Responding to User Requests and Consumer Rights
Many federal and state laws grant rights of control: access, correction, deletion, portability, against automated decision-making, and nondiscrimination. Requests have defined response periods and often a right to appeal; FCRA, HIPAA, and the GDPR grant specific access/correction rights.
How this supports CIPP/US study
Use this lesson to connect a privacy programme decision with the relevant regulator, duty or enforcement route. Continue with the CIPP/US study guide.
- Right to access
- Right to correction (rectification)
- Right to delete
- Right to portability
- Right against automated decision-making
- Right to nondiscrimination
Individuals exercise rights by request to a business or agency, which has a defined response period. A denial may trigger a right to appeal; a dissatisfied individual may complain to a regulator. Specific access rights exist under FCRA (credit reports plus rectification), HIPAA (medical records, with disputed entries noted), the Judicial Redress Act of 2015 (for qualifying non-U.S. individuals against a U.S. agency), and the GDPR in the EU. Where no statute requires access, it appears in fair information practices like the OECD Guidelines and APEC Principles.
Key terms - quick answers
What is “Right to access”?
What is “Right to appeal”?
What is “Judicial Redress Act of 2015”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.