GDPR rights

The eight rights carry specific response obligations for organizations, including defined timelines (generally 30 days, extendable to three months for complex requests).

  • Right of access: Individuals can request a copy of all personal data an organization holds about them.
  • Right to rectification: Individuals can request correction of inaccurate or incomplete personal data.
  • Right to erasure: Individuals can request deletion of their personal data when consent is withdrawn or data is no longer necessary.
  • Right to restriction of processing: Individuals can request that processing be paused while a dispute is resolved.
  • Right to data portability: Individuals can request their data in a machine-readable format, or ask for it to be transferred directly to another controller.
  • Right to object: Individuals can object to processing based on legitimate interests, direct marketing, or research purposes.
  • Rights related to automated decision-making: Individuals can request human review of significant decisions made solely by automated systems.
  • Right to be informed: Individuals must be clearly told how their data will be used at the time of collection. Fulfilling these rights requires locating relevant data across every system an organization uses, a task that demands automation at any meaningful scale.

Additional resources