Cross-Jurisdictional Global

Data Subject Rights Across Jurisdictions: The Complete Matrix

Every major privacy regime's individual rights compared: access, deletion, correction, portability, objection, opt-outs, and ADM rights, with the deadlines, verification standards, and exceptions that configure a global fulfillment pipeline.

Regulation

GDPR Articles 12-23, CCPA/CPRA and the state family, PIPL Chapter IV, LGPD Article 18, APPI's disclosure and cease-of-use rights, PIPEDA Principle 9, Quebec Law 25, DPDP Act Chapter III

Max Penalty

Rights violations reach the GDPR's 20 million EUR / 4% tier; state laws price per violation; the practical exposure is the complaint-to-inquiry pipeline that late or incomplete responses feed

Enforcing Authority

Each regime's regulator, with rights complaints the highest-volume enforcement trigger everywhere; the ICO reports subject access as its most-complained-about issue year after year

Official Source

www.edpb.europa.eu

Executive Summary

  • Access, deletion, and correction are now universal across every major regime; the divergence lives in the second tier (portability, objection, restriction) and the US-specific opt-out family.
  • Deadlines range from LGPD's 15 days through GDPR's one month to the US states' 45 days, each with different extension mechanics, so the clock is a per-regime parameter, not a policy.
  • Exception lists differ materially: what defeats a deletion request in California (nine enumerated exceptions) differs from what defeats it under Article 17, and applying the wrong list is a common failure.
  • Verification standards run from GDPR proportionality doctrine to the CCPA regulations' tiered rules with authorized-agent mechanics; both over- and under-verification are violations.
  • One pipeline with a jurisdiction configuration table beats parallel processes: the rights are similar enough to share machinery and different enough to need per-regime parameters.

Individual rights are where privacy law stops being architecture and becomes customer service with statutory deadlines: real people, in whatever volume the news cycle generates, exercising legal powers your systems must honor in 15 to 45 days depending on where they live. The convergence is genuine, access, deletion, and correction are now table stakes on every continent, and it is what makes one global pipeline feasible. The divergence is equally genuine, clocks, exceptions, verification tiers, appeal rights, response formats, and it is why that pipeline needs a jurisdiction configuration table rather than a single policy. Programs fail here in two ways: parallel per-regime processes that multiply cost and desynchronize, or a single GDPR-shaped process that quietly violates Brazil’s clock, California’s agent rules, and Virginia’s appeal mandate. The matrix, kept current and wired into the workflow engine, is the artifact that prevents both.

Universal rightsAccess, deletion, correction, everywhere that matters
The clocksLGPD 15d; GDPR/UK/PIPEDA/Quebec ~30d; US states 45d (+45); opt-outs 15 business days (CA)
US-only familyOpt-outs of sale/share/targeted ads/profiling + GPC honoring + statutory appeals
Danger zonesWrong exception list on refusals; over/under-verification; jurisdiction misresolution
Doctrine anchorEDPB right-of-access guidelines

Operationalizing it

Build the machine. DSAR automation details the shared pipeline this matrix configures.

Know the substrate. Data mapping and inventory determines what fulfillment can actually reach.

Handle the ADM layer. Automated decision-making opt-outs covers the profiling rights in depth.

See the legal context. The master privacy crosswalk places rights beside basis, breach, and transfer rules.

Rights requests often start with what users see on your site: check your public-facing data practices with a free scan.

Frequently Asked Questions

Which rights exist in which regimes, and where are the gaps?

The universal three: access (GDPR Article 15 with its metadata catalog; CCPA's right to know including categories sold/shared and specific pieces; PIPL Article 45; LGPD 18(II); APPI's disclosure right; PIPEDA Principle 9; Quebec; DPDP 11), deletion (Article 17's qualified erasure; CCPA deletion with service-provider propagation; PIPL 47; LGPD 18(VI); APPI's cease-of-use/erasure for violations; Quebec; DPDP 12), and correction (Article 16; now in every state law; PIPL 46; LGPD 18(III); APPI; Quebec; DPDP 12). The strong second tier, present in the GDPR family and patchily elsewhere: portability (Article 20's machine-readable export where processing rests on consent/contract and is automated; LGPD 18(V); Quebec's portability in force since September 2024; CCPA approximates it through access-format rules; PIPL 45's transfer-to-another-handler right where conditions are met; no APPI equivalent), objection (Article 21, absolute for direct marketing; LGPD's opposition right; no true US equivalent, the opt-outs play the role), restriction of processing (Article 18, largely a GDPR-family specialty), and withdrawal of consent as an operational right (universal in consent regimes, PIPL 15 requiring withdrawal as convenient as granting). The US-specific family: opt-out of sale (California's broad definition), sharing/cross-context behavioral advertising (CPRA), targeted advertising (the Virginia formulation adopted widely), profiling for decisions with legal or similarly significant effects (Colorado, Connecticut, and peers), plus limit-use-of-sensitive-PI (California's variant of the sensitive-consent gate), all with Global Privacy Control honoring mandatory in a growing state list. The automated-decision layer: GDPR Article 22's right not to be subject to solely automated significant decisions with human-intervention rights, PIPL 24's explanation-and-refusal right, LGPD 20's review right, and the CCPA ADMT rules phasing in; details in the ADM comparison. Gaps worth flagging in a matrix: no deletion right in Japan absent a violation, no general objection right in the US, no portability in several Asian regimes, and anti-discrimination/non-retaliation clauses (CCPA 1798.125, GDPR by doctrine) that constrain how you treat requesters everywhere.

What are the deadlines and extension mechanics per regime?

The clock table that configures the pipeline. GDPR/UK GDPR: one month from receipt, extendable by two further months for complexity or volume with notice within the first month (Article 12(3)); 'without undue delay' rides on top, so parking easy requests to day 29 is itself criticized. CCPA/CPRA: 45 days, extendable once by 45 with notice (access/deletion/correction); opt-outs of sale/share must be effectuated within 15 business days, and GPC signals processed as they arrive; the 12-month lookback for access (extendable to pre-2022 data on request unless impossible). Most other US states: 45 days plus a 45-day extension (Virginia, Colorado, Connecticut, and the family), with appeal processes mandatory, a distinctive state-law feature: the consumer can appeal your denial internally, and the appeal denial must include the AG complaint route. LGPD: 15 days for the full access statement (Article 19), immediate for the simplified declaration of processing existence, the tightest mainstream clock and the one that most often forces pipeline redesign. PIPL: 'timely' by statute with practice norms from implementing standards (the PIS specification's 30-day convention); refusals must be explained and a complaint channel provided. APPI: 'without delay,' with the two-week posture for disclosure in practice guidance. Quebec Law 25: 30 days, firm. PIPEDA: 30 days, extendable in defined circumstances with Commissioner-notified reasoning. India DPDP: as prescribed by the rules (the 2025 rules framework points to defined turnaround once fully commenced). Australia: APP 12's 'reasonable period' read as 30 days for access. The engineering translation: deadline, extension window, extension-notice requirement, and appeal mechanics are four columns in a configuration table keyed by jurisdiction, consumed by the same workflow engine, and the SLA dashboard alarms on the tightest applicable clock per request, which for a multinational is usually Brazil's.

How do exception and refusal grounds differ, and why does applying the wrong list matter?

Because a refusal is the highest-risk act in rights fulfillment, it is what complainants forward to regulators, and its validity depends entirely on the regime-specific exception list. Deletion exceptions: GDPR Article 17(3) permits retention for expression/information freedom, legal obligations, public health, archiving/research, and legal claims, notably no general 'business purposes' exception; CCPA 1798.105(d) enumerates its own list, completing the transaction, security and fraud, debugging, legal compliance, internal uses reasonably aligned with expectations, and the lists do not coincide: 'internal uses aligned with expectations' defends nothing in Europe, and Article 17(3)(e)'s legal-claims ground is broader than its California cousin. Access exceptions: GDPR Article 15(4) protects others' rights and freedoms (the third-party-data redaction duty), member-state law adds privilege and regulatory carve-outs, and the manifestly-unfounded-or-excessive refusal (Article 12(5)) is deliberately narrow, the ICO's guidance requires case-by-case justification and warns against volume alone as grounds; CCPA excludes certain security-sensitive data and caps repetition (twice in 12 months); trade secrets defend redactions nearly everywhere but rarely whole refusals. US state opt-outs have almost no exceptions, which surprises teams: a sale opt-out cannot be refused for business necessity, only fulfilled through the service-provider restructuring the statute contemplates. Sectoral overlays complicate further: HIPAA's access right runs on its own 30-day clock with its own denial grounds (and OCR has run an enforcement initiative on exactly this right since 2019), FCRA governs consumer-report file disclosure, and employment records attract member-state and provincial specialties. The operational disciplines: exception decisions are per-item, not per-request (withhold the privileged document, produce the rest); every withholding is logged with its legal ground (the withholding log is the refusal's defense); refusals are drafted or reviewed by counsel with the regime's appeal/complaint language included (mandatory in the state laws); and the exception table lives in the configuration layer beside the clocks, versioned as laws move.

How do verification and agent-request rules compare?

The two failure directions, over-verification obstructing rights and under-verification leaking data, are policed everywhere, with regime-specific mechanics. GDPR: proportionality doctrine, Recital 64 and EDPB guidance direct use of data you already hold, authentication into the existing account as the preferred method, and 'reasonable doubts' as the trigger for requesting more; demanding government ID for low-sensitivity contexts draws DPA criticism (several DPAs have fined excessive ID demands), and newly collected verification documents carry their own minimization and retention duties. CCPA regulations: the most prescriptive system, verification tiers scaled to sensitivity (reasonable degree for categories, reasonably high degree for specific pieces, matching two or three data points respectively, with declarations under penalty of perjury for the highest tier), an express ban on requiring account creation, fee-free verification, and detailed authorized-agent mechanics, businesses may require the agent's written authorization plus direct consumer confirmation, with power-of-attorney requests bypassing some checks; opt-outs, by design, require no verification at all (only fraud screening), because the remedy is low-risk. The state family broadly follows the CCPA's shape with local variations; Colorado's rules add universal-opt-out-mechanism recognition details. LGPD and PIPL: proportionate identity proof with less codified doctrine, agent requests via formal authorization; APPI: procedures the handler defines and publishes, within reasonableness. Quebec: identity verification plus the distinctive requirement that access be granted in an intelligible transcription. The operational convergence worth building to: authenticate-in-account as default everywhere, tiered step-up keyed to the matrix's sensitivity column, documented method per request, agent-request workflows for the US, and verification-failure responses that state what would suffice, since silent drops convert into complaints on every regime's books.

What does a jurisdiction-configured fulfillment architecture look like?

One machine, one configuration table, per-regime rendering. The machine (shared): intake normalization across channels (portal, email routing, GPC signal ingestion) into case records; identity verification with tiered step-up; scoping against the data inventory (systems, identifiers, vendor holdings); orchestrated collection and deletion with per-system evidence; human review for exemptions, third-party redaction, and adverse contexts; delivery through authenticated channels; and closure with the full audit trail, the same pipeline this library's DSAR automation guide details. The configuration table (per jurisdiction, the matrix operationalized): applicable rights list (drives which request types the portal offers a given user); clock, extension, and appeal parameters; verification tier rules and agent mechanics; exception lists per right; response-content requirements (Article 15's metadata catalog versus CCPA's categories-and-purposes disclosures versus LGPD's declaration formats); format rules (portability's machine-readable requirement, Quebec's intelligible transcription); anti-discrimination constraints; and complaint-route language for refusals and appeal denials. Jurisdiction resolution, the step teams underspecify: which configuration applies is a legal-mapping decision (user residency and the regime's scope tests, not IP geolocation alone), it must handle multi-regime individuals (an EU resident using your US service may hold GDPR rights; a Californian's household data spans persons), and the safest architecture defaults ambiguous cases to the more protective configuration rather than litigating edge cases per request. Governance around the machine: quarterly configuration review against legal change (this matrix decays as fast as the laws move), synthetic-request testing per jurisdiction (the fire drill that catches the broken Brazilian clock before a real 15-day request does), and metrics segmented by regime, cycle time versus clock, extension rate, refusal rate with grounds, appeal outcomes, because aggregate SLAs hide the jurisdiction that is quietly failing.

Regulatory Crosswalk

GDPR Articles 12-23CCPA/CPRALGPD Article 18PIPL Chapter IVQuebec Law 25

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.