Eight Data Subject Rights Under GDPR and Why They Matter
12 mins read

Eight Data Subject Rights Under GDPR and Why They Matter

Executive Summary (TL;DR)

  • GDPR grants individuals 8 core data subject rights: to be informed, access, rectification, erasure, restriction of processing, data portability, objection, and protection from solely automated decision-making
  • These rights aren’t just legal checkboxes; they’re operational challenges that require organizations to find, classify, govern, and act on data across complex systems
  • Similar rights exist under CCPA/CPRA, Virginia’s CDPA, and Brazil’s LGPD, though with varying degrees of alignment with GDPR
  • Data subject rights (what individuals can request) are different from GDPR principles (rules organizations must always follow, like data minimization)
  • Bottom line: privacy compliance depends less on policy language and more on whether your data infrastructure can support these rights in practice. This is why capabilities such as sensitive data discovery, policy-based governance, secure access, masking, auditability, and compliance automation matter.

As organizations collect, store, share, and analyze ever-growing volumes of personal data, privacy rights have shifted from a legal checkbox to an operational requirement. Individuals want visibility and control over how their data is used, and regulators expect organizations to respond clearly, consistently, and promptly. While many privacy laws now include similar protections, the best-known framework for the “eight data subject rights” is found in Chapter III of the GDPR. Controllers are primarily responsible for responding to these requests and, in most cases, must do so without undue delay and within one month.

In simple terms, these rights are designed to give individuals more control over their personal data and to push organizations toward better transparency, governance, and accountability. For enterprises, that means privacy is no longer just about policy. It depends on whether you can find data, classify it, govern it, protect it, and act on requests across siloed systems.

The eight GDPR data subject rights are: the right to be informed, right of access, right to rectification, right to erasure, right to restriction of processing, right to data portability, right to object, and the right not to be subject to solely automated decision-making, including profiling, when it produces legal or similarly significant effects.

Eight GDPR Data Subject Rights and How They Align Across Major Privacy Laws

These laws also include extra rights or duties not shown in a strict GDPR-8 graphic. California includes equal treatment and limits the use/disclosure of sensitive PI; Virginia includes an appeal process; LGPD includes rights regarding information sharing, denial of consent, and revocation of consent.

1. Right to Be Informed

The right to be informed is the foundation of privacy transparency. Individuals have the right to know what personal data is being collected, why it is being processed, how long it will be retained, and with whom it may be shared. Under GDPR, this information is typically delivered through a privacy notice at the time data is collected, or within a defined period when the data comes from another source.

For organizations, this is where privacy language meets data reality. You cannot give clear notices if you do not have a clear view of your data sources, retention logic, and third-party flows. That is why metadata visibility, policy governance, and data discovery matter so much in practice.

2. Right of Access

The right of access allows individuals to ask whether an organization is processing their personal data and, if so, to obtain access to that data along with supporting information such as the purpose of processing, the categories of data involved, and recipients or recipient categories. This is one of the most operationally demanding rights because it requires an organization to locate data accurately across multiple systems.

A subject rights request sounds simple on paper, but in real environments, data may be spread across applications, archives, cloud stores, files, and downstream copies. Fulfilling access requests consistently requires search, lineage awareness, and governed retrieval workflows.

3. Right to Rectification

Under Article 16, individuals have the right to have inaccurate personal data corrected without undue delay. They may also have incomplete personal data, depending on the purpose of processing.

From an enterprise standpoint, rectification is not just an update task. It requires confidence that the correction is applied to the right records, propagated where appropriate, and controlled through proper access permissions. Poor data quality and disconnected systems make this right harder to fulfill than many teams expect.

4. Right to Erasure

The right to erasure, often called the right to be forgotten, allows individuals to request deletion of personal data in certain circumstances, such as when the data is no longer necessary, consent is withdrawn, or the processing was unlawful. This right is important, but it is not absolute. Legal obligations, public interest grounds, and other exceptions may still apply.

Operationally, erasure depends on whether an organization can actually identify all relevant instances of the data across active systems, copies, and connected environments. Without enterprise-wide discovery and governance, deletion requests can easily become partial, manual, and risky.

5. Right to Restriction of Processing

This is the right that is often confused with data minimization, but they are not the same thing. Data minimization is a GDPR principle. Restriction of processing is a distinct right under Article 18. It allows an individual to ask an organization to limit how their data is used in certain cases, such as when the accuracy of the data is contested, or the processing is unlawful but erasure is not requested.

For organizations, restriction means more than simply “do nothing.” It requires the ability to flag data, suppress certain processing actions, and maintain auditable controls so restricted records are not used improperly.

6. Right to Data Portability

The right to data portability gives individuals the right to receive personal data they have provided to a controller in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where the legal conditions are met. This right applies when processing is based on consent or contract and is carried out by automated means.

In practice, portability requires structured extraction, consistency, and secure delivery. It is not just a file export feature. Organizations need governed ways to package relevant data accurately and provide it in a usable format without exposing other people’s data or unrelated records.

7. Right to Object

Article 21 gives individuals the right to object to certain types of processing, including processing based on legitimate interests and processing for direct marketing. In the direct marketing context, the right is especially strong: once an individual objects, the personal data should no longer be processed for that purpose.

This means organizations need more than preference centers. They need policy-aware controls that can identify where personal data is being used, distinguish processing purposes, and stop or reroute downstream processing when an objection is valid.

8. Right Not to Be Subject to Solely Automated Decision-Making, Including Profiling

GDPR does not create a broad, standalone “right not to be profiled” in every situation. More precisely, Article 22 gives individuals the right not to be subject to a decision based solely on automated processing, including profiling, when that decision produces legal effects or similarly significant effects.

This matters more as AI and machine-led decision-making become common in areas like lending, hiring, insurance, and eligibility workflows. Organizations using automated decision systems need transparency, lawful basis analysis, meaningful human review, and clear governance over the data feeding those systems. In high-impact use cases, a human-in-the-loop approach can help ensure decisions are not left entirely to automated processing.

Data Subject Rights vs. GDPR Principles: What’s the Difference?

A common point of confusion in GDPR is the difference between data subject rights and data protection principles. Rights are what individuals can exercise, such as access, rectification, erasure, or objection. Principles are the rules organizations must follow when processing personal data. These are set out in Article 5 and apply whether or not an individual makes a request. In simple terms, rights are what people can ask for (person-facing entitlements); principles are the standards organizations are expected to build into everyday processing (organization-facing obligations)

This distinction matters because data minimization is a GDPR principle, not a data subject right. The correct right is the restriction of processing. So while organizations must always minimize the personal data they collect and use, individuals may also request that processing be restricted in certain situations.

A Quick Look at the GDPR Principles

GDPR is built around seven core principles: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability. These principles guide how organizations collect, use, protect, and retain personal data.

How Solix Helps Operationalize Data Subject Rights

Meeting data subject rights at scale depends on whether an organization can find, understand, protect, and act on data consistently. That is where a unified privacy operations approach becomes useful.

Solix Sensitive Data Discovery is designed to identify sensitive data across structured and unstructured sources, across on-prem and cloud environments, using prebuilt and custom patterns, metadata search, and data-level scanning. That helps organizations build the visibility needed for access, erasure, rectification, and transparency workflows.

Solix Data Masking adds protection for sensitive data across repositories and environments through techniques such as referential masking, redaction, and format-preserving encryption, while preserving usability and referential integrity. That is especially valuable when privacy obligations intersect with non-production, analytics, and broader data security requirements.

Solix Consumer Data Privacy brings these capabilities together in a privacy-by-design suite on SOLIXCloud CDP, combining discovery, masking, encryption, lifecycle management, and compliance automation to help enterprises support privacy obligations such as access, deletion, minimization, and audit-ready reporting.

Solix Consumer Data Privacy

From Privacy Operations to Governed, AI-Ready Data

Solix helps organizations move beyond point compliance by connecting privacy operations with broader data governance and AI readiness. Solix CDP provides the common platform to unify, manage, and archive enterprise data across environments, while Solix AI Governance / EDG adds the governance layer needed to define policies, trust, and control around that data. For unstructured content, Solix ECS extends the same operational discipline to documents, files, and enterprise content.

On top of that foundation, Solix Enterprise AI adds an activation layer. Data Sense builds the intelligence that makes enterprise data readable, governable, and useful to AI. Data Ask uses that intelligence to deliver grounded answers through a natural-language interface, and AI Warehouse provides an AI-native, governance-first platform for downstream analytics, semantics, and model-driven use cases. The result is a more connected path from governed data to usable insight, without forcing organizations to treat privacy, governance, content, and AI as separate programs.

Learn more: “How to Comply with Consumer Data Privacy Regulations?” The full guide offers actionable steps to ensure compliance with consumer data privacy regulations and protect your business from costly violations. Read it now!

FAQs:

Are these eight rights specific to GDPR?

Yes. This exact “eight rights” framing is rooted in GDPR Chapter III. Other privacy laws may include similar rights, but the terminology and scope can vary by jurisdiction.

Who is primarily responsible for responding to data subject rights requests?

Under GDPR, the controller is primarily responsible for responding to the individual, although processors may support fulfillment, depending on the processing arrangement.

How long does an organization have to respond?

Generally, the response must be provided without undue delay and within one month. In complex cases, the deadline can be extended by up to two further months, but the individual must be informed within the first month.