Data subject rights,
answered inside the month.
GDPR data subject rights give every person in the EU and UK a say over the personal data you hold on them. This guide covers each right in Articles 15 to 22, the data subject access request (DSAR), the deadline and how to count it, identity checks, what changed in the UK in 2026, and how a request queue should run. Not legal advice: check decisions on scope and exemptions with counsel.
Last updated Published by TryTrustableNot legal advice
GDPR data subject rights are the eight rights in Articles 15 to 22 of the GDPR: access, rectification, erasure, restriction, notification of recipients, portability, objection, and protection from decisions based solely on automated processing. A controller must act on a request without undue delay and within one month of receipt, extendable by two further months for complex or numerous requests, free of charge in most cases, and may ask for more information only where it has reasonable doubts about who is asking.
What are the GDPR data subject rights?
The GDPR gives individuals eight rights over personal data held about them, set out in Articles 15 to 22. Article 12 then sets the rules for how you handle any request under them: in clear language, free of charge in most cases, and within a fixed time. Article 12(2) also requires you to facilitate the exercise of these rights, which is why a hidden email address is not enough.
| Article | Right | What the person can ask for | Main limits |
|---|---|---|---|
| 15 | Access | Confirmation that you process their data, a copy of it, and the purposes, categories, recipients, retention period, source and any automated decision-making | The copy must not adversely affect the rights and freedoms of others (Art. 15(4)) |
| 16 | Rectification | Correction of inaccurate data, and completion of incomplete data | Taking account of the purposes |
| 17 | Erasure (right to be forgotten) | Deletion, where one of six grounds applies, such as the data no longer being needed or consent being withdrawn | Exceptions for freedom of expression, legal obligations, public health, archiving and research, and legal claims (Art. 17(3)) |
| 18 | Restriction | That you store the data but stop otherwise using it, for example while accuracy is disputed | Four listed situations only |
| 19 | Notification | That you tell each recipient about a rectification, erasure or restriction, and tell the person who those recipients are if they ask | Unless impossible or a disproportionate effort |
| 20 | Portability | The data they gave you, in a structured, commonly used, machine-readable format, or sent directly to another controller where technically feasible | Only where processing is based on consent or contract and is carried out by automated means |
| 21 | Objection | That you stop processing based on public task or legitimate interests; and an absolute right to stop direct marketing | For legitimate interests, you may continue if you show compelling legitimate grounds |
| 22 | Automated decisions | Not to be subject to a decision based solely on automated processing with legal or similarly significant effects | Allowed for contract, law or explicit consent, with safeguards including human intervention |
Articles 13 and 14 (the right to be informed) sit alongside these: they set what your privacy notice must say.
What is a data subject access request (DSAR)?
A data subject access request, also called a subject access request (SAR) in the UK, is a request under Article 15. The person is entitled to three things: confirmation of whether you process their data; a copy of that data; and the supporting information in Article 15(1): purposes, categories of data, recipients (in particular any in third countries), the retention period or the criteria for it, their other rights, the right to complain, the source of the data if you did not collect it from them, and meaningful information about any automated decision-making.
The first copy is free. Article 15(3) lets you charge a reasonable fee based on administrative costs for further copies, and requires an electronic copy in a commonly used form where the request was made electronically. Article 15(4) is the main brake: the copy must not adversely affect the rights and freedoms of others, so review for third-party personal data before you send it. The EDPB's Guidelines 01/2022 set out how EU authorities read these provisions.
What is the deadline for a data subject request?
One month from receipt. Article 12(3) requires you to act without undue delay and in any event within one month, and lets you extend by two further months where necessary because of the complexity or number of requests. The extension is not automatic: you must tell the person within the first month, and give reasons. If you decide not to act, Article 12(4) requires you to say why within the month and tell them they can complain to a supervisory authority.
| Situation | Rule | Source |
|---|---|---|
| Standard response | Without undue delay, and within one month of receipt | GDPR Art. 12(3) |
| Complex or numerous requests | Extend by up to two further months; tell the person within the first month, with reasons | GDPR Art. 12(3) |
| You will not act | Tell the person within one month why, and that they can complain to a supervisory authority and seek a judicial remedy | GDPR Art. 12(4) |
| Fee | Free. A reasonable fee, or refusal, only where a request is manifestly unfounded or excessive; a fee may also be charged for further copies | GDPR Art. 12(5), 15(3) |
| UK: counting the month | From the day of receipt to the same date next month; if that date does not exist, the last day of the month; a weekend or bank holiday moves it to the next working day | ICO right of access guidance |
EU supervisory authorities and courts can count differently in detail. Treat the earliest reading as your target.
How do you verify identity for a DSAR?
Article 12(6) allows you to request additional information only where you have reasonable doubts about the identity of the person making the request. It is not a licence to demand a passport for every request. Good practice, consistent with the EDPB guidelines and the ICO's guidance:
- Match against what you already hold. A request from the email address on the account, or from inside a logged-in session, often needs nothing more.
- Ask for the least that resolves the doubt, and do not collect new identity documents you will then have to protect and delete.
- Be more careful where the data is sensitive or the request is for disclosure to a third party, such as a solicitor or a relative; check their authority to act.
- Record the method and why it was proportionate. In the UK, the ICO's position is that the time limit does not begin until you receive the information you reasonably asked for.
Under Article 11, if you genuinely cannot identify the person, you need not acquire extra data to do so, but you must tell them, and act if they give you information that lets you identify them.
The right to be forgotten: when must you erase?
Article 17 requires erasure without undue delay where a ground applies: the data is no longer necessary; consent is withdrawn and there is no other lawful basis; the person objects and you have no overriding grounds (or the objection is to direct marketing); the processing was unlawful; erasure is required by law; or the data was collected from a child for an online service. It is not absolute. Article 17(3) preserves processing needed for freedom of expression, a legal obligation, public health, archiving and research, and legal claims, so an invoice you must keep for tax law stays.
Two duties follow an erasure. Article 19 requires you to tell every recipient of the data, such as your processors, unless that is impossible or a disproportionate effort. And if you made the data public, Article 17(2) requires reasonable steps to tell other controllers processing it.
Portability, objection and automated decisions
Portability (Article 20) applies only to data the person provided, processed by automated means on the basis of consent or contract; JSON or CSV is fine. Objection (Article 21) is absolute for direct marketing; for legitimate interests or a public task you may continue only with compelling legitimate grounds. Automated decisions (Article 22): where you rely on the contract or explicit consent exceptions, offer human intervention, a chance to give a view and a way to contest the decision. If you build AI features, read this alongside our EU AI Act guide.
How do data subject rights differ under UK GDPR?
The UK GDPR keeps the same rights and the same one-month deadline with a two-month extension. The Data (Use and Access) Act 2025 amended the details, and the ICO confirmed on 19 June 2026 that all of its data protection provisions are now in force. For rights requests, the changes that matter are:
- Reasonable and proportionate searches. You must make reasonable efforts to find the information, but are not required to search in ways that are unreasonable or disproportionate to the importance of access.
- The clock and clarification. The ICO's guidance is that the time limit pauses on the day you ask for clarification and resumes the day after you receive it, and starts only when you have the ID or fee you asked for.
- Complaints. You must help people complain about how you use their data, for example with an electronic complaints form, acknowledge complaints within 30 days and respond without undue delay.
- Automated decisions. More lawful bases can support significant automated decisions, with safeguards, except for special category data.
If you serve both markets, run one process to the stricter reading of each step.
How a DSAR queue works
Most missed deadlines are requests that sat in an inbox nobody owned. A queue logs every request at receipt, gives it a deadline it cannot quietly lose, and keeps the evidence of each step. It needs a data map underneath: start with our record of processing activities template.
| Stage | What happens | What to record |
|---|---|---|
| 1. Intake | The request arrives by any route: web form, email, the privacy link on your cookie banner, a support ticket. The GDPR prescribes no form, so route requests that reach the wrong team rather than ignore them | Date and time of receipt, channel, the request in the person's words |
| 2. Classify | Decide which right or rights are being exercised. One message can ask for access and erasure together | Request type, deadline |
| 3. Verify | Only if you have reasonable doubt about identity; use information you already hold where you can | Method used, and why it was proportionate |
| 4. Clarify | If the request is unclear or you hold a large amount of data, ask what they want | What you asked, when |
| 5. Search | Every system in your data map, including processors, shared drives and email | Systems searched, by whom |
| 6. Review | Remove other people's data where disclosing it would affect their rights; apply any exemption | Redactions and exemptions relied on |
| 7. Respond | Send the data and the Article 15 information, or confirm the action taken | Date sent, what was sent |
| 8. Close | Tell recipients of any change under Article 19; keep the file | Outcome, closure date |
Data subject request automation in TryTrustable
The rights queue sits beside your consent records and your GDPR and UK GDPR controls, so a banner withdrawal and a written erasure request land in one place.
| In TryTrustable | What it does today |
|---|---|
| Privacy request link | The consent banner carries a link to your privacy request form, so the route is visible on every page |
| Public intake endpoint | Your own form can post requests straight into the queue; the request is logged at receipt |
| Request queue | Access, correction, erasure, consent withdrawal and grievance requests, each with a status from received through verifying and in progress to fulfilled or rejected |
| Deadlines | Computed from the request type at the moment of receipt, never typed in, and overdue requests are counted. The built-in periods follow India's DPDP Rules today; for EU and UK requests, work to the one-month GDPR clock, which is shorter |
| Audit trail | Whether identity was verified and how, the outcome, and a required reason for any rejection. A closed request cannot be reopened, so the record of when it was answered stands |
The queue manages and evidences requests. Searching your systems and deciding on exemptions stays with your team.
The things people ask us
How long do you have to respond to a data subject access request?
One month from receipt under Article 12(3). You can extend by two further months for complex or numerous requests if you tell the person within the first month and explain why.
Can we ask for ID before answering a DSAR?
Only where you have reasonable doubts about who is asking (Article 12(6)), and only for what resolves the doubt. Information you already hold, such as the account email, is often enough.
What is the right to be forgotten?
The Article 17 right to erasure. It applies where one of six grounds is met, such as data no longer being needed or consent being withdrawn, and has exceptions, including data you must keep to meet a legal obligation.
What is the right to be informed under GDPR?
Articles 13 and 14 require you to tell people, at collection or within a month if you got the data elsewhere, who you are, why you process their data, on what basis, who receives it, how long you keep it and what their rights are. That is your privacy notice; our privacy policy generator is a starting point.
Is a subject access request different under UK GDPR?
The deadline is the same. Since the Data (Use and Access) Act 2025 provisions came into force, you need only make reasonable and proportionate searches, and the ICO treats the clock as paused while you wait for a clarification you need.
Does TryTrustable delete data from our systems?
No. An erasure request raises a dated obligation for your team, and the record of what was done is kept. We do not take destructive access to your production databases.
Put every rights request on a clock you can show an auditor.
Thirty minutes on your request intake, your data map and the GDPR, UK GDPR and DPDP deadlines you answer to.