Rules & Requirements —
Understanding GDPR Data Subject Rights
GDPR grants data subjects rights such as access, correction, erasure, portability, and compliant responses.
Share this article
GDPR Data Subject Rights: All 8, Explained
Most lists of GDPR rights only mention seven. There are actually eight — the right to be informed gets left off a lot, which is a little ironic, since it's the right that makes all the others possible. You can't ask to see your data, fix it, or delete it if you never knew a company had it in the first place.
Here's all eight, plus the deadlines and exceptions that actually matter when you're the one responding to a request.
1. The Right to Be Informed
People have the right to know what data you're collecting, why, and what you're doing with it. Most companies handle this through a privacy notice, but it's not just a checkbox — the information actually has to be clear, not buried in legal language nobody reads.
2. Right of Access
Someone can ask for a copy of their own data. You have one month to respond, and the first copy has to be free. If they ask for more copies after that, you're allowed to charge a reasonable fee.
3. Right to Rectification
If someone's data is wrong or incomplete, they can ask you to fix it. Same one-month clock. And here's the part people forget: if you already shared that wrong data with someone else, you're supposed to tell them about the correction too, unless that's genuinely not possible.
4. Right to Erasure ("Right to Be Forgotten")
This is the one everyone's heard of, and it's also the one most people get wrong, because it's not absolute. You have to delete someone's data if, for example, you don't need it anymore, they've pulled their consent, or you were processing it unlawfully to begin with.
But you can say no in specific situations — if you need the data for a legal obligation, for public interest reasons, to defend yourself in a legal claim, for scientific or historical research, or for freedom of expression and information. If you decline, you have to tell the person why.
5. Right to Restrict Processing
This one's quieter than erasure. Instead of deleting the data, you just stop actively using it — but you can still store it. This shows up a lot when someone disputes the accuracy of their data and wants it frozen while you sort out who's right.
6. Right to Data Portability
People can ask for their data in a format they can actually reuse — and ask you to send it straight to another company if they want. This only applies to data they gave you directly, based on consent or a contract, and only if it was processed automatically. So it's narrower than it sounds.
7. Right to Object
People can object to certain kinds of processing — direct marketing is the big one, and there's no wiggle room there. If someone objects to marketing, you have to stop. Full stop, no exceptions.
This right is actually in the news right now. Meta has argued it can use people's data to train AI under "legitimate interest," without needing opt-in consent first. The privacy group noyb disagrees and has challenged it, with potential legal exposure reportedly in the hundreds of billions of euros range. However that plays out, it's a live example of how far "the right to object" can stretch when AI training data is involved.
8. Rights Related to Automated Decision-Making
People can push back on a decision made entirely by an algorithm if it has a real legal or otherwise significant effect on them — think automated loan denials or hiring screens. They can ask for an actual human to review it instead.
The Deadlines, in Plain Terms
One month from when you receive the request. If it's genuinely complex, or you're dealing with a flood of requests from the same person, you can stretch that to three months total — but you have to tell them about the extension within that first month. Miss that window, and the original one-month deadline just stands, extension or not.
Why This Actually Matters Day to Day
This isn't just a legal obligation sitting in a drawer — these requests are increasing fast. Some reports show access requests growing 50% in just two years. If you don't have a real process for finding someone's data across your systems, verifying who they are, and responding on time, you're going to get caught flat-footed the first time someone actually asks.
Controllers carry primary responsibility for fulfilling these rights — see GDPR: Controller vs. Processor Responsibilities for how that responsibility splits when a processor's involved too. And all eight rights ultimately trace back to the seven core GDPR principles, particularly transparency and accountability.
Where This Connects to Other Frameworks
A lot of the groundwork for handling these requests well — knowing where your data lives, having access controls, keeping good records — overlaps with what ISO 27001 and SOC 2 already expect. If you've built solid data mapping and access governance for either of those, you're most of the way to handling GDPR rights requests smoothly too.
FAQs
How many data subject rights does GDPR actually provide? Eight, though most lists only mention seven. The right to be informed is commonly left off, even though it underpins all the others — people can't exercise rights like access, correction, or deletion for data they never knew a company held.
How long does a company have to respond to a data subject rights request? One month from receipt of the request. If the request is genuinely complex or part of a flood of requests from the same person, this can be extended to three months total — but the person must be told about the extension within that initial one-month window.
Is the "right to be forgotten" absolute under GDPR? No. Organizations must delete data when it's no longer needed, consent has been withdrawn, or it was processed unlawfully — but they can decline in specific cases, such as a legal obligation, public interest, defending a legal claim, scientific research, or freedom of expression. If declined, the organization must explain why.
What's the difference between the right to erasure and the right to restrict processing? Erasure means the data is actually deleted. Restriction means the organization stops actively using the data but can still store it — commonly used when someone disputes the accuracy of their data and wants it frozen while the dispute is resolved.
What is the right to data portability, and how limited is it? It allows people to receive their data in a reusable format and request it be sent directly to another company. However, it only applies to data they provided directly, based on consent or a contract, and only if it was processed automatically — making it narrower than many assume.
Can someone object to having their data used for direct marketing? Yes, and there's no exception here. If someone objects to their data being used for direct marketing, the organization must stop, full stop — unlike other objection scenarios where an organization can sometimes justify continuing.
Does GDPR give people rights over decisions made entirely by AI or algorithms? Yes. Under rights related to automated decision-making, people can push back against decisions made solely by an algorithm if it has a significant legal or similar effect on them — such as an automated loan denial or hiring screen — and request human review instead.
Can a company use someone's data to train AI under "legitimate interest" without consent? This is currently a live legal dispute. Meta has argued it can rely on "legitimate interest" to use data for AI training without opt-in consent, while the privacy group noyb has challenged this, with potential legal exposure reportedly in the hundreds of billions of euros. The outcome isn't yet settled.
What happens if a company misses the one-month deadline for a rights request extension notice? If an organization fails to notify the requester about a deadline extension within the original one-month window, the original one-month deadline stands regardless — the extension isn't automatically granted just because the request is complex.
Who is responsible for fulfilling data subject rights requests — the controller or the processor? Controllers carry primary responsibility for fulfilling these rights, though processors have obligations too when they're involved in handling the data. See GDPR: Controller vs. Processor Responsibilities for how that responsibility splits.
Are data subject access requests actually increasing? Yes — some reports show access requests growing by 50% in just two years, making a reliable process for locating data, verifying requester identity, and responding on time increasingly important rather than optional.
In the Spotlight
Start your GDPR compliance journey with DSALTA's complete checklist.
The General Data Protection Regulation (GDPR) is Europe’s core privacy law, shaping how organizations collect, process, and protect the personal data of EU residents. Non-compliance can result in heavy fines, reputational damage, and loss of customer trust.
GDPR can feel complicated with its broad scope and strict requirements, but DSALTA® makes it manageable. With automated evidence collection, continuous monitoring, and AI- driven risk insights, you can maintain compliance without drowning in manual work. Use this checklist to guide your GDPR journey.
Read more about GDPR compliance with DSALTA.
Stop losing deals to compliance.
Get compliant. Keep building.
Join 100s of startups who got audit-ready in days, not months.




