Guide
GDPR Data Subject Rights: A Complete Guide
The GDPR grants individuals eight specific rights over their personal data. Every organization that processes personal data must understand these rights, recognize when they apply, and respond to requests correctly. This guide explains all eight data subject rights in practical detail — what they mean, when they apply, and how to handle them.
Understanding GDPR Data Subject Rights
The General Data Protection Regulation establishes a comprehensive set of rights for individuals — referred to in the regulation as “data subjects” — whose personal data is processed by organizations. These data subject rights are codified in Articles 15 through 22 of the GDPR and represent one of the most significant aspects of the regulation. They shift the balance of power from organizations that collect and process personal data to the individuals whose data it is.
These are not abstract principles. They are enforceable rights that individuals can exercise at any time, and organizations are legally obligated to respond. When a data subject submits a request exercising one of these rights, the organization must acknowledge and act on that request within 30 calendar days. In complex cases, this deadline can be extended by an additional 60 days, but the data subject must be informed of the extension and the reasons for it within the initial 30-day period.
Non-compliance with data subject rights is one of the most common grounds for GDPR enforcement actions. Supervisory authorities across the European Economic Area have issued substantial fines to organizations that failed to respond to access requests, ignored erasure demands, or made it unreasonably difficult for individuals to exercise their rights. Understanding these rights is not optional — it is a core compliance requirement.
8
Individual Rights
Articles 15 through 22 of the GDPR establish eight distinct rights that every data subject can exercise against any data controller.
30
Days to Respond
Organizations must respond to data subject requests within 30 calendar days. Complex requests may be extended to 90 days with notice.
€20M
Maximum Fine
Violations of data subject rights can result in fines of up to 20 million euros or 4% of annual global turnover, whichever is greater.
The 8 Rights
Every GDPR Data Subject Right Explained
Each right is established in a specific GDPR article. Below, we cover what each right means, when it applies, the common exceptions, how to handle requests, and how FixGDPR helps you stay compliant.
-
Articles 13 & 14
Right to Be Informed
The right to be informed is the foundation of GDPR transparency. It requires organizations to tell individuals what personal data is being collected about them, why it is being collected, how long it will be kept, and who it will be shared with. This right is not triggered by a request from the individual — it is an obligation that applies automatically whenever personal data is collected or processed.
What It Means
When you collect personal data directly from an individual (Article 13), you must provide specific information at the point of collection. This includes: the identity and contact details of the data controller, the purposes and legal basis for processing, the categories of recipients who will receive the data, details of any international transfers, the data retention period, and information about all other data subject rights. When personal data is obtained from a source other than the individual (Article 14), the same information must be provided within one month of obtaining the data.
When It Applies
- Every time personal data is collected from an individual, whether through a form, a cookie, an account registration, or any other mechanism
- When personal data is obtained indirectly, such as from a third-party data provider, a public register, or another organization
- When the purposes of processing change after the data was originally collected
Common Exceptions
- The individual already has the information you would be required to provide
- Providing the information would be impossible or involve disproportionate effort (Article 14 only, and must be justified)
- The data is subject to a legal obligation of professional secrecy
How to Handle It
The primary vehicle for fulfilling the right to be informed is your privacy policy. It must be written in clear, plain language, be easily accessible from every page of your website, and cover every category of information specified in Articles 13 and 14. You should also provide layered notices at specific data collection points — for example, a brief notice next to a sign-up form that links to the full privacy policy. Review and update your privacy policy whenever your data practices change.
Timeline
Information must be provided at the time of data collection (Article 13) or within one month of obtaining data from other sources (Article 14). There is no response deadline because this is not a request-based right — it is a proactive obligation.
How FixGDPR helps: Our privacy policy generator creates a comprehensive, GDPR-compliant privacy policy that covers every disclosure required by Articles 13 and 14. It is automatically updated when regulations change, and it stays synchronized with your actual cookie and tracker configuration detected by our scanner — so your privacy policy always reflects reality.
-
Article 15
Right of Access
The right of access, commonly known as a Subject Access Request (SAR), allows any individual to request confirmation of whether their personal data is being processed and, if so, to obtain a copy of that data along with supplementary information about how it is being used. This is one of the most frequently exercised data subject rights and one that supervisory authorities take very seriously when investigating complaints.
What It Means
When an individual makes an access request, you must provide them with: confirmation that you are processing their personal data, a copy of all the personal data you hold about them, the purposes of processing, the categories of data concerned, the recipients or categories of recipients who have received the data, the retention period or criteria used to determine it, information about their other rights, and the source of the data if it was not collected directly from the individual. The data must be provided in a commonly used electronic format if the request was made electronically.
When It Applies
- Any individual whose data you process can submit an access request at any time, for any reason
- The individual does not need to explain why they want access to their data
- Requests can be submitted verbally, in writing, or through electronic means
Common Exceptions
- Manifestly unfounded or excessive requests (e.g., repetitive requests with no new purpose) — you may charge a reasonable fee or refuse
- Requests that would adversely affect the rights and freedoms of others, such as revealing personal data about a third party
- Data subject to legal privilege or ongoing legal proceedings in certain circumstances
How to Handle It
Establish a clear process for receiving and responding to access requests. Verify the identity of the requester before releasing any data. Search all systems and databases where personal data may be stored, including backups, email archives, CRM systems, and analytics platforms. Compile a complete copy of the data and provide it in a structured, commonly used format such as PDF or CSV. Include supplementary information about your processing activities as required by Article 15(1).
Timeline
You must respond within 30 calendar days of receiving the request. This can be extended by up to 60 additional days for complex or numerous requests, but you must inform the individual of the extension and the reasons within the initial 30-day period. The first copy must be provided free of charge.
How FixGDPR helps: FixGDPR scans and documents what personal data your website collects through cookies, trackers, and forms. This gives you a clear inventory of data collection points, making it significantly easier to locate and compile all personal data when an access request arrives. Our compliance dashboard tracks the data categories you collect and the third parties you share them with.
-
Article 16
Right to Rectification
The right to rectification gives individuals the ability to request the correction of inaccurate personal data or the completion of incomplete personal data that an organization holds about them. This right reflects the GDPR principle of accuracy enshrined in Article 5(1)(d), which requires that personal data be kept accurate and up to date. When an individual identifies an error in the data you hold about them, you are obligated to correct it without undue delay.
What It Means
If an individual discovers that the personal data you hold about them is factually incorrect — a misspelled name, a wrong address, an outdated phone number, an incorrect date of birth — they have the right to request that you correct it. The right also extends to incomplete data: if you are processing data that is incomplete in a way that is relevant to the purpose of processing, the individual can request that missing information be added. For example, if you hold a customer's billing address but it is missing a postal code, and the customer requests that you add it, you must comply.
When It Applies
- The personal data held by the organization is factually inaccurate
- The personal data is incomplete and the individual wishes to supplement it
- The individual provides evidence or a statement that supports the correction
Common Exceptions
- No general exceptions exist — if data is inaccurate, it must be corrected
- If accuracy is contested and you cannot determine which version is correct, you may restrict processing while verifying (see Right to Restrict Processing)
- Data retained for legal or archival purposes may have different considerations, but must still be annotated as contested if relevant
How to Handle It
When you receive a rectification request, verify the identity of the requester. Review the data in question and the evidence or statement provided by the individual. If the data is indeed inaccurate or incomplete, make the correction across all systems and databases where the data is stored. If you have shared the inaccurate data with any third parties, you must inform those third parties of the correction under Article 19, unless this proves impossible or involves disproportionate effort. Notify the individual when the correction is complete.
Timeline
You must respond within 30 calendar days. If the request is complex, the deadline can be extended to 90 days with notification to the individual within the initial 30-day period. Corrections should be made as quickly as possible to prevent ongoing use of inaccurate data.
How FixGDPR helps: FixGDPR's compliance monitoring ensures your data handling processes are documented. When a rectification request comes in, you can use our platform to track which systems contain the individual's data, making it easier to ensure corrections are applied everywhere — not just in one database.
-
Article 17
Right to Erasure (Right to Be Forgotten)
The right to erasure — often referred to as the “right to be forgotten” — is one of the most well-known and frequently exercised GDPR data subject rights. It allows individuals to request that an organization permanently delete all personal data it holds about them. This right gained public attention through the landmark Google Spain case in 2014, and the GDPR codified and expanded it significantly. It is the right that generates the most requests and the most confusion about when it does and does not apply.
What It Means
When an individual exercises the right to erasure, you must permanently delete all personal data you hold about them from all systems, including production databases, backups (within a reasonable timeframe), email archives, CRM records, analytics data, and any other storage medium. If you have made the data public (for example, by publishing a user profile or a forum post), you must also take reasonable steps to inform other controllers who are processing the data that the data subject has requested erasure.
When It Applies
- The personal data is no longer necessary for the purpose it was originally collected or processed for
- The individual withdraws consent and there is no other legal basis for the processing
- The individual objects to processing under Article 21 and there are no overriding legitimate grounds
- The personal data has been unlawfully processed
- Erasure is required to comply with a legal obligation under EU or member state law
- The data was collected in relation to the offer of information society services to a child
Common Exceptions
- The data is needed to exercise or defend legal claims
- Processing is necessary to comply with a legal obligation (e.g., tax records, anti-money laundering requirements)
- Processing is necessary for reasons of public interest in the area of public health
- The data is needed for archiving purposes in the public interest, scientific or historical research, or statistical purposes
- The data is required for exercising the right of freedom of expression and information
How to Handle It
When an erasure request arrives, first verify the identity of the requester. Then determine whether any exceptions apply. If none apply, proceed to delete the data from all systems. Document the deletion process, including which systems were checked and what was removed. If you have shared the data with third parties, notify them of the erasure request under Article 19. Inform the individual when the erasure is complete, or provide a clear explanation if any exceptions prevent full deletion.
Timeline
You must respond within 30 calendar days. Extensions of up to 60 additional days are permitted for complex cases with prior notification. Even when invoking an exception, you must communicate your decision to the individual within the 30-day deadline.
How FixGDPR helps: FixGDPR scans your website to identify all cookies, trackers, and data collection mechanisms. This comprehensive inventory helps you know exactly where personal data originates and flows, so when an erasure request arrives you have a clear map of every system that needs to be checked and purged. Our privacy policy generator also ensures your policy accurately describes how individuals can exercise the right to erasure.
-
Article 18
Right to Restrict Processing
The right to restrict processing is a nuanced right that allows individuals to request that their personal data be stored but not actively used. Rather than demanding outright deletion, the individual is asking you to freeze the data — keep it in place but stop processing it for any purpose beyond storage. This right is particularly useful in situations where the accuracy of the data is in dispute, or while a decision about an objection is being made.
What It Means
When processing is restricted, you must stop all active processing of the individual's personal data. You can continue to store the data, but you cannot use it, share it, include it in analytics, send marketing communications based on it, or process it in any other way. The only exceptions are: processing with the individual's consent, processing for the establishment, exercise, or defence of legal claims, for the protection of the rights of another person, or for reasons of important public interest. The data should be clearly marked as restricted in your systems to prevent accidental processing.
When It Applies
- The individual contests the accuracy of their personal data — processing is restricted while you verify accuracy
- The processing is unlawful, but the individual prefers restriction over erasure
- You no longer need the data for processing, but the individual needs it for the establishment, exercise, or defence of legal claims
- The individual has objected to processing under Article 21 and you are verifying whether your legitimate grounds override theirs
Common Exceptions
- Processing with the data subject's explicit consent (even during restriction)
- Processing necessary for legal claims
- Processing for the protection of the rights of another natural or legal person
- Processing for reasons of important public interest of the EU or a member state
How to Handle It
When you receive a restriction request, verify the identity of the requester and determine which of the four applicable grounds the request falls under. Flag the individual's data across all systems to prevent it from being included in any active processing. If you have shared the data with third parties, inform them of the restriction under Article 19. When the restriction is lifted — for example, because the accuracy has been verified or the objection review is complete — you must inform the individual before resuming processing.
Timeline
You must acknowledge and implement the restriction within 30 calendar days. The restriction remains in place until the underlying issue is resolved. Before lifting the restriction, you must notify the individual.
How FixGDPR helps: FixGDPR's consent management and data mapping tools help you maintain clear records of processing activities. When a restriction is requested, our platform helps you identify all the places where the individual's data might be actively processed, so you can ensure the freeze is applied comprehensively across your entire technology stack.
-
Article 20
Right to Data Portability
The right to data portability allows individuals to receive their personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another data controller without hindrance. This right was introduced by the GDPR to prevent “vendor lock-in” and to empower individuals to move their data between service providers easily. It is narrower in scope than the right of access because it only applies to certain types of data processed under certain legal bases.
What It Means
When an individual exercises the right to data portability, you must provide them with their personal data in a format that can be read by a computer — JSON, CSV, XML, or another structured format. The individual can then take that file and provide it to another organization. If technically feasible and requested by the individual, you must transmit the data directly to another controller on their behalf. The format must allow the receiving controller to use the data without needing proprietary software or manual re-entry.
When It Applies
- The data was provided directly by the individual (not data inferred or derived by the organization, such as algorithmic scores or internal assessments)
- The processing is carried out by automated means (not manual paper records)
- The legal basis for processing is consent (Article 6(1)(a) or Article 9(2)(a)) or contractual necessity (Article 6(1)(b))
Common Exceptions
- Data processed on the basis of legitimate interest, legal obligation, or public interest is not covered by the portability right
- Derived or inferred data (e.g., credit scores, customer profiles built from analytics) does not need to be included
- The right must not adversely affect the rights and freedoms of others
- Portability does not require you to adopt or maintain technically compatible processing systems
How to Handle It
When a portability request is received, identify all personal data that the individual provided directly and that is processed by automated means on the basis of consent or contract. Extract this data into a structured, machine-readable format. Provide the data file to the individual, or if they request it and it is technically feasible, transmit it directly to the controller they designate. Note that fulfilling a portability request does not automatically delete the data from your systems — the individual would need to exercise the right to erasure separately if they also want deletion.
Timeline
You must respond within 30 calendar days. Extensions of up to 60 additional days are available for complex requests with notification to the individual. The data must be provided free of charge.
How FixGDPR helps: FixGDPR identifies the data collection mechanisms on your website, helping you map exactly what personal data is collected directly from individuals through forms, account registrations, and consent interactions. This mapping is essential for determining which data falls within the scope of portability requests and which does not.
-
Article 21
Right to Object
The right to object allows individuals to challenge the processing of their personal data in specific circumstances. Unlike the right to erasure, which is about deleting data, the right to object is about stopping particular types of processing. It is especially powerful in two areas: processing based on legitimate interests and direct marketing. For direct marketing, the right to object is absolute — no exceptions, no balancing test, and no grounds for refusal.
What It Means
When an individual objects to the processing of their personal data, you must stop processing that data unless you can demonstrate compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the individual, or the processing is necessary for the establishment, exercise, or defence of legal claims. For direct marketing purposes — including profiling related to direct marketing — the individual has an absolute right to object, and you must stop processing immediately and without qualification upon receiving the objection.
When It Applies
- Processing is based on legitimate interest (Article 6(1)(f)) or the performance of a task carried out in the public interest (Article 6(1)(e))
- Processing for direct marketing purposes, including any profiling related to direct marketing
- Processing for scientific or historical research or statistical purposes, unless the processing is necessary for a task carried out for reasons of public interest
Common Exceptions
- For legitimate interest processing: you can continue if you can demonstrate compelling legitimate grounds that override the individual's interests, rights, and freedoms
- Processing necessary for legal claims can continue regardless of the objection
- For direct marketing: there are no exceptions — objections must always be honored
How to Handle It
Your privacy policy and any marketing communications must clearly inform individuals of their right to object. When you receive an objection, determine the legal basis for the processing in question. If it is direct marketing, stop processing immediately. If it is based on legitimate interest, conduct a balancing test to determine whether your grounds are compelling enough to override the individual's interests. Document your assessment. If you decide to continue processing, you must provide the individual with a clear explanation of your compelling grounds. If you stop processing, confirm this to the individual.
Timeline
For direct marketing objections, processing must cease immediately upon receipt of the objection. For other objections, you must respond within 30 calendar days with your decision and reasoning.
How FixGDPR helps: FixGDPR's consent banner gives visitors a clear way to object to non-essential data processing from the moment they arrive on your website. Our cookie blocking technology ensures that marketing and analytics scripts are suppressed when an individual declines consent, effectively implementing the right to object at the technical level for website tracking and advertising.
-
Article 22
Rights Related to Automated Decision-Making
Article 22 of the GDPR establishes that individuals have the right not to be subject to a decision based solely on automated processing — including profiling — which produces legal effects concerning them or similarly significantly affects them. This right is about protecting individuals from decisions made entirely by algorithms, machine learning models, or automated systems without any meaningful human involvement. It covers areas such as automated credit scoring, algorithmic hiring decisions, insurance risk assessments, and any other automated process that has a substantial impact on an individual's rights or circumstances.
What It Means
If your organization uses automated systems to make decisions about individuals that have a significant effect on them — approving or denying a loan, determining insurance premiums, screening job applications, assigning credit limits, or deciding who receives targeted advertising — the individual has the right to demand that a human being review the decision. They also have the right to express their point of view, to contest the decision, and to receive a meaningful explanation of the logic involved. Solely automated decisions with significant effects are prohibited unless specific conditions are met.
When It Applies
- Decisions are made solely by automated means with no meaningful human involvement in the decision-making process
- The decision produces legal effects (such as denial of a contract) or similarly significantly affects the individual (such as denial of an online credit application or automated rejection of a job application)
- This includes profiling that results in automated decisions with significant effects
Common Exceptions
- The decision is necessary for entering into or performing a contract between the individual and the data controller
- The decision is authorized by EU or member state law that also includes suitable measures to safeguard the individual's rights and freedoms
- The decision is based on the individual's explicit consent
- Even when exceptions apply, you must implement suitable safeguards including the right to obtain human intervention, express their point of view, and contest the decision
How to Handle It
First, audit your systems to identify any processes that make solely automated decisions with significant effects on individuals. For each such process, ensure that you have a valid legal basis (contract, law, or explicit consent) and that suitable safeguards are in place. Implement a mechanism for individuals to request human review of automated decisions. Train staff who conduct human reviews to ensure they have the authority and knowledge to override automated decisions when appropriate. Your privacy policy must disclose the existence of automated decision-making, the logic involved, and the significance and envisaged consequences for the data subject.
Timeline
Requests for human review or challenges to automated decisions must be addressed within 30 calendar days, consistent with the general GDPR request timeline. When an individual contests an automated decision, the human review should be substantive and not merely a rubber stamp of the automated outcome.
How FixGDPR helps: FixGDPR's privacy policy generator includes a section on automated decision-making that you can customize to accurately describe any profiling or automated processing your organization performs. Our compliance checklist also prompts you to audit automated decision-making processes, ensuring nothing is overlooked when building your GDPR compliance posture.
Practical Guide
How to Handle Data Subject Requests
Setting up a structured process for receiving, tracking, and responding to data subject requests is essential. Follow these steps to ensure you never miss a deadline or overlook a request.
-
Verify the requester's identity
Before releasing any personal data or making changes, you must confirm that the person making the request is actually the data subject they claim to be. Ask for enough identifying information to be confident without requesting excessive data. For existing customers, you can verify identity against account details. For others, a government-issued ID or other reasonable verification is appropriate. Do not release personal data to an unverified requester — doing so would itself be a GDPR violation. Balance security with proportionality: the verification process should not be so burdensome that it discourages individuals from exercising their rights.
-
Log the request with date received
Record every data subject request as soon as it arrives, noting the date received, the type of request (access, erasure, rectification, etc.), the identity of the requester, and the channel through which it was received. This log serves two purposes: it helps you track your 30-day response deadline, and it provides documentary evidence of your compliance in case of a regulatory audit. Use a centralized system rather than relying on individual email inboxes — requests that get lost or forgotten are a common source of GDPR complaints. Assign each request to a responsible team member.
-
Respond within 30 days
The GDPR requires a response within 30 calendar days of receiving the request. For complex requests or high volumes of requests from the same individual, you can extend this deadline by an additional 60 days — bringing the maximum to 90 days total. However, you must inform the data subject of the extension and the reasons for it within the initial 30-day period. The clock starts on the day the request is received, not the day you begin working on it. If the deadline falls on a weekend or public holiday, respond by the last business day before the deadline to be safe.
-
Provide information free of charge
For the first request from an individual, you must provide the information or take the requested action free of charge. You may charge a reasonable fee based on administrative costs for any further copies of data requested under the right of access, or if the request is manifestly unfounded or excessive — particularly if it is repetitive. However, charging a fee is the exception, not the norm. If you intend to charge, you must justify it and communicate the amount to the data subject before proceeding. Most organizations simply absorb the cost as a compliance expense.
-
Document everything
Keep detailed records of every data subject request you receive and how you handled it. Document the request itself, your identity verification process, the searches you conducted, the data you found (or did not find), the response you provided, the date you responded, and any exceptions you invoked. This documentation is your evidence of compliance under the accountability principle of GDPR Article 5(2). If a supervisory authority investigates a complaint, they will ask to see your records. Organizations with thorough documentation are far better positioned to demonstrate good faith compliance than those operating informally.
Get started
Make data subject rights compliance easier
FixGDPR gives you the tools to understand what data your website collects, maintain a compliant privacy policy, and manage consent — the foundation for handling data subject requests correctly.
Related resources
Learn more about GDPR compliance
What Is GDPR?
A plain-language overview of the General Data Protection Regulation: who it applies to, what it requires, and what happens when organizations fail to comply.
GDPR Compliance Checklist
A step-by-step checklist covering every requirement of the GDPR, from data mapping and lawful basis documentation to breach notification procedures.
Privacy Policy Generator
Generate a GDPR-compliant privacy policy that covers all required articles, including data subject rights disclosures, customized to your actual data practices.
GDPR for Small Business
A practical guide to GDPR compliance for small businesses, covering the essentials without the enterprise complexity and legal jargon.