Page Banner

What rights do individuals have under GDPR?

Home » Blog » What rights do individuals have under GDPR?

Data protection is not just a legal obligation for businesses. It is a set of real, enforceable rights that belong to every individual, and understanding those rights matters whether you are a sole trader in Manchester, a corporate legal team in London, or simply someone who has ever filled in an online form. The General Data Protection Regulation, known as GDPR, was introduced to bring clarity and control back to the people whose personal data is being collected, stored, and used every day.

Since the UK retained and adapted this framework following Brexit, the rights it contains now sit within the UK GDPR, which is enforced by the Information Commissioner’s Office (ICO). The practical substance of those rights remains largely the same as the EU original, but it is worth understanding precisely how they apply in a UK context before assuming full cross-border alignment.


What Are the Rights of Individuals Under the UK GDPR?

The UK GDPR sets out eight distinct rights that individuals can exercise in relation to their personal data. These rights are not aspirational guidelines; they are legal entitlements that organisations must honour within defined timeframes, typically one calendar month from the point a request is received.

The right of access, often called a Subject Access Request (SAR), is perhaps the most commonly exercised. It allows any individual to request a copy of the personal data an organisation holds about them, along with information about how that data is being used, where it came from, and who it has been shared with.

RightWhat It MeansTypical Response Timeframe
Right of AccessObtain a copy of your personal data1 month
Right to RectificationCorrect inaccurate or incomplete data1 month
Right to ErasureRequest deletion of your data1 month
Right to Restrict ProcessingLimit how your data is used1 month
Right to Data PortabilityTransfer your data to another provider1 month
Right to ObjectObject to processing based on legitimate interestsWithout undue delay
Rights re Automated DecisionsChallenge decisions made by automated systems1 month
Right to be InformedKnow how and why your data is collectedAt point of collection

Looking to ensure your data remains GDPR compliant? Take a look at our Database Information here

Funeral Directors Database


What Are the Five Core Rights of Individuals Most Frequently Exercised?

While all eight rights carry legal weight, five of them appear most frequently in practice. The right to erasure, commonly called the “right to be forgotten,” allows individuals to request that an organisation deletes their personal data in certain circumstances, such as when the data is no longer needed for its original purpose or when consent is withdrawn.

The rights to rectification, restriction of processing, data portability, and objection round out this group. Rectification is particularly relevant when someone discovers that an employer, insurer, or financial provider holds outdated or simply wrong information about them, since inaccurate data can have real downstream consequences that affect decisions made about a person’s life.


What Are the 7 GDPR Principles That Underpin Individual Rights?

The seven data protection principles form the foundation on which all individual rights rest. They are outlined in Article 5 of both the UK GDPR and the original EU regulation, and they set out the conditions under which personal data must be processed at all times.

Those principles are lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Every individual right exists to enforce at least one of these principles in practice, which is why understanding the principles helps people understand when and why a particular right applies to their situation.

PrincipleCore Requirement
Lawfulness, Fairness & TransparencyData must be processed legally and openly
Purpose LimitationData collected for one purpose cannot be reused for another without justification
Data MinimisationOnly collect the data that is genuinely necessary
AccuracyData must be kept up to date and corrected when wrong
Storage LimitationData should not be kept longer than necessary
Integrity & ConfidentialityData must be kept secure against loss or unauthorised access
AccountabilityOrganisations must be able to demonstrate compliance

Contact Our Team: 01276 69 11 99


What Is Reclassified as an Individual’s Right Under the UK GDPR?

One area where the UK GDPR introduced some nuance compared to its EU predecessor relates to automated decision-making. Under the UK framework, the right to object to solely automated decisions, including profiling, is treated as a distinct individual right rather than simply a safeguard. This matters in practice because automated systems now influence credit scoring, insurance pricing, job application screening, and a range of other high-stakes decisions.

For further detail on how the UK GDPR applies to automated processing and what qualifies as a right under domestic law, the ICO’s guidance on individual rights provides the definitive reference point. Separately, the UK Government’s legislation page for the Data Protection Act 2018 sets out the statutory framework within which these rights operate.

It is also worth noting that certain rights carry exemptions. Public authorities, law enforcement bodies, and organisations processing data for scientific or archival research may be able to restrict some rights in specific, defined circumstances, which is why seeking tailored advice is always sensible when a request is refused.

Understanding What Rights Individuals Have Under GDPR: A Practical Summary

The rights contained within the UK GDPR represent one of the most significant shifts in data privacy that individuals in the UK have ever had access to. Whether someone is querying why a company holds their contact details, challenging a credit decision they believe was made on faulty information, or simply wanting to move their data from one service provider to another, the legal framework exists to support them. These are not abstract provisions sitting in regulatory documents; they are actionable rights that can be exercised at any time and must be responded to by law.

Organisations of every size have a corresponding obligation to make exercising these rights straightforward. A person should not need to write a formal legal letter or know the precise article number of the regulation to get a response. Where requests are refused, the refusal must be explained in writing and the individual must be told they have the right to complain to the ICO, which remains the UK’s lead supervisory authority for data protection matters.

The practical reality is that most people become aware of these rights only when something goes wrong: an incorrect credit file, an unwanted marketing campaign, or a data breach notification letter. Building awareness of what the UK GDPR actually provides, and knowing how to act on it, puts individuals in a far stronger position to protect their personal information in an increasingly data-driven world.

  • The UK GDPR grants eight enforceable individual rights, including access, erasure, rectification, and the right to object, all of which must be fulfilled within one calendar month in most cases.
  • The seven data protection principles underpin every right in the regulation, setting the conditions under which personal data must be collected, used, and stored by any organisation operating in the UK.
  • Automated decision-making is treated as a distinct right under UK GDPR, reflecting the growing role of algorithmic systems in decisions that directly affect people’s financial, professional, and personal circumstances.

What Rights Do Individuals Have Under GDPR: Frequently Asked Questions

What is the right of access under GDPR and how do I use it?

The right of access, formally known as a Subject Access Request, allows you to ask any organisation whether it holds your personal data and to receive a copy of it. You can submit a request verbally or in writing, and the organisation must respond within one calendar month free of charge in most cases.

Can an organisation refuse a Subject Access Request?

Yes, but only in specific circumstances, such as when a request is considered manifestly unfounded or excessive. If refused, the organisation must explain why in writing and inform you of your right to complain to the ICO.

What does the right to erasure actually cover under UK GDPR?

The right to erasure allows you to request that an organisation deletes your personal data when it is no longer necessary for its original purpose, when you withdraw consent, or when the data has been processed unlawfully. It is not an absolute right and does not override other legal obligations the organisation may have.

How does the right to data portability work in practice?

Data portability allows you to receive your personal data in a structured, commonly used, machine-readable format and to transfer it to another organisation if you choose. This right applies specifically where processing is based on consent or contract and is carried out by automated means.

What is the difference between restricting processing and requesting erasure?

Restricting processing means the organisation can continue to store your data but cannot actively use it, which is useful when you are disputing the accuracy of the data rather than wanting it deleted outright. Erasure, by contrast, requires the data to be permanently removed.

What are the 7 principles of GDPR and do they apply to individuals?

The seven principles govern how organisations must handle personal data; they are not rights exercised by individuals directly. However, they form the legal basis for every individual right, meaning that when an organisation breaches a principle, you can often invoke a corresponding right to seek a remedy.

What is profiling under GDPR and how is it regulated?

Profiling involves using personal data to evaluate certain aspects of a person, such as their financial situation, health, or behaviour, and it is regulated under Article 22 of the UK GDPR. You can read more about the concept and its legal background on the Wikipedia page for the General Data Protection Regulation.

What does the right to object mean for direct marketing?

If an organisation is processing your data for direct marketing purposes, you have an absolute right to object at any time and the organisation must stop immediately. This right cannot be overridden by the organisation’s legitimate interests.

How long does an organisation have to respond to a rights request?

In most cases, organisations must respond to individual rights requests within one calendar month of receipt. This can be extended by a further two months where requests are complex or numerous, but you must be informed of the extension within the initial one-month period.

What happens if an organisation fails to comply with a GDPR rights request?

If an organisation fails to respond appropriately, you can complain to the Information Commissioner’s Office, which has the power to investigate and issue fines. In serious cases, you may also have the right to seek compensation through the courts.

Are there any rights that apply specifically to children under UK GDPR?

Children’s personal data is entitled to heightened protection under the UK GDPR, particularly in the context of online services, and the ICO’s Age Appropriate Design Code sets out specific requirements for platforms likely to be accessed by under-18s. Where consent is required for processing a child’s data, parental or guardian consent is typically needed for younger children.

Does Brexit mean UK GDPR rights are different from EU GDPR rights?

The UK GDPR closely mirrors the EU GDPR and the eight individual rights remain substantively the same. However, the UK now operates its own independent framework overseen by the ICO rather than through EU supervisory mechanisms, so cross-border complaints may need to be directed to both authorities depending on where the organisation is based.

What is the right to be informed and when must it be provided?

The right to be informed requires organisations to tell individuals what personal data they are collecting, why they are collecting it, how long they will keep it, and who they will share it with. This information must typically be provided at the point of data collection, usually through a privacy notice.

What should I do if I think my GDPR rights have been violated?

Your first step should be to raise a complaint directly with the organisation, as many issues are resolved at this stage. If the response is unsatisfactory, you can escalate to the ICO through its official complaints process, which handles data protection complaints from individuals across the UK.

Further Reading About Marketing Databases