Chapter 14: The GDPR and International Privacy Issues

Data Subject Rights: Overview and Handling Requests

The GDPR grants individuals control through rights to be informed, access, rectification, erasure, restriction, portability, objection, and freedom from automated decision-making. Controllers must respond within one month (extendable to three) and generally cannot charge a fee.

How this supports CIPP/US study

Use this lesson to identify the disclosure, workplace or cross-border rule that changes the result in a fact pattern. Continue with the CIPP/US study plan.

A cornerstone of the GDPR is giving individuals control over their personal data. The Data subject rights are: to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and not to be subject to automated decision-making.

Response timing and fees

Controllers must respond within one month of receipt (or, where necessary, within three months), in writing or orally if requested. They should verify identity by reasonable means such as photo ID. Generally they cannot charge a fee, but may charge to cover administrative costs for requests that are manifestly unfounded or excessive, or for additional copies.

A controller may refuse to act on a request where an exemption exists, or where the request is manifestly unfounded or excessive.

Key terms - quick answers

What is “Data subject rights”?
The set of GDPR rights giving individuals control over their personal data, including access, rectification, erasure, restriction, portability, and objection.

Sources and study method

This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.