Insights / Corporate & Commercial

Does the Data Protection Act Protect Your Company’s Reputation?

By Clay & Associates Advocates · 3 min read ·

A focused businessman working on his laptop at a table

When something damaging about a company appears online, it is tempting to reach for the Data Protection Act as a tool to get it taken down, especially since it already gives individuals a right to object to processing and to have false or misleading data corrected. The honest answer is that the Act was not built to protect a company’s reputation directly, and understanding exactly where it stops, and where it still genuinely helps, saves a lot of wasted effort chasing the wrong remedy.

A company is not a “data subject”, and that matters more than it sounds

The Data Protection Act, 2019 defines a data subject as an identified or identifiable natural person who is the subject of personal data. A company is a legal person, not a natural one, and simply does not fit this definition. This means a company cannot itself object to processing, demand correction of false data, or invoke any of the Act’s data subject rights over content that is purely about the company as a corporate entity, its financial performance, its business practices, its products. However damaging that content is, the Data Protection Act is not the tool that reaches it.

Where it actually does help, and it is a real gap worth knowing

Damaging content about a company very often includes personal data about identifiable individuals connected to it, a named director, a named executive, photographs, home addresses, or personal details woven into an otherwise corporate story. Those individuals, not the company, are the data subjects with respect to that specific information, and they can personally exercise their own rights: objecting to the processing of their personal data, demanding correction of information about them that is false or misleading, and in some cases pursuing a claim for the way their personal data was used. Where a damaging piece names a director and includes inaccurate personal details about them specifically, that director’s individual complaint can sometimes achieve more than the company’s own efforts ever could, since it is aimed at the one legal hook the Act actually provides.

Coordinating this without confusing the company’s interest with the individual’s

A company can support and coordinate this kind of response, briefing the affected director on what the Act actually allows, helping identify exactly which statements about them personally are false, and aligning the timing with whatever other steps the company is taking. What it cannot do is exercise the right itself or file the complaint in the company’s own name, since the right belongs to the individual, not the business. Keeping this distinction clear also protects the individual director, since a complaint that reads as a corporate PR exercise wearing an individual’s name is considerably weaker than one that is genuinely about that person’s own data.

What actually protects the company itself

For damage to the company’s own reputation, the tools that actually apply are defamation law where a false statement of fact has caused real harm, the Consumer Protection Act where a competitor or third party has made a false representation about your goods or services, and platform-level takedown requests for content that breaches a platform’s own policies regardless of whether it meets a formal legal threshold. The Data Protection Act sits alongside these as a narrow, individual-specific tool, not a general-purpose reputation remedy, and treating it as the latter usually means spending time on a complaint that was never going to reach the content actually causing the damage.

Sources

&

Clay & Associates Advocates
This article is general information, not legal advice. For advice on your matter, speak to counsel.

Related Insights

Discover more