Data Subject Rights and How to Honor Them

About this module

Data subject rights can arrive through a formal portal, an email, social media, or a casual conversation. This lesson teaches employees to recognize requests for access, correction, erasure, restriction, portability, and objection, then route them quickly. Learners see why the 30-day clock for a Subject Access Request starts as soon as a valid request is received, and why identity checks matter before releasing anything. The safe pattern is to log the request, verify identity, preserve records, avoid side conversations, and escalate to the privacy team or DPO immediately.

Key takeaways

  • A Subject Access Request can arrive informally and still trigger a deadline
  • Organizations usually have 30 calendar days to respond to a valid access request
  • Identity must be verified before releasing personal data
  • Employees should log, preserve, and escalate requests instead of answering alone

Full Transcript

Data protection laws don't just restrict organisations. They give individuals powerful, enforceable rights over their own data.

In this module we will unpack every right and show you exactly how to respond. Under G.D.P.R., the U.K. G.D.P.R., and C.C.P.A., individuals are called data subjects.

They hold a set of rights that are not optional guidelines — they are legal entitlements. Failing to honour them can trigger regulatory investigations, fines, and reputational damage.

The Right to Access — also called a Subject Access Request — lets any individual ask your organisation for a complete copy of the personal data you hold on them. You must confirm whether you process their data and provide a copy, free of charge.

The Right to Rectification means individuals do not have to live with wrong information. If they believe data you hold is inaccurate or incomplete, they can ask you to fix it.

You must act promptly and inform any third parties you have shared the data with. The Right to Erasure, or the right to be forgotten, allows individuals to ask you to delete their personal data.

This applies when data is no longer needed for its original purpose, when consent is withdrawn, or when the data has been processed unlawfully. The Right to Restriction lets individuals put a hold on how you process their data.

This applies when accuracy is challenged, when processing is unlawful but the individual prefers restriction over deletion, or when you no longer need the data but they do for a legal claim. The Right to Data Portability empowers individuals to take their data and move it elsewhere.

You must provide it in a structured, commonly-used, machine-readable format such as C.S.V. or J.S.O.N., and you can be required to transmit it directly to another controller if technically feasible. Organisations have 30 calendar days to respond to a Subject Access Request.

That clock starts the moment a valid request is received. In complex cases you may extend by two further months, but you must notify the individual within the first 30 days.

A Subject Access Request is a formal request by an individual to see the personal data an organisation holds about them. It can be submitted verbally, by email, via social media, or even in a casual conversation.

There is no required format. If someone asks what data do you have on me, that is a S.A.R. Before you respond to a S.A.R., you must verify the identity of the person making the request.

Ask for reasonable proof — such as a passport or utility bill — but do not make it unnecessarily burdensome. The 30-day clock can be paused while you clarify identity.

Remember: releasing data to the wrong person is itself a serious breach. Failing to respond to a Subject Access Request on time is not a minor oversight.

It is a reportable compliance failure. Regulators actively receive complaints from data subjects who feel ignored.

The I.C.O. can issue enforcement notices, fines, and in serious cases refer matters for criminal prosecution. A compliant S.A.R. response follows a clear process.

Log the request date the moment it arrives. Verify identity.

Conduct a thorough search across every system that could hold personal data. Compile the results, redact anything you are legally entitled to withhold, and send a clear, plain-language response before day thirty.

The Right to Object allows individuals to stop certain types of processing. If the objection is to direct marketing, you must stop immediately — no exceptions.

For processing based on legitimate interests, you can continue only if you can demonstrate compelling grounds that override the individual's interests, rights, and freedoms. Always document your reasoning.

The I.C.O. received over fifteen thousand data rights complaints in the 2022 to 2023 reporting year. That means individuals are actively exercising their rights and escalating when organisations fail them.

Every unresolved S.A.R. is a potential complaint. Treat each one as a priority.

Every employee has a role to play. If someone contacts you asking about their data — however informally — treat it as a S.A.R. Log it, do not delay, and escalate to your D.P.O. or privacy team immediately.

Do not discuss the request with colleagues who are not directly involved, and do not delete or alter any records that might be covered by the request. Data subject rights are not a box-ticking exercise — they are legally enforceable entitlements.

Know the rights. Know the deadlines.

And when a request arrives, act quickly, carefully, and completely.