Data Rights and Making a Subject Access Request

Solicitor reviewing case papers
Photo via Pexels

Data protection regimes in many jurisdictions give individuals rights over information held about them, and those rights are practical rather than theoretical.

The main rights

Access: to obtain a copy of the personal data an organisation holds about you.

Rectification: to have inaccurate data corrected.

Erasure in defined circumstances.

Restriction and objection, including to direct marketing, which is usually absolute.

Portability, to receive data in a usable format.

Rights concerning automated decisions that significantly affect you.

Making an access request

No particular form is required. A clear written request stating that you are exercising your right of access is sufficient.

Usually free, with a response period defined in the relevant regime, extendable for complex requests.

The organisation may ask you to verify your identity, which is legitimate.

Being specific about what you want — a date range, a department, a type of record — produces a more useful response faster than a request for everything.

Where it is useful

Employment disputes, where it can reveal internal communications about you.

Complaints against a company, where call recordings and notes are held.

Financial disputes, where account records and decision reasoning may be held.

Checking accuracy of records held by organisations that make decisions about you.

The limits

Data about other people is usually redacted.

Certain material may be exempt, including some legal advice and material relating to investigations.

Requests that are manifestly excessive can attract a fee or refusal, though this is applied narrowly.

If the response is inadequate

Ask the organisation to explain what it withheld and why.

Complain to the organisation's data protection officer where one exists.

Escalate to the relevant supervisory authority, which is free.

Marketing

Objecting to direct marketing must be honoured, and continued contact after objection is a breach worth reporting.

Correcting inaccurate records

The right to rectification is frequently more useful than access, since an inaccurate record can affect decisions for years.

Identify the specific entry and state what is wrong and what it should say, with supporting evidence where you have it.

The organisation must respond within a defined period, and where it disputes the correction it should record that the accuracy is contested.

Ask it to inform anyone it has shared the data with, which it is generally obliged to do.

Where your data has gone

Organisations are usually required to tell you who they share data with, either in their privacy notice or on request.

Credit reference agencies, marketing companies and analytics providers are common recipients and are frequently not obvious from the original relationship.

Where data has been shared onward, your rights generally apply against those recipients too, though pursuing each is laborious.

Breach notification

Organisations must usually notify affected individuals where a breach is likely to result in a high risk to them.

If you are notified, change the password for that service and anywhere it was reused, and watch for targeted approaches referencing the breached information.

Breach notifications are themselves impersonated by fraudsters, so verify through the organisation's official channels rather than through links in the message.

General information; data protection rules vary by jurisdiction.

Article Was Generated By AI.

This article is general information only and does not constitute professional advice. Circumstances vary, and you should consult a qualified professional before making decisions based on this content.