- Gather authoritative evidence.
- Submit a rectification request.
- Request restriction if ongoing use risks harm.
- Check downstream corrections.
Common traps
Things that often confuse the issue
- Disagreement is not always inaccuracy.
- An accurate record of a past error can be retained if needed, provided its status is clear.
- Do not accept “system-generated” as an answer to an accuracy challenge.
Evidence worth keeping
A refusal should contain reasoning, not simply “our records are correct”.
If the controller rejects rectification, ask what evidence it checked and why that evidence outweighs yours. ICO guidance also treats it as good practice to mark the record as disputed where the controller remains satisfied it is accurate. Where corrected data was disclosed to recipients, the controller generally has obligations to communicate the rectification unless doing so is impossible or involves disproportionate effort.
Useful wording.
“Please treat this as a request for rectification. The inaccurate statement is [x]; the correct position is [y]; my supporting evidence is [z]. Please restrict use of the disputed data while you verify it and explain the evidence relied upon if you refuse correction.”
Restriction can protect you while accuracy is being checked.
Where you contest accuracy, the right to restriction may apply while the controller verifies the data. Restriction generally means the organisation can store the information but should not continue using it in the ordinary way, subject to the legal exceptions. Ask specifically for restriction if continuing use could cause harm while the dispute remains unresolved.
| Request | Purpose |
|---|---|
| Rectification | Correct inaccurate data or complete incomplete data. |
| Restriction | Pause ordinary use while accuracy or another qualifying issue is checked. |
| SAR | Obtain the underlying personal data and evidence trail. |
| Complaint | Challenge the controller’s investigation or refusal. |
The more consequential the data, the stronger the verification should be.
ICO guidance says controllers should take reasonable steps to check accuracy, with greater effort where the information is used to make significant decisions. If disputed data affects credit, employment, housing, insurance, safeguarding or access to services, explain the consequence and ask what source was relied upon and how the controller verified it.
Define the alleged inaccuracy precisely: fact, incomplete fact, historic event or opinion.
The DPA 2018 describes personal data as inaccurate if it is incorrect or misleading as to a matter of fact. That distinction matters. A record can accurately state that somebody made an allegation even if you dispute the allegation itself; an opinion may be accurately recorded as an opinion even though you disagree with it. A resolved mistake may also remain part of an accurate chronology if the later correction is clearly recorded.
Your request should therefore identify exactly what field or statement is wrong, why it is wrong, what the accurate position is and what evidence supports the correction.
Official sources
Check the rules behind this guide
These are official or primary sources for this topic. Rules, scheme terms and deadlines can change, so check the live source before relying on a formal time limit or procedure.