Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

GDPR data subject rights explained including access, rectification, erasure and portability

GDPR Data Subject Rights Explained

The GDPR data subject rights put individuals firmly in control of their personal data — and give organizations a clear set of obligations to honour. Handling rights requests correctly, and on time, is one of the most visible parts of GDPR compliance. This guide explains each right, how to respond, and the timelines that apply.

GDPR data subject rights explained including access, rectification, erasure and portability

For the wider context, see our complete GDPR guide.

What are GDPR data subject rights?

Data subject rights are the legal entitlements the GDPR grants to individuals over their personal data. They allow people to find out what data you hold, correct it, have it deleted, restrict or object to its use, and move it elsewhere. Organizations must be able to recognise these requests, verify the requester, and respond within set timeframes — usually free of charge.

The eight data subject rights

  • The right to be informed — to know how their data is used, via clear privacy notices.
  • The right of access — to obtain a copy of their personal data (a “subject access request”).
  • The right to rectification — to have inaccurate data corrected.
  • The right to erasure — the “right to be forgotten,” in defined circumstances.
  • The right to restrict processing — to limit how their data is used.
  • The right to data portability — to receive and reuse their data across services.
  • The right to object — to certain processing, including direct marketing.
  • Rights related to automated decision-making and profiling — including a right to human intervention.

How to respond to a data subject request

A reliable process matters because requests can arrive by any channel — email, phone, or a form. You should log the request, verify the individual’s identity, locate the relevant data across your systems, apply any exemptions carefully, and respond clearly. Because a request can involve data held in many places, organizations that have mapped their data in advance respond far more smoothly than those searching from scratch.

Timelines and exemptions

You must respond to a data subject request without undue delay and within one month, extendable by up to two further months for complex or numerous requests. Responses are generally free, though a reasonable fee may apply to manifestly unfounded or excessive requests. Some rights are qualified rather than absolute — for example, erasure may not apply where you have a legal obligation to retain data — so each request must be assessed on its facts.

Handle rights requests with confidence.

Our GDPR Toolkit includes a data-subject-rights procedure and request templates — plus the records of processing that make locating data fast — editable in Word and Excel.

Explore the GDPR Toolkit →

Frequently asked questions

What are the GDPR data subject rights?

The rights to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and rights related to automated decision-making and profiling.

How long do you have to respond to a data subject request?

Without undue delay and within one month, extendable by up to two further months for complex or numerous requests.

Is the right to erasure absolute?

No. Erasure applies in defined circumstances and can be overridden where, for example, you have a legal obligation to retain the data. Each request is assessed on its facts.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.