GDPR gives individuals a set of enforceable rights over their data, and it gives organizations one month to honor each request. The rights live in Articles 15 to 22: access, rectification, erasure, restriction of processing, data portability, objection, and safeguards against purely automated decisions. Article 12 wraps them all in procedural rules covering deadlines, fees, and identity verification.
| Regulation | GDPR, Articles 12 to 22 |
|---|---|
| Deadline | 1 month, extendable to 3 for complex requests |
| Max penalty | EUR 20M or 4% of global annual turnover |
| Enforcing authority | National supervisory authorities, coordinated by the EDPB |
| Official text | EUR-Lex CELEX 32016R0679 |
The eight rights at a glance
- Access (Art. 15). A copy of the data plus the metadata: purposes, recipients, retention, sources, and the existence of automated decision-making.
- Rectification (Art. 16). Correct inaccurate data and complete incomplete data.
- Erasure (Art. 17). Deletion where one of six grounds applies, subject to the Article 17(3) exceptions.
- Restriction (Art. 18). Freeze processing while accuracy or objections are contested.
- Portability (Art. 20). A machine-readable export of provided data processed on consent or contract.
- Objection (Art. 21). An absolute stop for direct marketing; a balancing test for legitimate-interests processing.
- Automated decisions (Art. 22). Protection against decisions based solely on automated processing with legal or similarly significant effects.
- Notification (Art. 19). Pass rectifications, erasures, and restrictions on to every recipient of the data.
Why requests go wrong
Most failures are operational, not legal. Requests arrive through channels nobody monitors, identity checks are either absent or wildly disproportionate, and data sits in systems the privacy team does not know about. The one-month clock does not pause while you find out which SaaS tools hold the person’s records. This is why a current data inventory is the single best DSAR investment: the organizations that miss deadlines are almost always the ones searching for data after the request arrives.
Objection to direct marketing deserves special attention because it is absolute. Article 21(3) leaves no balancing test: when someone objects, marketing processing stops. Continuing to email someone who objected is one of the most commonly fined small violations in Europe.
Building the workflow
Set up a single intake point and publish it in your privacy notice. Verify identity proportionately. Search every system in your data map, including processors, whose Article 28 contracts oblige them to assist. Respond within the month in clear language, and log the request, the searches, the decision, and the delivery. Those logs are your defense when a complaint lands.
For a comparison of how these rights map to CCPA, LGPD, and other regimes, see the data subject rights matrix. And because your privacy notice must accurately describe these rights and how to exercise them, a free scan checks what your public policy actually promises.