Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Privacy

Your GDPR Rights and How to Use Them

The GDPR gives you powerful rights over your personal data. Learn about your rights to access, erasure, and more, and follow our step-by-step guide.

By · Published · 11 min read

A person's hands holding a translucent key over a complex, abstract network of glowing data points, symbolizing control over personal information.

The General Data Protection Regulation (GDPR) gives you a powerful set of legal rights to control how organizations use your personal data. These rights allow you to see what information a company holds on you, demand corrections, request its deletion, and object to certain types of processing. Understanding and using these rights is a fundamental step in managing your digital footprint and protecting your privacy.

What is GDPR and Who Does It Protect?

Enacted in 2018, the GDPR is a landmark data protection law from the European Union. Its primary goal is to give individuals control over their personal data. While it's an EU regulation, its reach is global. The GDPR applies to any organization in the world that processes the personal data of people located within the European Economic Area (EEA), which includes all EU countries plus Iceland, Liechtenstein, and Norway.

So, if you are in the EEA and use a service from a company based in the United States, that company must comply with GDPR when handling your data. Post-Brexit, the UK has its own version called the UK GDPR, which mirrors the EU regulation in almost every way.

"Personal data" is a broad term under GDPR. It’s any information that can be used to identify a living person, either directly or indirectly. This includes obvious identifiers like your name, email address, and phone number, but also less direct ones like your IP address, cookie identifiers, location data, and even biometric or genetic information. If data can be linked back to you, it's likely protected by GDPR.

Your Core Data Protection Rights Under GDPR

The regulation establishes eight fundamental rights for individuals. Understanding what each one does is the key to using them effectively.

The Right to be Informed

Organizations must be transparent about how they collect and use your personal data. This information should be provided in a privacy notice that is concise, easy to understand, and readily accessible. It must detail what data they are collecting, why they are collecting it (the lawful basis), how long they will keep it, and with whom they will share it.

The Right of Access

This is one of the most powerful rights. You have the right to ask a company for a copy of all the personal data it holds about you. This is commonly known as a Data Subject Access Request (DSAR). You can also ask for supplemental information, such as the purpose of the processing and the categories of data concerned, which should already be in their privacy notice.

The Right to Rectification

You have the right to have inaccurate personal data corrected. If you notice a company has an old address, an incorrect birthdate, or a misspelled name for you, you can demand they fix it. If the data is incomplete, you also have the right to have it completed.

The Right to Erasure ('Right to be Forgotten')

This right allows you to request the deletion of your personal data. This is not an absolute right and only applies in specific circumstances, such as:

  • The data is no longer necessary for the purpose it was originally collected.
  • You withdraw consent (if consent was the legal basis for processing).
  • You object to the processing and there are no overriding legitimate grounds to continue.
  • The data was unlawfully processed.

However, a company can refuse an erasure request if the data is needed to comply with a legal obligation, for public health purposes, or for exercising the right of freedom of expression. Still, companies that ignore valid requests face significant penalties, as seen when [French regulator CNIL fined Extia €300,000 for ignoring erasure requests](/posts/cnil-fines-extia-right-to-erasure) from former employees.

The Right to Restrict Processing

This right allows you to 'pause' the processing of your data. It's an alternative to requesting erasure. You can request a restriction when you're contesting the accuracy of the data, when the processing is unlawful but you don't want it erased, or when you've objected to processing and are waiting for a decision on your objection. During the restriction period, the organization can store the data but not use it.

The Right to Data Portability

This right allows you to obtain and reuse your personal data for your own purposes across different services. You can request your data in a structured, commonly used, and machine-readable format (like a CSV or JSON file). This is designed to make it easier for you to switch from one service provider to another, for example, moving your playlists from one music streaming service to another.

The Right to Object

You have the absolute right to object to your data being used for direct marketing. Once you object, the organization must stop immediately. You can also object to processing that is based on 'legitimate interests' or 'public task'. In these cases, the organization must stop processing unless it can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms. Regulators take this seriously; for instance, [BBVA Italia was fined €5.5M for ignoring marketing opt-outs](/posts/bbva-italia-fined-marketing-objection) from its customers.

Rights Related to Automated Decision-Making and Profiling

GDPR gives you rights when an organization is using automated processes to make decisions about you that have a legal or similarly significant effect. You have the right to not be subject to such a decision, to obtain human intervention, and to be able to express your point of view and challenge the decision.

How to Make a GDPR Request: A Step-by-Step Guide

Exercising your rights is usually straightforward. Here’s how to do it.

  1. Identify the Data Controller: The 'data controller' is the organization holding your data. Find their privacy policy, which is usually linked in the footer of their website. This page should contain contact details for privacy inquiries, often for a Data Protection Officer (DPO).
  1. Draft Your Request: Your request doesn't need to be long or formal. Simply state who you are and which right you want to exercise. Be as specific as possible. For example, instead of "I want my data," you could say, "Pursuant to my right of access under Article 15 of GDPR, please provide me with a copy of all personal data you hold about me."
  1. Prove Your Identity: A company must verify your identity before handing over personal data. This is to prevent someone from fraudulently accessing your information. They should only ask for the minimum information necessary to confirm you are who you say you are.
  1. Send and Track: Email is the best method as it creates a time-stamped record. Send your request to the DPO or privacy contact address. Under GDPR, the organization has one calendar month to respond to your request. This can be extended by a further two months if the request is complex or you have made multiple requests.

What to Do When a Company Ignores Your Request

If the one-month deadline passes without a response, or if you receive an inadequate reply, don't give up.

First, send a polite follow-up. Reference your original request, the date it was sent, and the one-month deadline stipulated in Article 12 of the GDPR. State that you expect a prompt and complete response.

If that doesn't work, your next step is to lodge a complaint with the relevant Data Protection Authority (DPA). Every country in the EU/EEA has its own DPA (e.g., the CNIL in France, the AEPD in Spain, the Garante in Italy). You should complain to the DPA in the country where you live, where you work, or where the alleged infringement took place.

Your complaint should include details of your request, the company's response (or lack thereof), and any correspondence. The DPA has the power to investigate your complaint, order the company to comply, and issue substantial fines. This process is your ultimate recourse when your rights are ignored. While you're thinking about your data, it's also wise to know [what to do after your data is exposed in a breach](/posts/what-to-do-after-a-data-breach), as this is another common way your information can be compromised.

Beyond Individual Requests: GDPR's Broader Impact

While the individual rights are the most visible part of GDPR, the regulation has had a much wider effect on how companies approach privacy. It established the principles of "privacy by design" and "privacy by default," meaning organizations must build data protection into their systems from the ground up rather than treating it as an afterthought.

One of the most significant changes was the mandatory breach notification rule. Under GDPR, companies must report certain types of data breaches to the relevant DPA within 72 hours of becoming aware of them. If the breach is likely to result in a high risk to the rights and freedoms of individuals, they must also inform those affected directly and without undue delay.

Taking Back Control of Your Data

Your GDPR rights are not just theoretical principles; they are practical tools you can use to hold organizations accountable and manage your personal information in an increasingly data-driven world. Submitting a DSAR to a company you interact with frequently can be an eye-opening experience, revealing the sheer volume of data collected about you.

Exercising your right to erasure or objecting to marketing can significantly reduce your digital footprint and unwanted communications. These actions, when taken collectively by many individuals, create a powerful incentive for companies to adopt more privacy-respecting practices.

While sending individual requests is effective, it can also be time-consuming. For those looking to manage their data more broadly, particularly with data brokers who buy and sell personal information, it's worth comparing the benefits of [DIY opt-outs vs a data removal service](/posts/diy-opt-out-vs-data-removal-service). These services automate the process of sending out removal requests on your behalf, helping you scale your efforts to reclaim your privacy.

Read next