Data Subject Rights (GDPR)
In short: The rights the GDPR grants every person vis-à-vis companies that process their personal data — including access, rectification, erasure and data minimisation.
In more detail: An overview of the most important data subject rights: right of access (Art. 15 — which data is being processed?), right to rectification (Art. 16 — have incorrect data corrected), right to erasure (Art. 17, the “right to be forgotten”), right to data portability (Art. 20 — export data in a structured form), right to restriction of processing, and the principle of data minimisation (Art. 5 — collect only as much data as necessary; not a “right” of its own in the narrower sense, but closely related). Companies usually have to answer these requests within one month.
In Depth
The data subject rights in detail, with the respective GDPR articles:
Art. 15 Right of access - Which data is processed about me, for what purpose?
Art. 16 Right to rectification - have incorrect/incomplete data corrected
Art. 17 Right to erasure - "right to be forgotten", with exceptions
(e.g. statutory retention obligations)
Art. 18 Restriction - temporarily "freeze" processing instead of deleting
Art. 20 Data portability - export in a structured, machine-readable format
Art. 21 Right to object - object to certain processing (e.g. direct marketing)
For companies, this results in concrete technical requirements: an access request (Art. 15) has to be answered within one month — which means a system needs a practicable way to compile ALL data stored about a person, not just the data from the main database (log files, backups, support tickets etc. can also be relevant). The right to erasure (Art. 17) often conflicts with other legal obligations, such as the ten-year retention obligation for invoices under German commercial law — in such cases a soft-delete approach is usually used: the account is marked as deleted and personal fields are anonymised, while legally required records are kept in anonymised form.
Deleting vs. anonymising
The distinction between “deleting” and “anonymising” is important: anonymised data (from which no conclusion about a person is possible any more, not even by linking it with other available data) no longer falls under the GDPR, because it’s no longer personal data — real deletion is therefore not always strictly necessary if anonymisation is sufficient. This is to be distinguished from pseudonymisation (e.g. replacing the name with an ID, with the mapping table kept separately): pseudonymised data is still considered personal, because re-identification remains possible with the matching key — the GDPR only treats pseudonymisation as an additional protective measure, not as a way out of its scope.
Why access requests are technically laborious
In practice, Art. 15 (right of access) is the most laborious point for many companies: personal data often hides in unexpected places — analytics tools, email marketing platforms, support ticket systems, backup snapshots, even in other users’ free-text fields (e.g. a support note “customer Max Mustermann complained”). Larger companies therefore often build a central “privacy dashboard” that automatically queries all known data sources for a person, instead of searching manually through all systems for every request.
Limits of data subject rights
Data subject rights don’t apply absolutely — Art. 12(5) GDPR allows manifestly unfounded or excessive requests (e.g. the same person submitting a new access request every day) to be refused or a reasonable fee to be charged. The right to erasure also explicitly does NOT apply if processing is necessary to comply with a legal obligation, to exercise the right of freedom of expression, or to establish legal claims — a company may, for example, keep data relating to an ongoing legal dispute despite an erasure request.
See also: GDPR, Personal data