Data Subject Rights (Overview)

Articles 12-22 GDPR — the 8 rights

Practitioner's note: This article is practice-oriented compliance documentation, not legal advice. We are a compliance specialist, not a law firm. For legally binding information please consult a licensed lawyer.

TL;DR

The 8 data subject rights: information, access, rectification, erasure, restriction, objection, data portability, automated decision-making. Response deadline 1 month (extendable to 3).

What are data subject rights (overview)?

The 8 rights:

Practical example

An employee requests access to all stored data. Response within 1 month: ROPA extract, categories, recipients, retention periods.

Frequently asked questions

Deadline?
1 month from receipt. Extension by 2 months possible (complex cases).
Subject to charges?
Initial response is free of charge. A fee may apply for manifestly unfounded or excessive requests.

See also