Data Subject Rights: Overview and Handling Requests
The GDPR grants individuals control through rights to be informed, access, rectification, erasure, restriction, portability, objection, and freedom from automated decision-making. Controllers must respond within one month (extendable to three) and generally cannot charge a fee.
How this supports CIPP/US study
Use this lesson to identify the disclosure, workplace or cross-border rule that changes the result in a fact pattern. Continue with the CIPP/US study plan.
A cornerstone of the GDPR is giving individuals control over their personal data. The Data subject rights are: to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and not to be subject to automated decision-making.
Controllers must respond within one month of receipt (or, where necessary, within three months), in writing or orally if requested. They should verify identity by reasonable means such as photo ID. Generally they cannot charge a fee, but may charge to cover administrative costs for requests that are manifestly unfounded or excessive, or for additional copies.
A controller may refuse to act on a request where an exemption exists, or where the request is manifestly unfounded or excessive.
Key terms - quick answers
What is “Data subject rights”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.