What Are Your Data Rights?

A Simple Guide to Controlling Your Personal Data

Every day, vast amounts of personal data are collected, stored, and processed, often without individuals fully appreciating the extent of data being gathered about their habits, preferences, and identity. Even when awareness exists, gaining meaningful control over how this information is used presents a significant challenge. The UK General Data Protection Regulation (UK GDPR) directly addresses this by establishing a robust legal framework designed to ensure that each individual has autonomy over their own personal data.

The UK GDPR grants individuals specific, enforceable powers known as data subject rights that serve as a legal framework to ensure transparency, accountability, and fairness whenever their personal data is processed.

Personal data is any information that can be used, on its own or combined with other details, to identify a living person. This can include, for example, names but also indirect identifiers like an employee ID number because it can be used with other data to identify the individual it refers.

This article provides an overview of each data subject right established under the UK GDPR. By examining real-world scenarios and practical examples, we illustrate the concrete application of these rights and outline how individuals can effectively exercise control over their personal data.

Right to be informed

The right to be informed requires any organisation collecting or processing personal data to proactively explain to individuals what data they hold, why they are processing it, how long they intend to retain it, and with whom it will be shared. Transparency is required whether data is collected from individuals or from other third-party sources.

Organisations generally fulfil their obligation to inform individuals about how their personal data is collected and used by creating a privacy notice, a detailed public statement that explains what personal information a company collects, why it is needed, how it is stored and protected, and who it may be shared with. A privacy notice is generally published on the organisation website and must be concise, transparent, intelligible and in an easily accessible form, using clear and plain language.

However, this transparency requirement can be fulfilled in other ways as well:

  • Just-in-time notices: relevant and focused privacy information delivered at the time organisations collect individual pieces of information about people.

  • Privacy dashboards: preference management tools that inform individuals how the organisation uses their data and allow them to manage what happens with it.

  • Contextual permissions and signs: on-screen mobile permission prompts or physical signs, such as CCTV notices at building entrances.

Regardless of how it is delivered, the information individuals receive must clearly outline:

  • Details of the organisation and how to contact them

  • The purpose and lawful basis for processing: specific reasons for collecting personal data and the legal grounds under the UK GDPR justifying its use.

  • The categories of personal data obtained: names, health information, location data etc.

  • The retention periods for the personal data: exact timeframes or clear criteria defining how long personal data will be stored.

  • The recipients of the data and details of any transfer to third countries or international organisations

  • The rights available to individuals in respect of the processing

Identifying incomplete privacy information

Scenario: You sign up for a new online gym membership. On the registration form, they collect your full name, email address, home address, and payment details. Before submitting the form, you check the gym’s Privacy Notice to see how your data will be handled, which simply states: “We collect your details to manage your membership. We may share your information with trusted partners for marketing purposes, and we store your data for as long as necessary.”

This privacy notice is not in line with the right to information under the UK GDPR as it does not clarify and detail why your data is collected, how long it will be retained, who are the third parties that will receive your data, and does not provide an overview of your rights.

Right to access personal data

Individuals can exercise the right of access through a subject access request (SAR), which allows them to obtain a copy of their personal information from an organisation, as well as supplementary information. It is a fundamental right that helps individuals understand how and why an organisation is using their information and verify that it is doing so lawfully.

When exercising this right, individuals are entitled to receive confirmation of whether or not the organisation is processing their personal information or can receive a copy of their personal information held by the organisation or supplementary information regarding the context of the processing activity.

A copy of the individual’s data or supplementary information can be provided in different ways depending on how the request was made and, on the means available to the organisation. Regardless of the method used to send the data to the individual the data, must be be transferred securely.

For instance, if a request is made electronically (e.g., by email or social media), individuals should expect to receive their information in a commonly used electronic format unless another reasonable format is requested. On the other hand, if requested verbally or by letter, the organisation may provide it in any commonly used paper or electronic format matching the individual's preference. Organisations may also fulfil a SAR by providing secure online access where individuals can view and download their information directly.

Importantly, where an individual asks for a copy of their personal data and their information is contained in documents which also include third-party data, the third-party data can be redacted but the organisation must provide sufficient context to make the response intelligible.

Exemptions

Organisations are not always required to disclose all requested information: in specific circumstances, an exemption to withhold confirmation, copies of data, or supplementary information may apply.

Common grounds where an exemption may apply include:

  • Where disclosure would prejudice the prevention, investigation, or detection of crime, the prosecution of offenders, or tax assessment.

  • Communications covered by legal professional privilege, such as email exchanges between a lawyer and their client.

  • Processing related to protecting the public against financial loss, dishonesty, corporate mismanagement, misconduct, health and safety risks at work, failure in services provided by a public body, adverse and abusing business conduct.

  • Regulatory functions relating to legal services, the health service and children’s services.

  • Judicial appointments, independence and proceedings.

  • Journalism, academia, art and literature, research and statistics, and archiving in the public interest.

If an organisation refuses a request (wholly or partly) based on an exemption, or because the request is manifestly unfounded or excessive, individuals must be informed within one calendar month. Individuals should expect a clear explanation of the refusal decision, alongside details on how to complain to the ICO or seek a judicial remedy.

Requesting a full record of your activity data

Scenario: After using the gym app for a year, you decide you want to see all the data the gym holds about you, including your workout logs, check-in timestamps, and payment history. You send an email to the gym's customer support email stating, “I would like a copy of all my personal data.”

After verifying your identity (for instance by requesting a copy of your passport), the gym must provide a copy of your records in a standard electronic format within one calendar month, free of charge. If any of the files include another member's or staff member’s details, the gym must redact the other member's personal data while still giving you access to the context concerning you.

Right to rectification

The right to rectification is designed to ensure that organisations maintain accurate records about individuals. It allows individuals to request that inaccurate personal data be corrected, or that incomplete personal data be completed, without undue delay.

Additionally, if an organisation has shared the inaccurate data with external recipients, it must also notify them of the correction, unless doing so is impossible or involves disproportionate effort.

Requesting a correction of personal details

Scenario: While checking your account details on the gym mobile app, you notice that your date of birth is recorded incorrectly. You send a brief message through the app's support chat explaining the situation and requesting the details be corrected.

Importantly, you do not need to fill out formal paperwork to make your request, however the gym is allowed to ask you to verify your identity to update the date of birth. From the moment you provide your ID, the gym has one calendar month to satisfy your request.

Right to erasure

The right to erasure, also known as the right to be forgotten, ensures that organisations do not retain individuals’ personal data when it is no longer appropriate to do so. It allows individuals to request that personal data be erased without undue delay under specific circumstances.

Individuals have the right to have their personal data erased in the following circumstances:

  • the personal data is no longer necessary for the purpose for which it was originally collected or processed;

  • the individual has withdrawn their consent for the personal data to be processed;

  • the individual objects to the processing of their personal data, and there is no overriding legitimate interest to continue this processing;

  • the individual objects to the processing of their personal data for direct marketing purposes;

  • the personal data has been processed unlawfully;

  • the organisation must erase the personal data to comply with a legal obligation; or

  • the organisation has processed the personal data to offer services to a child.

Additionally, if the organisation has shared personal data with external recipients, it must also notify them about the request to erasure, unless doing so is impossible or involves disproportionate effort.

Individuals must receive clear information from the organisation that the erasure request has been actioned and what will happen to their personal data once the request is fulfilled, including in respect of backup systems.

Exemptions

There are certain circumstances in which the right to erasure does not apply if processing the data is necessary:

  • to exercise the right of freedom of expression and information;

  • to comply with a legal obligation;

  • for the performance of a task carried out in the public interest or in the exercise of official authority;

  • for archiving purposes in the public interest, scientific research, historical research or statistical purposes where erasure is likely to render impossible or seriously impair the achievement of that processing; or

  • for the establishment, exercise or defence of legal claims.

Requesting erasure of your data

Scenario: You decide to cancel your gym app subscription and email the gym's privacy team asking them to permanently delete your account, workout history, and personal details.

Because the data is no longer necessary for the purpose for which it was originally collected (“performance of a contract”, i.e. providing your gym membership), the gym must erase your personal data from their active databases and backup systems within one calendar month.

Right to restrict processing

The right to restrict processing allows individuals to request organisations to stop processing the personal data without undue delay under specific circumstances. This means that an individual can limit the way that an organisation uses their data.

Importantly, in most cases, a restriction cannot be indefinite and can only be in place for a defined period of time.

An individual’s right to request restriction of processing applies in the following circumstances:

  • the individual has requested for the accuracy of their personal data to be checked, and the organisation is carrying out verification;

  • the personal data has been unlawfully processed;

  • when the individuals need the data to establish, exercise or defend a legal claim even though the organisation does not need it anymore; or

  • when an organisation is considering whether they have legitimate grounds to override an individual’s request to objecting of processing.

Many different activities fall under the definition of data processing. It can include the collection, structuring, dissemination and erasure of data. Therefore, individuals should expect the organisation to have different types of restrictions that are appropriate for the type of processing carried out. This can mean temporarily moving personal data to another processing system, making the data unavailable to users, or temporarily removing published data from a website.

Importantly, when a request is accepted, the organisation can no longer process the individual’s personal data, except for storage, unless:

  • the individual provides consent for it;

  • it is for the establishment, exercise or defence of legal claims;

  • it is for the protection of the rights of another person (natural or legal); or

  • it is for reasons of important public interest.

Notably, if the organisation has disclosed personal data to external recipients, they must contact each recipient and inform them of the request to restrict processing, unless this proves impossible or involves disproportionate effort.

Restricting account processing during a billing complaint

Scenario: You notice the gym app charged you in excess for your monthly subscription. You contact customer support to dispute the error, and while they investigate the issue, you ask them to temporarily pause processing your account details for billing, so you are not charged incorrectly again.

The gym must restrict the processing of your payment data for billing operations. They can continue to store your details, but they cannot process any new payments until the overcharge issue is investigated and resolved.

Right to data portability

The right to data portability is designed to allow individuals to obtain and reuse their personal data for their own purposes across different services. It gives individuals the right to receive personal data they have provided to an organisation, and to request transmission of this data directly to another organisation. In other words, it allows to individuals to request to move, copy or transfer personal data easily from one organisation’s environment to another in a safe and secure way, without affecting its usability.

The right to data portability only applies in specific circumstances:

  • when the individual provided consent or when the organisations are relying on performance of a contract as the lawful basis for processing personal data, and

  • when the processing is carried out by automated means (i.e. excluding paper files)

Importantly, the scope of this right is limited to the personal data collected directly by the individual rather than from third party sources.

Individuals can receive their personal data by either:

  • the organisation sending it directly to them; or

  • accessing an automated tool that allows them to extract the requested data.

Whether an organisation can transmit their data directly to another organisation, is assessed on a case-by-case basis. This shall be interpreted broadly and means that when something is possible, the organisations should proceed with the transmission without putting any legal, technical or financial obstacles to the request.

However, in certain circumstances, the organisations may refuse to undertake the transmission for legitimate reason if able to justify it. For example, if the transmission would adversely affect the rights and freedoms of others.

Upon request, personal data must be provided in a structured, commonly used, and machine-readable format, such as a spreadsheet, whether transferred directly to the individual or another organisation.

Obtaining your data to share it with a new provider

Scenario: You decide to change gyms and request a structured download of your workout history so you can upload it directly into your new gym’s platform.

As you provided this information yourself and it is held digitally, the gym must provide your data in a structured, machine-readable format. This allows you to transfer your workout profile directly into another digital tool without re-entering the data manually.

Right to object to processing

The right to object allows individuals to stop or prevent organisations from processing their personal data under specific circumstances. An objection may relate to all personal data held about an individual, specific information, or a particular processing purpose.

Individuals can expect organisations to inform them of this right clearly and separately from other information on their rights. Specifically, individuals must be informed of their right to object processing in the following circumstances:

  • the personal data is processed for direct marketing purposes, or

  • the lawful basis relied on for processing is:

    • public task (for the performance of a task carried out in the public interest);

    • public task (for the exercise of official authority vested in the organisation); or

    • legitimate interests.

Individuals have an absolute right to object to the processing of their personal data for direct marketing purposes at any time, including any profiling related to direct marketing. This means that once a request is made, all processing for this purpose must stop immediately and the organisation has no legal grounds to refuse compliance.

It is possible for individuals to object when an organisation uses their data to carry out a public task in the public interest, to carry out a public task to exercise official authority and to pursue the legitimate interests of the organisation or a third party.

However, in these situations, the right is not absolute. Individuals must provide specific reasons for their objection based on their particular situation. A request to object processing shall be respected unless the organisation can prove:

  • Compelling legitimate grounds to continue processing that override the interests, rights, and freedoms of the individual; or

  • That processing is necessary for the establishment, exercise, or defence of legal claims.

Importantly, organisations can rely on public interest reasons to refuse an objection but must ensure that this limitation is clearly stated in their privacy notice and that individuals are aware of it.

When organisations evaluate an objection request from an individual, greater weight is given to cases where the processing causes the individual substantial damage or distress, such as financial loss.

Where personal data is used for scientific or historical research, or statistical purposes with appropriate safeguards, the right to object is more restricted. The individual only has a right to object if the lawful basis for processing is based on:

  • public task (on the basis that it is necessary for the exercise of official authority), or

  • legitimate interests.

Importantly, an individual does not have a right to object if the lawful basis relied on for processing is performance of a task carried out in the public interest, as this trumps individuals' interests.

Where an organisation receives an objection to the processing of personal data and has no grounds to refuse, it needs to stop or not begin processing the data.

Respecting the right to object may mean that the organisation needs to erase personal data, but it may not always be the appropriate pathway. For example, when an individual objects to the processing of their data for direct marketing, the organisation can place their details onto an internal “do-not-contact” list. This ensures the organisation honours the individual’s request and avoids contacting them in the future.

Objecting to direct marketing notifications

Scenario: The gym app begins sending you weekly push notifications and emails promoting partner brands and other offers. You send an email stating that you object to your details being used for marketing purposes.

Because the objection relates to direct marketing, your right is absolute. The gym cannot refuse your request or argue that they have a legitimate interest to continue sending you direct marketing notifications. They must immediately stop sending these communications and add your details to an internal suppression list, so you are not accidentally contacted again.

Rights in relation to automated decision making and profiling

Individuals have specific protections regarding automated decision-making and profiling. These rights are designed to protect individuals when decisions are made about them solely by computer systems without human involvement, particularly when those decisions have serious impacts on their rights and freedoms.

An example of “automated-decision making” is an online tool that automatically decides whether a job application and CV can shall be rejected or not as part of the recruiting process.

Additionally, the legislation provides a right for individuals regarding profiling. Profiling is a form automated processing that uses personal data to evaluate, analyse, or predict personal aspects of an individual. This can include when organisations gather data from sources like search habits, online shopping, and social media.

Individuals are granted these specific protections because automated decision-making and profiling can lead to quicker and more consistent outcomes for organisations in various contexts, they also carry risks of bias, error, or unfair treatment.

An organisation can only subject an individual to a solely automated decision with legal or significant effects, meaning decisions that affect an individual’s rights and have a serious impactful influence on their life, if it is:

  • Necessary for a contract;

  • Authorised by law; or

  • Based on explicit consent.

An organisation can only use automated decision making with special category data if they have the explicit consent from the individual or the processing is necessary for reasons of substantial public interest.

When an organisation carries out solely automated decision-making or profiling that significantly impacts an individual, individuals can expect to be informed about the logic involved in the decision-making process, as well as its significance and envisaged consequences.

Individuals should be provided easy ways to request that a real person review the decision, express their own point of view, receive an explanation of the outcome, and challenge the decision. Additionally, the organisation shall use and implement appropriate safeguards to prevent errors, bias, and discriminatory effects.

Dealing with an automated decision

Scenario: The gym app uses an automated computer algorithm to review applications for its premium discount. The app instantly rejects your application without an employee reviewing it.

Because a computer made the decision on its own and affected your membership price, you have the right to request that a human re-examine your application to make the final decision instead.

Making a valid data subject rights request

In general, individuals may submit data subject rights requests using any form of communication, whether written, verbal, or electronic, and do not need to explicitly reference specific legislation, as organisations are obligated to recognise and process valid requests regardless of how they are framed or submitted. Organisations may refuse to comply with a request or, in some instances, charge a reasonable administrative fee if a specific legal exemption applies, or if the request is deemed manifestly unfounded or excessive.

A request is considered manifestly unfounded if it is made maliciously to harass or cause disruption, and excessive when the request unnecessarily repeats or overlaps with prior submissions.

Unless an exception applies, organisations must comply without undue delay and within one calendar month of receiving the request (or necessary proof of identity). This deadline may be extended by up to two additional months for complex or multiple requests, provided the individual is notified.

Managing your data rights with Zolteria

Knowing your data rights is important, but exercising them can be difficult when your personal information is spread across multiple organisations and every request requires separate communication, identity verification and follow-up.

Zolteria simplifies this process by providing a free secure online portal where you can manage all your data rights in one place. Your identity can be securely pre-verified, reducing the need to repeat verification when making future requests, while each request can be tracked from submission through to completion. Instead of drafting emails, searching for the right contact at each organisation and proving who you are every time, you can submit and manage your requests through a single, consistent process.

Next
Next

Mitigating Risks Related to International Data Transfers