GDPR Data Subject Rights Explained: All Eight Rights (2026)

Independently fact-checked against primary sources (last audited September 11, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 11, 2026. · 21 primary sources cited on this page. How we verify our legal content

GDPR Data Subject Rights Explained: All Eight Rights (2026)

Frequently Asked Questions

What are the eight GDPR data subject rights?

The eight rights under GDPR Chapter III are: (1) the right to be informed (Articles 13 and 14), (2) the right of access (Article 15), (3) the right to rectification (Article 16), (4) the right to erasure, also called the right to be forgotten (Article 17), (5) the right to restriction of processing (Article 18), (6) the right to data portability (Article 20), (7) the right to object (Article 21), and (8) rights related to automated decision-making and profiling (Article 22). Article 12 governs the procedural obligations that apply across all rights.

How do I make a GDPR data subject access request?

Contact the organisation that holds your data through any available channel: email, letter, web form, or telephone. Clearly state that you want to access your personal data. You do not need to cite Article 15 or use the phrase 'subject access request.' The organisation must respond within one calendar month and provide the first copy free of charge. Keep a record of your request and when you sent it. If the organisation does not respond within one month, or refuses without adequate explanation, file a complaint with your national data protection authority.

Can an organisation charge a fee for a DSAR?

The first copy of your personal data must be provided free of charge, and the CJEU confirmed in Case C-307/22 (26 October 2023) that this holds even where your reason for asking has nothing to do with data protection. Two separate fee rules then apply. Under Article 12(5), a reasonable administrative fee may be charged, or the request refused, where the request is manifestly unfounded or excessive, in particular where requests are repetitive; the controller must demonstrate that threshold is met and the bar is high. Under Article 15(3), a reasonable fee based on administrative costs may be charged for any further copies you request, and that fee needs no finding of abuse.

Is the right to erasure absolute under the GDPR?

No. Article 17(3) GDPR sets out five circumstances, points (a) to (e), in which the right to erasure does not apply: where processing is necessary for exercising freedom of expression and information; for compliance with a legal obligation under Union or Member State law or for the performance of a task carried out in the public interest or in the exercise of official authority; for public health purposes in the public interest; for archiving in the public interest, scientific or historical research, or statistical purposes where erasure would seriously impair the objective; or for establishing, exercising, or defending legal claims. Organisations must assess each request against these exemptions individually.

What is the difference between erasure and restriction of processing?

The right to erasure (Article 17) requires the organisation to delete the personal data entirely. The right to restriction of processing (Article 18) requires the organisation to stop actively using the data but allows it to continue storing it. Restriction is appropriate as an interim measure, for example when the individual contests accuracy and wants the data preserved while the controller verifies it, or when the individual needs the data retained for a legal claim.

How long does an organisation have to respond to a rights request?

One calendar month from the day the request is received: a request received on 5 March must be answered by 5 April at the latest (EDPB Guidelines 01/2022, paragraph 160). Where the following month has no matching date, the deadline is the last day of that month. For complex requests or where the same individual has submitted numerous requests, the deadline may be extended by up to two additional months (three months total). The organisation must inform the individual of the extension and the reason for it within the first calendar month. If no extension notice is sent within that period, the one-month deadline stands.

Does the right to data portability apply to all my personal data?

No. The right to data portability under Article 20 applies only when two conditions are both met: the processing is based on consent or on a contract with the individual, and the processing is carried out by automated means. It does not apply to data processed under legitimate interests, legal obligation, or public interest. It also covers only data the individual provided to the controller, not inferred or derived data such as risk scores, customer segments, or profiling outputs.

Can I challenge a decision made by an algorithm or AI system?

Yes, in certain circumstances. Article 22 GDPR gives individuals the right not to be subject to a decision based solely on automated processing, including profiling, where the decision produces a legal effect or a similarly significant effect. Profiling is an included example rather than a separate requirement, so a solely automated decision without profiling is still covered. Where the decision rests on the contract exception in Article 22(2)(a) or the explicit-consent exception in Article 22(2)(c), Article 22(3) gives you the right to obtain human intervention, express your point of view, and contest the decision. Where the decision is authorised by Union or Member State law under Article 22(2)(b), that authorising law must lay down its own safeguards, which may differ. The EU AI Act adds transparency and human-oversight obligations for high-risk AI systems, but Regulation (EU) 2026/1744 postponed those to 2 December 2027 for Annex III systems such as credit scoring and employment, and to 2 August 2028 for Annex I systems. Article 22 applies in full today regardless.

What happens if I object to direct marketing?

The right to object to direct marketing under Article 21(2) and (3) is absolute and immediate. Once you object, the organisation must stop processing your data for direct marketing purposes, including any profiling related to that marketing. No balancing test applies and no legitimate grounds can override it.

What is the Digital Omnibus and does it change my GDPR rights?

The European Commission published the Digital Omnibus Package on 19 November 2025 as two separate proposals. The AI half was adopted and is now Regulation (EU) 2026/1744 of 8 July 2026, which postponed the EU AI Act's high-risk obligations to 2 December 2027 and 2 August 2028. It changed no GDPR right. The data half, COM(2025) 837, would amend the GDPR: replacing Article 22(1) and (2) so that solely automated decisions become permitted on stated grounds rather than prohibited with exceptions, adding a ground to refuse or charge for an access request where the individual abuses the right, narrowing the Article 13 transparency duty, adding an Article 88c legitimate-interest basis for AI development with an unconditional right to object as one of its safeguards, and extending the breach-notification deadline from 72 to 96 hours. That half is still a proposal: as of 10 September 2026 the European Parliament file (2025/0360(COD)) is awaiting a committee decision, so interinstitutional negotiations have not begun. All existing GDPR data subject rights described in this article remain fully in force and unchanged until any amending regulation is published in the Official Journal of the EU.

Updates

Corrected the EU AI Act timetable to reflect Regulation (EU) 2026/1744, which moved the high-risk obligations to 2 December 2027 and 2 August 2028; restated Article 22 so that profiling is not a separate condition and the Article 22(3) safeguards attach only to the contract and explicit-consent exceptions; added the Article 15(3) fee for further copies alongside the Article 12(5) abuse fee; replaced a misattributed EDPB erasure finding with the report list actually published and corrected the 2024 access action to 30 supervisory authorities; stated the C-154/21 recipient exception disjunctively; corrected the Digital Omnibus status from trilogue to committee stage and described the proposed Article 22 rewrite; named Article 23 as the restriction provision; added the SCHUFA, Dun & Bradstreet and FT rulings and Regulation (EU) 2025/2518; and replaced two dead official links.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Expanded from 2,890 to ~4,800 words. Added full section on the right to be informed (Articles 13-14). Added CJEU case law section covering C-154/21 and C-487/21. Added Digital Omnibus November 2025 context. Added EU AI Act and Article 22 interaction. Updated enforcement section with CEF 2024 access report, CEF 2025 erasure report, and CEF 2026 transparency launch. Expanded DSAR section with identity verification and complaint filing detail. Added 10-item FAQ.

Reviewed and approved by an editor

Initial publication.

Sources and References

  1. Regulation (EU) 2016/679 (GDPR): Full Official Text(eur-lex.europa.eu).gov
  2. GDPR Article 12: Transparent information and modalities(eur-lex.europa.eu).gov
  3. EDPB Guidelines 01/2022 on data subject rights, Right of Access, version 2.1 (30 May 2024; first adopted 28 March 2023)(edpb.europa.eu).gov
  4. EDPB Guidelines 5/2019 on the Right to Be Forgotten in Search Engines(edpb.europa.eu).gov
  5. CJEU Case C-154/21, RW v Österreichische Post AG, 12 January 2023(eur-lex.europa.eu).gov
  6. CJEU Case C-487/21, F.F. v Österreichische Datenschutzbehörde and CRIF GmbH, 4 May 2023(eur-lex.europa.eu).gov
  7. EDPB: Challenges hindering full implementation of the right to erasure (February 2026)(edpb.europa.eu).gov
  8. EDPB CEF Report 2025: Implementation of the Right to Erasure(edpb.europa.eu).gov
  9. EDPB: CEF 2026: coordinated enforcement on transparency and information obligations(edpb.europa.eu).gov
  10. EDPB: CEF 2024: challenges to full implementation of the right of access (January 2025)(edpb.europa.eu).gov
  11. European Commission: Information for Individuals on GDPR Rights(commission.europa.eu).gov
  12. European Commission: Dealing with Requests from Individuals Exercising Their Data Protection Rights(commission.europa.eu).gov
  13. EDPB: National Supervisory Authorities (Members)(edpb.europa.eu).gov
  14. Regulation (EU) 2026/1744 (Digital Omnibus on AI), 8 July 2026, amending Article 113 of the AI Act(eur-lex.europa.eu).gov
  15. Regulation (EU) 2025/2518 on additional procedural rules for enforcing Regulation (EU) 2016/679, 26 November 2025(eur-lex.europa.eu).gov
  16. CJEU Case C-307/22, FT v DW, judgment of 26 October 2023(eur-lex.europa.eu).gov
  17. CJEU Case C-634/21, OQ v Land Hessen (SCHUFA Holding), judgment of 7 December 2023(eur-lex.europa.eu).gov
  18. CJEU Case C-203/22, CK v Magistrat der Stadt Wien (Dun & Bradstreet Austria), judgment of 27 February 2025(eur-lex.europa.eu).gov
  19. European Commission proposal COM(2025) 837 final (Digital Omnibus), 19 November 2025(eur-lex.europa.eu).gov
  20. European Parliament Legislative Observatory, procedure file 2025/0360(COD)(oeil.secure.europarl.europa.eu).gov
  21. EDPB CEF Report 2024: Implementation of the Right of Access (adopted 16 January 2025)(edpb.europa.eu).gov
Share: