Individual Rights Under GDPR
Understanding and fulfilling the rights of individuals under the UK GDPR — a practical guide for organisations.
The Eight Individual Rights Under GDPR
The UK GDPR grants individuals eight fundamental rights over their personal data. Organisations that process personal data — whether as a controller or a data processor — must understand these rights and have processes in place to fulfil them.
Right to Be Informed
Individuals have the right to be told how their personal data is collected and used. This is typically fulfilled through privacy notices that explain the purpose, lawful basis, retention periods and who the data is shared with.
Right of Access
Also known as a Subject Access Request (SAR). Individuals can request a copy of the personal data you hold about them, along with supplementary information about how it is processed.
Right to Rectification
Individuals can ask you to correct inaccurate personal data or complete incomplete data. You must respond within one calendar month.
Right to Erasure
Also known as the 'right to be forgotten'. Individuals can request deletion of their personal data in certain circumstances — for example, when it is no longer necessary for the original purpose.
Right to Restrict Processing
Individuals can request that you limit how you use their data. You can still store the data but must stop processing it in other ways until the restriction is lifted.
Right to Data Portability
Individuals can obtain and reuse their personal data across different services. You must provide data in a structured, commonly used and machine-readable format.
Right to Object
Individuals can object to the processing of their personal data for direct marketing, research, or processing based on legitimate interests. Direct marketing objections must be complied with immediately.
Rights Related to Automated Decision-Making
Individuals have the right not to be subject to decisions made solely by automated processing — including profiling — if those decisions produce legal or similarly significant effects.
Handling Data Subject Requests
When an individual exercises any of their GDPR rights, your organisation must respond within one calendar month. This can be extended by a further two months for complex or numerous requests — but you must inform the individual within the first month and explain the reason for the delay.
Requests can be made verbally or in writing, and you cannot charge a fee in most cases. You must verify the identity of the requester before disclosing any personal data. For guidance on managing these requests, see our page on GDPR subject access requests.
Consequences of Failing to Uphold GDPR Rights
Failing to respond to data subject requests properly and within the required timeframe can result in complaints to the ICO, enforcement notices, and significant fines. It also damages trust with customers and employees.
Ensure Your Organisation Is Prepared
A GDPR audit can assess whether your processes for handling individual rights are adequate. Combine this with data protection training for staff to ensure frontline teams recognise and escalate requests correctly. Review your compliance checklist for a structured approach.
Ready to Get Started?
Contact us to discuss how we can support your organisation with practical, outcome-focused cyber security.
Get in Touch