The UK has some strong privacy laws that give you control over how your personal data is collected, used and shared. And we think it's important that you know exactly what they are, and how they apply to you.
These laws include (but aren't limited to):
- The UK General Data Protection Regulation (you'll probably know this as the GDPR!)
- The Data Protection Act 2018
- The Data (Use and Access) Act 2025
Here's a breakdown of:
- your rights
- when they apply
- and how you can exercise them
You have a right to:
Be informed
It's your right to…
Know what personal data we process about you and how we process it.
How?
We keep you informed:
- through this privacy policy
- through the information we give you when you buy a policy or product with us
- by answering your questions and requests when you get in touch
Make a Subject Access Request (“SAR”)
It's your right to…
Ask for access to the personal data we process about you, as well as certain other information about how we process it.
How?
To ask for access to your personal data, you can email us at InformationRightsTeam@admiralgroup.co.uk or give us a call.
Rectification
It's your right to…
Ask that we change or update your personal data if it's inaccurate or incomplete.
How?
You can update your details at any time by getting in touch with us or in your online account.
Erasure
It's your right to…
Ask us to delete your personal data in some situations.
For example, you can ask us to delete personal data:
- we no longer need for the reason we collected it
- we process based on the legal basis of consent, and you withdraw your consent
- when you object (check out our section on objecting below) and
- if we have processed it unlawfully
- there are no overriding legitimate grounds for us to keep your personal data
- or you object to how we've processed your personal data for direct marketing purposes
Just a heads up, there are some situations where we won't be able to delete your data. For example:
- when it's still necessary for us to process your personal data for the reason we collected it (for instance, so we can give you a service)
- when we have legitimate grounds to use your personal data which override your interest to delete it (for example, where we need the data to protect ourselves from fraud)
- when we have a legal obligation to keep the data (for example, to help prevent money laundering)
- when we need the data to support or defend legal claims (for example, if there's an issue with your account and we haven't been able to resolve yet)
How?
You can ask us to delete your personal data by emailing us at InformationRightsTeam@admiralgroup.co.uk
Restriction
It's your right to…
Ask us to restrict our processing of all, or some, of your personal data.
You can do this if:
- your personal data isn't accurate
- we processed it unlawfully
- we don't need your personal data for a specific reason
- you object to how we process it, and we're assessing your objection request - check out our section on objecting below
You can ask that we restrict processing your data either temporarily or permanently.
Just so you know - unless there is a valid request to restrict your personal data being processed, we might:
- continue to store your personal data
- process it with your consent
- use it to support or defend a legal claim (for example, if there's an issue with your account and we haven't been able to resolve yet)
How?
You can make a restriction request by emailing us at InformationRightsTeam@admiralgroup.co.uk
Object
It's your right to…
Object to us processing your personal data.
You can do this if:
- we're processing your personal data on the legal basis of Legitimate interests
- we're using your data for direct marketing purposes
Just a heads up - if you object to us processing your data on the legal basis of Legitimate interests, and not for direct marketing purposes, we might continue to process your personal data if we can show we have a strong and legitimate reason to.
How?
You can make an objection request by contacting us at InformationRightsTeam@admiralgroup.co.uk
You can unsubscribe from direct marketing at any time by:
- clicking 'unsubscribe' on any direct marketing email from us
- emailing marketingpreferences@admiralgroup.co.uk
- writing to Head of Customer Assurance, Tŷ Admiral, David Street, Cardiff, CF10 2AA
Data portability
It's your right to…
Ask us to transmit your personal data to a third party.
You have the right to get your personal data in an electronic format, and the right to transmit your data to a third party for use in that third party's service.
Just so you know - if you'd like, we'll give you an electronic copy of your data to pass onto third parties. But right now, we can't send your information directly on to a third party.
How?
For more information see our section on access above.
Not be subject to automated decision making
It's your right to…
Have a human involved when a decision is going to be made that would have a legal or significant effect on you.
This right doesn't apply if:
- the decision is needed to enter into, or perform, a contract between you and us
- it's authorised by law
- we have your explicit consent.
In those cases, you do still have a right to request human intervention. So don't hesitate to let us know your views and challenge the decision!
How?
You can ask for more information about how we make decisions about you by getting in touch. Find out more about automated decision making.
To make a complaint
It's your right to…
You have the right to make a complaint about any concerns you have on how we process your personal data.
You can raise your complaint with the Information Commissioner's Office
How?
Find out how to raise a complaint with the DPO and find the ICO details here.
Got more questions?
Do I have to pay to make a information rights request?
In most cases, you don't have to pay to exercise your rights.
How long does it take once I've made a privacy request?
Once you've made a request to us about your data, we have one month to respond.
In some situations, we can extend it by another two months.