GDPR Data Subject Rights Explained: All Eight Rights (2026)
Independently fact-checked against primary sources (last audited September 11, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 11, 2026. · 21 primary sources cited on this page. How we verify our legal content

Under Chapter III of Regulation (EU) 2016/679, the GDPR grants eight enforceable rights to individuals in the European Union: the right to be informed, access, rectification, erasure, restriction of processing, data portability, objection, and rights related to automated decision-making. Those rights sit in Chapter III, which runs from Article 12 to Article 23. Organisations must respond to any request within one calendar month.
The GDPR gives every individual in the European Union enforceable rights over their own personal data. These rights appear in Chapter III of Regulation (EU) 2016/679, which runs from Article 12 to Article 23. They cover the full lifecycle of data: from the moment an organisation first collects it (the right to be informed) through accessing, correcting, deleting, moving, and challenging its use.
Understanding these rights matters in both directions. Individuals need to know what they can demand and how to demand it. Organisations need to know what they are obliged to do, within what timelines, and where exemptions apply.
This article explains all eight rights in detail, covers how data subject access requests (DSARs) work in practice, notes the key CJEU rulings that have shaped interpretation, and addresses the most significant recent developments including the EDPB's coordinated enforcement reports and the Digital Omnibus proposal.
For the broader regulatory framework, see What Is GDPR. For compliance implementation steps, see the GDPR Compliance Checklist. For consent rules in detail, see GDPR Consent Requirements.
Jurisdiction scope: This article addresses data subject rights under EU Regulation (EU) 2016/679 (GDPR). It does not cover UK GDPR (which diverged from EU GDPR after Brexit), or Member State-specific derogations that may apply in particular sectors. For UK-specific rights, consult the ICO.
This article provides general legal information only. It is not legal advice. Consult a qualified data protection lawyer or privacy professional for advice specific to your situation.
The Eight GDPR Data Subject Rights at a Glance
The GDPR's Chapter III establishes eight distinct rights. Article 12 provides the overarching procedural framework: responses must be free of charge (in the first instance), delivered in a concise, transparent, intelligible and easily accessible form, using clear and plain language. The one-month default response deadline runs across all rights.
| Right | Primary Article | Core Content |
|---|---|---|
| Right to be informed | Articles 13 and 14 | Receive privacy information at the point of data collection |
| Right of access | Article 15 | Obtain confirmation and a copy of personal data held |
| Right to rectification | Article 16 | Have inaccurate or incomplete data corrected |
| Right to erasure | Article 17 | Request deletion of personal data |
| Right to restriction of processing | Article 18 | Limit use of data without deleting it |
| Right to data portability | Article 20 | Receive data in a structured, machine-readable format |
| Right to object | Article 21 | Challenge processing based on legitimate interests or direct marketing |
| Rights related to automated decision-making | Article 22 | Challenge decisions made solely by automated systems |

The Right to Be Informed (Articles 13 and 14)
The right to be informed is the foundation on which all other GDPR rights rest. It requires organisations to provide individuals with clear information about what personal data is being collected and how it will be used, before or at the point of collection. Without transparency, individuals cannot meaningfully exercise any of the other seven rights.
Article 13 governs situations where the organisation collects personal data directly from the individual, for example via a web form, app registration, or written application. Article 14 governs situations where personal data is obtained from a third party rather than from the individual themselves.
What Organisations Must Disclose
Under both Articles 13 and 14, organisations must provide at minimum:
- The identity and contact details of the data controller, and of the data protection officer if one is appointed
- The purposes of processing and the legal basis for each purpose
- Where processing relies on legitimate interests, the specific interests pursued
- Any recipients or categories of recipients
- Details of transfers to third countries and the applicable safeguards
- The retention period, or criteria used to determine it
- The existence of all applicable data subject rights and how to exercise them
- The right to withdraw consent, where consent is the legal basis
- The right to lodge a complaint with a supervisory authority
- Under Article 14 only: the source from which the personal data originates
Timing Requirements
For direct collection under Article 13, privacy information must be provided at the time the data is obtained. For indirect collection under Article 14, the deadline is within one month of obtaining the data, or at first contact with the individual if earlier, or at the point of disclosure to another recipient if earlier still.
The CEF 2026 Enforcement Focus
The EDPB selected Articles 12, 13 and 14 as the topic for its 2026 Coordinated Enforcement Framework (CEF) action, launched on 19 March 2026. Twenty-five data protection authorities across Europe are taking part. In the EDPB's words, the right to be informed "is a core element of transparency and ensures that individuals have more control over their data." Enforcement outcomes are expected to generate findings on whether privacy notices in practice meet the GDPR standard.
Right of Access (Article 15)
The right of access is the most commonly exercised GDPR right and the most litigated. Article 15 allows individuals to obtain confirmation of whether an organisation processes their personal data and, if so, to receive a copy of that data together with prescribed supplementary information.
What the Right Covers
Under Article 15(1), the data subject is entitled to:
- Confirmation that processing is occurring
- A copy of the personal data itself
- The purposes of processing
- The categories of personal data concerned
- The recipients or categories of recipients, including those in third countries
- The planned retention period, or criteria used to determine it
- The existence of the rights to rectification, erasure, restriction and objection
- The right to lodge a complaint with a supervisory authority
- Where data was not collected from the individual, information about its source
- Whether automated decision-making including profiling is used, and meaningful information about the logic involved
CJEU Case Law on Article 15
The CJEU has substantially narrowed the discretion controllers previously exercised in responding to access requests.
In Case C-154/21, RW v Österreichische Post AG (judgment of 12 January 2023), the Court held that Article 15(1)(c) requires controllers to disclose the actual identity of recipients to whom personal data has been or will be disclosed. The ruling leaves two alternative escape routes, not one. A controller may fall back on categories of recipient where it is impossible to identify those recipients, or where it demonstrates that the access request is manifestly unfounded or excessive within the meaning of Article 12(5). Outside those two situations, vague generic category descriptions no longer satisfy the article.
In Case C-487/21, F.F. v Österreichische Datenschutzbehörde and CRIF GmbH (judgment of 4 May 2023), the Court held that the right to obtain a "copy" under Article 15(3) means the data subject must receive a faithful and intelligible reproduction of all personal data held. That right can extend to copies of extracts from documents, entire documents, or database extracts where necessary to give the individual access to their data in a comprehensible form. Controllers cannot provide a curated or summarised selection.
In Case C-307/22, FT v DW (judgment of 26 October 2023), the Court held that the controller must supply the first copy of a person's personal data free of charge even where the reason for the request has nothing to do with data protection, and that national law cannot make the individual bear the cost of that first copy in order to protect the controller's economic interests.
In Case C-203/22, CK v Magistrat der Stadt Wien (Dun & Bradstreet Austria intervening, judgment of 27 February 2025), the Court read Article 15(1)(h) as entitling the individual to an explanation of "the procedure and principles actually applied" to produce a specific automated result, such as a credit profile, given concisely and intelligibly. A claimed trade secret does not defeat that right. The controller must instead hand the allegedly protected material to the supervisory authority or the court, which balances the competing interests and decides how far access goes.
The EDPB Guidelines 01/2022 on the Right of Access (version 2.1 of 30 May 2024, first adopted 28 March 2023) further confirm that controllers cannot limit replies to data they consider "relevant" or "important." Access must cover all personal data held.
CEF 2024 Findings on Right of Access
The EDPB published its CEF 2024 report on the right of access in January 2025, following a coordinated action in which 30 supervisory authorities across the EEA took part and 1,185 controllers answered the questionnaire. Recurring challenges included: a lack of documented internal procedures for handling requests; a lack of awareness about how far the access right actually extends; and barriers to exercising the right, including blanket demands for identity documents on every request.

Right to Rectification (Article 16)
Article 16 gives individuals the right to have inaccurate personal data corrected without undue delay. Individuals can also request that incomplete data be completed, including by providing a supplementary statement.
Scope and Practical Examples
This right applies whenever factual personal data held by an organisation is incorrect or incomplete. Common examples include misspelled names, incorrect addresses, outdated phone numbers, and employment records with wrong dates. The right does not apply to assessments or opinions (a performance review rating is an opinion, not a factual inaccuracy), though individuals may request that a supplementary statement be attached to disputed subjective assessments.
Third-Party Notification Obligation
When a controller rectifies data, Article 19 of the GDPR requires notification to each recipient to whom the data was previously disclosed, unless doing so proves impossible or involves disproportionate effort. The controller must also inform the individual about those recipients if asked.
Right to Erasure / Right to Be Forgotten (Article 17)
Article 17 allows individuals to request deletion of their personal data. The right to erasure, also called the "right to be forgotten," is one of the GDPR's most prominent provisions. It is not absolute: Article 17(3) sets out the situations in which the right does not apply.
Grounds for Erasure
Erasure is required under Article 17(1) when:
- The data is no longer necessary for the purpose for which it was collected or processed
- The individual withdraws consent and no other legal basis applies
- The individual objects under Article 21 and there are no overriding legitimate grounds for the controller
- The data was unlawfully processed
- Erasure is required to comply with an EU or Member State legal obligation
- The data was collected from a child in connection with information society services (Article 8)
Grounds for Refusing Erasure
Under Article 17(3), controllers may refuse erasure when processing is necessary for:
- Exercising the right to freedom of expression and information
- Compliance with a legal obligation under Union or Member State law (for example, statutory tax record retention), or performance of a task carried out in the public interest or in the exercise of official authority vested in the controller
- Public health purposes in the public interest (Article 9(2)(h) and (i))
- Archiving in the public interest, scientific research, or statistical purposes where erasure would seriously impair the objective
- Establishing, exercising, or defending legal claims
Watch out: The legal claims exemption is frequently misapplied. Organisations sometimes invoke it pre-emptively to avoid erasure obligations. The exemption requires that legal proceedings are actually pending, threatened, or reasonably anticipated, not that the controller might theoretically face a future claim.
Search Engine Erasure
The right to erasure has particular significance for search engines. Following the Google Spain ruling (Case C-131/12, 2014), individuals may request that search engines delist results about them. The EDPB Guidelines 5/2019 set out the criteria DPAs apply when evaluating delisting requests.
CEF 2025: Challenges in Implementing the Right to Erasure
The EDPB published its CEF 2025 report on the right to erasure in February 2026. Thirty-two DPAs participated across 2025, with nine initiating formal investigations and 23 conducting fact-finding. Seven recurring implementation challenges were identified:
- Absence of a documented and updated internal procedure for handling erasure requests
- Absent or inadequate training of staff members
- Insufficient information provided to data subjects
- Misuse of, and legal uncertainty about, the exceptions used to deny erasure requests
- Difficulties in defining and implementing data retention periods
- Deletion of personal data in the context of back-ups
- Difficulties with anonymisation used to respond to erasure requests
Right to Restriction of Processing (Article 18)
Article 18 allows individuals to ask an organisation to retain their data but stop actively using it. When restriction is in place, the controller may store the data but cannot process it unless the individual consents, or the processing is necessary for legal claims, protecting another person's rights, or important public interest reasons.
When Restriction Applies
Individuals may request restriction in four circumstances:
- They contest the accuracy of the data, and restriction applies while the controller verifies accuracy
- The processing is unlawful but the individual prefers restriction over erasure
- The controller no longer needs the data but the individual needs it to establish, exercise, or defend legal claims
- The individual has objected under Article 21, and the outcome of the balancing exercise is pending
Practical Effect
Restriction is effectively a "pause" on active processing. The controller must inform the individual before lifting any restriction. This right serves as a middle ground between full erasure and unrestricted processing, and is particularly useful in contested factual disputes or during litigation.
Right to Data Portability (Article 20)
Article 20 gives individuals the right to receive personal data they provided to a controller in a structured, commonly used, and machine-readable format, and to have that data transmitted directly to another controller where technically feasible. The right is designed to reduce vendor lock-in and support switching between competing services.
Conditions for Portability
The right to data portability applies only when two conditions are both met:
- Processing is based on consent (Article 6(1)(a) or Article 9(2)(a)) or on a contract with the individual (Article 6(1)(b))
- Processing is carried out by automated means
Data processed under legitimate interests, legal obligation, or public interest does not attract the portability right.
What Data Is Covered
Portability covers data the individual "provided to" the controller. This includes data actively submitted (form entries, uploaded documents, profile information) and data generated through use of a service (transaction history, usage logs, location data from app use). It does not include inferred or derived data such as risk scores, customer segments, or algorithmic profiling outputs, as these are generated by the controller rather than provided by the individual.
Format Requirements
The data must be provided in a structured, commonly used, and machine-readable format. CSV, JSON, and XML are widely accepted formats. Where technically feasible and at the individual's request, the controller must transmit the data directly to another named controller.
Right to Object (Article 21)
Article 21 allows individuals to object to processing in two distinct scenarios with markedly different legal consequences.
Objection to Legitimate Interest or Public Interest Processing
When processing is based on legitimate interests (Article 6(1)(f)) or public interest (Article 6(1)(e)), individuals may object on "grounds relating to their particular situation." The controller must stop processing unless it can demonstrate compelling legitimate grounds that override the individual's interests, rights, and freedoms, or the processing is necessary for legal claims.
The burden rests with the controller to conduct a genuine balancing exercise specific to the individual's stated circumstances, not a generic assertion that its interests are weighty.
Absolute Right to Object to Direct Marketing
The right to object to processing for direct marketing is unconditional. Article 21(2) and (3) state that when an individual objects to processing for direct marketing, the controller must stop immediately, for that purpose and for any related profiling. No balancing test applies and no legitimate grounds can override it.
Objection to Research Processing
Individuals may also object to processing for scientific, historical, or statistical research purposes on grounds relating to their particular situation, unless the processing is necessary for a task in the public interest.

Rights Related to Automated Decision-Making and Profiling (Article 22)
Article 22 provides that individuals have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significant effects on them.
The Core Protection
Two conditions must both be present for Article 22 to be engaged:
- The decision is based solely on automated processing (no meaningful human involvement)
- The decision produces a legal effect (denial of credit, visa, or employment) or a similarly significant effect (denial of insurance, exclusion from services, severe financial or social consequences)
Profiling is not a third condition. Article 22(1) covers a decision "based solely on automated processing, including profiling," and those last two words are an inclusive example, not a requirement. A solely automated decision that involves no profiling at all is still caught.
The CJEU applied Article 22(1) broadly in Case C-634/21, OQ v Land Hessen (SCHUFA Holding intervening, judgment of 7 December 2023). The automated calculation by a credit information agency of a probability value about a person's ability to meet future payments is itself automated individual decision-making, where a third party that receives the value draws strongly on it to establish, implement, or terminate a contract with that person. The scoring agency is inside Article 22, not only the lender that acts on the score.
Permitted Exceptions
Article 22(2) permits solely automated decisions with legal or similarly significant effects in three circumstances:
- The decision is necessary for entering into or performing a contract with the individual
- It is authorised by EU or Member State law with suitable safeguards
- It is based on the individual's explicit consent
Mandatory Safeguards
Article 22(3) attaches three minimum safeguards to two of the three exceptions, not to all of them. It applies "in the cases referred to in points (a) and (c) of paragraph 2," meaning the contract exception and the explicit-consent exception. Where the decision rests on either of those, the individual must have the right to:
- Obtain human intervention on the part of the controller
- Express their point of view
- Contest the decision
Where the decision is instead authorised by Union or Member State law under Article 22(2)(b), Article 22(3) does not apply. The authorising law must itself lay down suitable measures to safeguard the individual's rights, freedoms, and legitimate interests, and those measures may differ from the three listed above. Anyone facing a statutory automated decision should check the enabling law rather than assume a right to human review.
The controller must also provide meaningful information about the logic involved in the automated system and the significance and envisaged consequences of the decision for the individual. Case C-203/22, discussed above, sets the standard for what that information has to contain.
Interaction with the EU AI Act
The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024, and its general date of application is 2 August 2026. Its high-risk layer no longer lands on that date. Regulation (EU) 2026/1744, the Digital Omnibus on AI of 8 July 2026, amended Article 113 of the AI Act and postponed Chapter III, Sections 1, 2 and 3 (with the exception of Article 6(5)), which carry the requirements and obligations for high-risk systems.
| High-risk category | Obligations now apply from |
|---|---|
| Article 6(2) and Annex III systems: credit scoring, employment decisions, access to essential services, migration | 2 December 2027 |
| Article 6(1) and Annex I systems: AI as a safety component of a product already covered by EU product legislation | 2 August 2028 |
The AI Act's transparency duties for providers and deployers in Article 50(1) to (6) are unchanged and still apply from 2 August 2026 (the Omnibus amends only Article 50(7), on codes of practice). A new Article 111(4) gives providers whose generative systems were already on the market before that date until 2 December 2026 to comply with the content-marking obligation in Article 50(2).
Article 22 of the GDPR is untouched by any of this and applies in full today. A credit-scoring or employment decision taken solely by automated means is governed by Article 22 now, whether or not the AI Act's high-risk obligations have begun to bind the system that produced it. Where both regimes eventually apply, both sets of obligations must be satisfied, and the EDPB and the EU AI Office are expected to issue coordinated guidance on the overlap.
How Data Subject Access Requests (DSARs) Work in Practice
Article 12 provides the procedural framework that governs responses to all data subject rights requests.
Making a Request
Individuals do not need to use specific legal language or reference any GDPR article. Any clear communication that identifies what the individual wants is sufficient. Requests may be made by email, web form, letter, telephone, or any other channel the controller operates.
The One-Month Deadline
Controllers must respond within one month of receipt (Article 12(3)). The period is counted under Regulation (EEC, Euratom) No 1182/71, so it expires on the same date of the following month. The EDPB Guidelines 01/2022 give the worked example at paragraph 160: a request received on 5 March must be answered by 5 April at the latest. Where the following month has no matching date, the deadline is the last day of that month, so a request received on 31 August is due by 30 September. If the last day falls on a weekend or public holiday, the controller has until the next working day.
Extensions
For complex requests, or where an individual has submitted numerous requests simultaneously, the deadline may be extended by a further two months (three months total). To use the extension, the controller must notify the individual within the first calendar month and explain the reason for the extension. Failure to send the extension notice within the first month means the controller cannot rely on the extension.
Fees
Two separate fee rules apply, and they are often run together.
Under Article 12(5), information under Articles 13 and 14 and any communication or action taken under Articles 15 to 22 and 34 must be provided free of charge. A reasonable administrative fee, or an outright refusal, is permitted only where the request is manifestly unfounded or excessive, in particular because it is repetitive. The controller bears the burden of demonstrating that threshold is met. The bar is high; a routine request from an individual who has not previously made the same request is not excessive.
Under Article 15(3), the controller must provide a copy of the personal data undergoing processing, and may charge a reasonable fee based on administrative costs for any further copies the individual asks for. That second fee needs no finding of abuse. The CJEU confirmed the shape of the rule in Case C-307/22 (26 October 2023): the first copy is free even where the reason for the request has nothing to do with data protection, which is what leaves room for a charge on the copies after it.
Identity Verification
Controllers may request information to verify the identity of the requester, but only where genuine doubt exists. Verification measures must be proportionate. Controllers may not impose disproportionate verification hurdles as a deterrent. For online accounts, asking the user to authenticate through existing account credentials is generally sufficient. Requesting passport copies or government ID is typically disproportionate unless the data at issue is particularly sensitive or the circumstances specifically warrant it.
When Requests Can Be Refused
Controllers may decline to act on requests that are manifestly unfounded or excessive. If a request is refused, the controller must inform the individual of:
- The reasons for the refusal
- Their right to lodge a complaint with a supervisory authority
- Their right to seek a judicial remedy
The controller cannot ignore the request. Even a refusal must be communicated within the one-month deadline.
Filing a Complaint
Every EU Member State has a national data protection authority where individuals may file complaints free of charge. The EDPB maintains a full list of all national supervisory authorities with their contact details. Prominent authorities include the CNIL (France), the BfDI (Germany), the DPC (Ireland, which supervises many US-headquartered tech companies with EU bases in Ireland), and the APD/GBA (Belgium). Our guide walks through filing a complaint with Ireland's Data Protection Commission.
Cross-border complaints get a uniform procedure in 2027. Regulation (EU) 2025/2518 of 26 November 2025, published in the Official Journal on 12 December 2025, lays down additional procedural rules for enforcing the GDPR and applies from 2 April 2027. It fixes what a cross-border complaint must contain to be admissible: your name and contact details, enough information to identify the controller or processor, and a description of the alleged infringement. Nothing beyond that may be demanded as a condition of admissibility, and an authority that finds the complaint incomplete must declare it inadmissible within two weeks and tell you why. Until that date, national procedural rules govern how your complaint is handled.
Exemptions and Limits on Data Subject Rights
Data subject rights are not unlimited. Article 23 is the operative provision. Union or Member State law may restrict, by legislative measure, the scope of the obligations and rights in Articles 12 to 22 and Article 34, as well as Article 5 so far as it corresponds to them, provided the restriction respects the essence of the fundamental rights involved and is a necessary and proportionate measure in a democratic society to safeguard:
- National security, public security, and defence
- Prevention, investigation, and prosecution of criminal offences
- Other important public interest objectives of the EU or a Member State, including public health, social protection, and taxation
- Protection of judicial independence
- Enforcement of civil law claims
- The rights and freedoms of other individuals
Recital 73 covers the same ground as background, but a recital has no independent legal force. A national derogation has to be traced to Article 23 and to the Member State law that actually enacts it.
Organisations operating across multiple EU Member States must identify whether any applicable Member State derogations apply to their processing in each jurisdiction.
Recent Developments (2024 to 2026)
EDPB Coordinated Enforcement: Systemic Gaps Across All Rights
The EDPB's annual Coordinated Enforcement Framework actions have now covered the right of access (2024) and the right to erasure (2025). The clearest overlap between the two reports is the absence of documented, up-to-date internal procedures for handling rights requests, which each names as a distinct finding. Beyond that, the two diverge. The 2024 access report points to uncertainty about how far access extends, inconsistent retention periods, and barriers such as blanket demands for identity documents. The 2025 erasure report points to inadequate staff training, misuse of the Article 17(3) exceptions, erasure in back-ups, and anonymisation used in place of deletion.
The 2026 action focuses on Articles 12 to 14 (transparency and information). Given the pattern of previous years, the EDPB anticipates systemic gaps in the quality and accessibility of privacy notices. The 25 participating DPAs share and discuss their findings during the second half of 2026, after which a consolidated report is drafted and submitted to the EDPB for adoption. On the timing of the two previous cycles, where the 2024 access report was adopted in January 2025 and the 2025 erasure report in February 2026, that consolidated report should be expected in 2027.
CJEU: Narrowing Controllers' Discretion
The CJEU's access jurisprudence has consistently narrowed controllers' room to limit compliance. Case C-154/21 (January 2023) requires disclosure of actual recipient identities unless identification is impossible or the request is manifestly unfounded or excessive. Case C-487/21 (May 2023) requires a full and faithful copy of all personal data. Subject access responses that were common practice until 2022 (summary tables, category-only descriptions, curated selections) are now non-compliant.
The line has continued past 2023. Case C-307/22 (26 October 2023) confirmed the first copy is free whatever the requester's motive. Case C-634/21, SCHUFA Holding (7 December 2023) brought credit-scoring agencies themselves inside Article 22(1) where a lender draws strongly on the score. Case C-203/22, Dun & Bradstreet Austria (27 February 2025) held that "meaningful information about the logic involved" means the procedure and principles actually applied, and that a trade-secret claim shifts the question to a supervisory authority or court rather than ending it.
The Digital Omnibus Package (November 2025)
The European Commission published its Digital Omnibus Package on 19 November 2025. It carried two separate legislative proposals, and they have since gone in different directions.
The AI half, COM(2025) 836 (procedure 2025/0359(COD)), has been adopted. It is now Regulation (EU) 2026/1744 of 8 July 2026, which postponed the AI Act's high-risk obligations as set out earlier in this article.
The data half, COM(2025) 837 (procedure 2025/0360(COD)), proposes targeted GDPR amendments and is still only a proposal. The items that matter most for data subject rights:
- A replacement of Article 22(1) and (2). The provision would flip from a prohibition with exceptions ("The data subject shall have the right not to be subject to a decision based solely on automated processing") into a permission: such a decision "may be based solely on automated processing, including profiling, only where" one of the three grounds applies. The contract ground would also gain the words "regardless of whether the decision could be taken otherwise than by solely automated means," which removes the necessity argument controllers have to meet today.
- A new ground in Article 12(5) allowing a controller to refuse or charge for an access request where the individual "abuses the rights conferred by this regulation for purposes other than the protection of their data." This targets scenarios such as employment litigation where DSARs are used instrumentally rather than for genuine privacy protection.
- A narrowing of the Article 13 transparency duty where there are reasonable grounds to assume the individual already has the information.
- A new Article 88c providing that processing personal data in the context of developing and operating an AI system or AI model "may be pursued for legitimate interests within the meaning of Article 6(1)(f)," subject to safeguards. An unconditional right to object appears there as one of the listed safeguards attached to that new legitimate-interest ground. It is not a free-standing new right, and Article 21 itself would not be amended. A companion Article 9(2)(k) would add an AI-development ground for special categories of data, with a new Article 9(5) requiring controllers to avoid collecting such data and to remove it where it turns up.
- A relaxation of the Article 33 breach-notification deadline from 72 to 96 hours, which matters for our 72-hour rule guide.
These remain proposals. As of 10 September 2026 the European Parliament's file records the stage as "awaiting committee decision": joint ITRE and LIBE rapporteurs were appointed on 25 February 2026, a committee draft report was published on 22 June 2026, and committee amendments were tabled on 27 July 2026. Parliament has not adopted a first-reading position, so interinstitutional negotiations have not begun. The current GDPR rights described in this article remain fully in force and unchanged until any amending regulation is published in the Official Journal.
More GDPR Guides
- What Is GDPR for a comprehensive overview of the regulation and its legal basis
- GDPR Consent Requirements for valid consent standards and how consent interacts with data subject rights
- GDPR Compliance Checklist for a step-by-step compliance implementation guide
- GDPR Fines and Penalties for enforcement data and the consequences of non-compliance
- GDPR Breach Notification 72-Hour Rule for breach reporting obligations
- EU Data Privacy Laws for the complete EU data protection overview
Disclaimer
This article provides general legal information about data subject rights under Regulation (EU) 2016/679 (GDPR). It covers EU GDPR only and does not address UK GDPR or Member State-specific derogations. The information was verified as of 10 September 2026. The GDPR is a living instrument: supervisory authority guidance, CJEU rulings, and enforcement decisions continually refine how its provisions are interpreted. This article is not a substitute for legal advice. Consult a qualified data protection lawyer or privacy professional licensed in your jurisdiction for advice specific to your situation.
About the Author
[PLACEHOLDER: author roster pending]
Authorities Cited
- Regulation (EU) 2016/679 (GDPR): Full Official Text. https://eur-lex.europa.eu/eli/reg/2016/679/oj
- GDPR Article 12: Transparent information, communication and modalities. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679
- EDPB Guidelines 01/2022 on data subject rights, Right of Access, version 2.1 (30 May 2024; first adopted 28 March 2023). https://www.edpb.europa.eu/system/files/2023-04/edpb_guidelines_202201_data_subject_rights_access_v2_en.pdf
- EDPB Guidelines 5/2019 on the Right to Be Forgotten in Search Engines. https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_201905_rtbfsearchengines_afterpublicconsultation_en.pdf
- CJEU Case C-154/21, RW v Österreichische Post AG, judgment of 12 January 2023. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:62021CJ0154
- CJEU Case C-487/21, F.F. v Österreichische Datenschutzbehörde and CRIF GmbH, judgment of 4 May 2023. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:62021CJ0487
- EDPB: Identifies challenges hindering full implementation of the right to erasure (February 2026). https://www.edpb.europa.eu/news/news/2026/edpb-identifies-challenges-hindering-full-implementation-right-erasure_en
- EDPB CEF Report 2025: Implementation of the Right to Erasure. https://www.edpb.europa.eu/system/files/2026-02/edpb_cef-report_2025_right-to-erasure_en.pdf
- EDPB: CEF 2026 launch: coordinated enforcement on transparency and information obligations. https://www.edpb.europa.eu/news/news/2026/cef-2026-edpb-launches-coordinated-enforcement-action-transparency-and-information_en
- EDPB: CEF 2024: challenges to full implementation of the right of access (January 2025). https://www.edpb.europa.eu/news/news/2025/cef-2024-edpb-identifies-challenges-full-implementation-right-access_en
- European Commission: Information for Individuals on GDPR Rights. https://commission.europa.eu/law/law-topic/data-protection/information-individuals_en
- European Commission: Dealing with Requests from Individuals Exercising Their Data Protection Rights. https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/dealing-requests-individuals_en
- EDPB: National Supervisory Authorities (Members). https://edpb.europa.eu/about-edpb/about-edpb/members_en
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), 8 July 2026, amending Article 113 of the AI Act. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32026R1744
- Regulation (EU) 2025/2518 on additional procedural rules for enforcing the GDPR, 26 November 2025. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32025R2518
- CJEU Case C-307/22, FT v DW, judgment of 26 October 2023. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:62022CJ0307
- CJEU Case C-634/21, OQ v Land Hessen (SCHUFA Holding), judgment of 7 December 2023. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:62021CJ0634
- CJEU Case C-203/22, CK v Magistrat der Stadt Wien (Dun & Bradstreet Austria), judgment of 27 February 2025. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:62022CJ0203
- European Commission proposal COM(2025) 837 final (Digital Omnibus), 19 November 2025. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:52025PC0837
- European Parliament Legislative Observatory, procedure file 2025/0360(COD). https://oeil.secure.europarl.europa.eu/oeil/en/procedure-file?reference=2025/0360(COD)
- EDPB CEF Report 2024: Implementation of the Right of Access (adopted 16 January 2025). https://www.edpb.europa.eu/system/files/documents/2025-01/edpb_cef-report-2024_20250116_rightofaccess_en.pdf
Last updated: 10 September 2026. GDPR provisions cited reflect Regulation (EU) 2016/679 as in force on 10 September 2026. The GDPR half of the Digital Omnibus (COM(2025) 837) is still before the European Parliament's committees and has not amended the GDPR.
Frequently Asked Questions
What are the eight GDPR data subject rights?
The eight rights under GDPR Chapter III are: (1) the right to be informed (Articles 13 and 14), (2) the right of access (Article 15), (3) the right to rectification (Article 16), (4) the right to erasure, also called the right to be forgotten (Article 17), (5) the right to restriction of processing (Article 18), (6) the right to data portability (Article 20), (7) the right to object (Article 21), and (8) rights related to automated decision-making and profiling (Article 22). Article 12 governs the procedural obligations that apply across all rights.
How do I make a GDPR data subject access request?
Contact the organisation that holds your data through any available channel: email, letter, web form, or telephone. Clearly state that you want to access your personal data. You do not need to cite Article 15 or use the phrase 'subject access request.' The organisation must respond within one calendar month and provide the first copy free of charge. Keep a record of your request and when you sent it. If the organisation does not respond within one month, or refuses without adequate explanation, file a complaint with your national data protection authority.
Can an organisation charge a fee for a DSAR?
The first copy of your personal data must be provided free of charge, and the CJEU confirmed in Case C-307/22 (26 October 2023) that this holds even where your reason for asking has nothing to do with data protection. Two separate fee rules then apply. Under Article 12(5), a reasonable administrative fee may be charged, or the request refused, where the request is manifestly unfounded or excessive, in particular where requests are repetitive; the controller must demonstrate that threshold is met and the bar is high. Under Article 15(3), a reasonable fee based on administrative costs may be charged for any further copies you request, and that fee needs no finding of abuse.
Is the right to erasure absolute under the GDPR?
No. Article 17(3) GDPR sets out five circumstances, points (a) to (e), in which the right to erasure does not apply: where processing is necessary for exercising freedom of expression and information; for compliance with a legal obligation under Union or Member State law or for the performance of a task carried out in the public interest or in the exercise of official authority; for public health purposes in the public interest; for archiving in the public interest, scientific or historical research, or statistical purposes where erasure would seriously impair the objective; or for establishing, exercising, or defending legal claims. Organisations must assess each request against these exemptions individually.
What is the difference between erasure and restriction of processing?
The right to erasure (Article 17) requires the organisation to delete the personal data entirely. The right to restriction of processing (Article 18) requires the organisation to stop actively using the data but allows it to continue storing it. Restriction is appropriate as an interim measure, for example when the individual contests accuracy and wants the data preserved while the controller verifies it, or when the individual needs the data retained for a legal claim.
How long does an organisation have to respond to a rights request?
One calendar month from the day the request is received: a request received on 5 March must be answered by 5 April at the latest (EDPB Guidelines 01/2022, paragraph 160). Where the following month has no matching date, the deadline is the last day of that month. For complex requests or where the same individual has submitted numerous requests, the deadline may be extended by up to two additional months (three months total). The organisation must inform the individual of the extension and the reason for it within the first calendar month. If no extension notice is sent within that period, the one-month deadline stands.
Does the right to data portability apply to all my personal data?
No. The right to data portability under Article 20 applies only when two conditions are both met: the processing is based on consent or on a contract with the individual, and the processing is carried out by automated means. It does not apply to data processed under legitimate interests, legal obligation, or public interest. It also covers only data the individual provided to the controller, not inferred or derived data such as risk scores, customer segments, or profiling outputs.
Can I challenge a decision made by an algorithm or AI system?
Yes, in certain circumstances. Article 22 GDPR gives individuals the right not to be subject to a decision based solely on automated processing, including profiling, where the decision produces a legal effect or a similarly significant effect. Profiling is an included example rather than a separate requirement, so a solely automated decision without profiling is still covered. Where the decision rests on the contract exception in Article 22(2)(a) or the explicit-consent exception in Article 22(2)(c), Article 22(3) gives you the right to obtain human intervention, express your point of view, and contest the decision. Where the decision is authorised by Union or Member State law under Article 22(2)(b), that authorising law must lay down its own safeguards, which may differ. The EU AI Act adds transparency and human-oversight obligations for high-risk AI systems, but Regulation (EU) 2026/1744 postponed those to 2 December 2027 for Annex III systems such as credit scoring and employment, and to 2 August 2028 for Annex I systems. Article 22 applies in full today regardless.
What happens if I object to direct marketing?
The right to object to direct marketing under Article 21(2) and (3) is absolute and immediate. Once you object, the organisation must stop processing your data for direct marketing purposes, including any profiling related to that marketing. No balancing test applies and no legitimate grounds can override it.
What is the Digital Omnibus and does it change my GDPR rights?
The European Commission published the Digital Omnibus Package on 19 November 2025 as two separate proposals. The AI half was adopted and is now Regulation (EU) 2026/1744 of 8 July 2026, which postponed the EU AI Act's high-risk obligations to 2 December 2027 and 2 August 2028. It changed no GDPR right. The data half, COM(2025) 837, would amend the GDPR: replacing Article 22(1) and (2) so that solely automated decisions become permitted on stated grounds rather than prohibited with exceptions, adding a ground to refuse or charge for an access request where the individual abuses the right, narrowing the Article 13 transparency duty, adding an Article 88c legitimate-interest basis for AI development with an unconditional right to object as one of its safeguards, and extending the breach-notification deadline from 72 to 96 hours. That half is still a proposal: as of 10 September 2026 the European Parliament file (2025/0360(COD)) is awaiting a committee decision, so interinstitutional negotiations have not begun. All existing GDPR data subject rights described in this article remain fully in force and unchanged until any amending regulation is published in the Official Journal of the EU.
Updates
Corrected the EU AI Act timetable to reflect Regulation (EU) 2026/1744, which moved the high-risk obligations to 2 December 2027 and 2 August 2028; restated Article 22 so that profiling is not a separate condition and the Article 22(3) safeguards attach only to the contract and explicit-consent exceptions; added the Article 15(3) fee for further copies alongside the Article 12(5) abuse fee; replaced a misattributed EDPB erasure finding with the report list actually published and corrected the 2024 access action to 30 supervisory authorities; stated the C-154/21 recipient exception disjunctively; corrected the Digital Omnibus status from trilogue to committee stage and described the proposed Article 22 rewrite; named Article 23 as the restriction provision; added the SCHUFA, Dun & Bradstreet and FT rulings and Regulation (EU) 2025/2518; and replaced two dead official links.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Expanded from 2,890 to ~4,800 words. Added full section on the right to be informed (Articles 13-14). Added CJEU case law section covering C-154/21 and C-487/21. Added Digital Omnibus November 2025 context. Added EU AI Act and Article 22 interaction. Updated enforcement section with CEF 2024 access report, CEF 2025 erasure report, and CEF 2026 transparency launch. Expanded DSAR section with identity verification and complaint filing detail. Added 10-item FAQ.
Reviewed and approved by an editor
Initial publication.
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
General Data Protection Regulation (GDPR)
Art. 12Transparent information, communication and modalities for the exercise of the rights of the data subjectIn forcecited in 14 of our articles
1. The controller shall take appropriate measures to provide any information referred to in Articles 13 and 14 and any communication under Articles 15 to 22 and 34 relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child. The information shall be provided in writing, or by other means, including, where appropriate, by electronic means. When requested by the data subject, the information may be provided orally, provided that the identity of the data subject is proven by other means. 2. The controller shall facilitate the exercise of data subject rights under Articles 15 to 22. In the cases referred to in Article 11(2), the controller shall not refuse to act on the request of the data subject for exercising his or her rights under Articles 15 to 22, unless the controller demonstrates that it is not in a position to identify the data subject. 3.
Official text (excerpt) · last checked 2026-08-12 · Read the full text in our law library · Verify at eur-lex.europa.eu
Cited in 16 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- FT v DW (Court of Justice of the European Union 2023, C-307/22)
- Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V (Court of Justice of the European Union 2024, C-757/22)
- F.F. v Österreichische Datenschutzbehörde and CRIF GmbH (Court of Justice of the European Union 2023, C-487/21)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: How to File a Data Protection Complaint (Beschwerde) with Austria's DSB, GDPR in Austria (DSGVO): How EU Law and the Datenschutzgesetz Work Together, How to Submit a Data Deletion Request (2026)
Search our record of EU legislation — GDPR, ePrivacy, AI Act and more, from EUR-Lex →
Sources and References
- Regulation (EU) 2016/679 (GDPR): Full Official Text(eur-lex.europa.eu).gov
- GDPR Article 12: Transparent information and modalities(eur-lex.europa.eu).gov
- EDPB Guidelines 01/2022 on data subject rights, Right of Access, version 2.1 (30 May 2024; first adopted 28 March 2023)(edpb.europa.eu).gov
- EDPB Guidelines 5/2019 on the Right to Be Forgotten in Search Engines(edpb.europa.eu).gov
- CJEU Case C-154/21, RW v Österreichische Post AG, 12 January 2023(eur-lex.europa.eu).gov
- CJEU Case C-487/21, F.F. v Österreichische Datenschutzbehörde and CRIF GmbH, 4 May 2023(eur-lex.europa.eu).gov
- EDPB: Challenges hindering full implementation of the right to erasure (February 2026)(edpb.europa.eu).gov
- EDPB CEF Report 2025: Implementation of the Right to Erasure(edpb.europa.eu).gov
- EDPB: CEF 2026: coordinated enforcement on transparency and information obligations(edpb.europa.eu).gov
- EDPB: CEF 2024: challenges to full implementation of the right of access (January 2025)(edpb.europa.eu).gov
- European Commission: Information for Individuals on GDPR Rights(commission.europa.eu).gov
- European Commission: Dealing with Requests from Individuals Exercising Their Data Protection Rights(commission.europa.eu).gov
- EDPB: National Supervisory Authorities (Members)(edpb.europa.eu).gov
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), 8 July 2026, amending Article 113 of the AI Act(eur-lex.europa.eu).gov
- Regulation (EU) 2025/2518 on additional procedural rules for enforcing Regulation (EU) 2016/679, 26 November 2025(eur-lex.europa.eu).gov
- CJEU Case C-307/22, FT v DW, judgment of 26 October 2023(eur-lex.europa.eu).gov
- CJEU Case C-634/21, OQ v Land Hessen (SCHUFA Holding), judgment of 7 December 2023(eur-lex.europa.eu).gov
- CJEU Case C-203/22, CK v Magistrat der Stadt Wien (Dun & Bradstreet Austria), judgment of 27 February 2025(eur-lex.europa.eu).gov
- European Commission proposal COM(2025) 837 final (Digital Omnibus), 19 November 2025(eur-lex.europa.eu).gov
- European Parliament Legislative Observatory, procedure file 2025/0360(COD)(oeil.secure.europarl.europa.eu).gov
- EDPB CEF Report 2024: Implementation of the Right of Access (adopted 16 January 2025)(edpb.europa.eu).gov