The Eight User Rights Under the GDPR

The Eight User Rights Under the GDPR

The GDPR may be legislation aimed at data controllers (and businesses), but it's data subjects that are truly at the core of the text.

All the rules, restrictions, and requirements placed in the GDPR share the aim of protecting data subjects (or users) and upholding their rights.

The GDPR explicitly states its commitment to European citizens and data subjects early on in the legislation. Chapter 3 of the GDPR records those rights as the Rights of the Data Subject.

Chapter 3 outlines eight distinct rights that all Europeans are entitled to and that your organization must uphold through your data practices. The eight user rights are:

  1. The Right to Information
  2. The Right of Access
  3. The Right to Rectification
  4. The Right to Erasure
  5. The Right to Restriction of Processing
  6. The Right to Data Portability
  7. The Right to Object
  8. The Right to Avoid Automated Decision-Making

Let's take a look at each one in turn and look at examples of how you can disclose these rights in your Privacy Policy so your users can exert them if they choose to.

Need a Privacy Policy? Our Privacy Policy Generator will help you create a custom policy that you can use on your website and mobile app. Just follow these few easy steps:

  1. Click on "Start creating your Privacy Policy" on our website.
  2. Select the platforms where your Privacy Policy will be used and go to the next step.
  3. Privacy Policy Generator - Select platforms - Step 1

  4. Add information about your business: your website and/or app.
  5. Privacy Policy Generator - Add your business info - Step 2

  6. Select the country:
  7. Privacy Policy Generator - Add your business info - Step 2

  8. Answer the questions from our wizard relating to what type of information you collect from your users.
  9. Privacy Policy Generator - Answer questions from our wizard - Step 3

  10. Enter your email address where you'd like your Privacy Policy sent and click "Generate". Privacy Policy Generator - Enter your email address - Step 4

    And you're done! Now you can copy or link to your hosted Privacy Policy.

1. The Right to Information

1. The Right to Information

The first of the eight rights lies in Articles 13 and 14 of the GDPR. Article 13 refers to information that you must provide when you collect personal data directly from data subjects. Article 14 covers your responsibilities when you obtain data about the data subject from a third party or indirectly.

It holds that the data subject has the right to ask a data controller what kind of data they process and why the data controller needs it.

What kind of information do you need to provide?

Article 13 holds that you must provide the following information when you collect their data (not after):

  1. Controller identity and contact details and those of the controller's EU representative (if applicable)
  2. Data Protection Officer contact details (if a DPO was appointed)
  3. Legal basis for processing and purposes of processing
  4. Country where the processing occurs
  5. Legitimate interests of the processor and third parties
  6. Any recipients of personal data
  7. Any intention to transfer personal data outside the specified processing place and to a third country (particularly if the country is outside the EU)
  8. Data retention policy (how long data is stored)
  9. Explanation of rights to rectification, erasure, restriction of processing, and portability
  10. Explanation of right to withdraw consent
  11. Explanation of right to complain to the relevant supervisory authority
  12. If data collection is a contractual requirement and any consequences
  13. Existence of profiling and other types of automated decision-making and information about the logic behind them

Article 14 states that you need to provide the same information even if you don't collect the data directly from a data subject.

The right to information is very broad. A data subject can ask what personal data you collect generally, what processors the controller works with, and how the data gets used.

You will uphold the right to information first as part of your Privacy Policy, which is where all the information will be disclosed and made available to your users.

How to Create a GDPR-Compliant Privacy Policy

A GDPR-compliant Privacy Policy must include all of the data points listed above as they pertain to your data processing activities.

In addition to providing all these details, it must be:

  1. Concise
  2. Intelligible
  3. Easy to find
  4. Transparent

Concise refers to including all the relevant information but not including irrelevant or unintelligible details that attempt to hide your processes. It also refers to readability. You might choose to offer both a short Privacy Policy that covers the bases briefly in addition to the full-length policy.

Intelligible refers to both your use of language and the way you display your Privacy Policy.

You must use language that the average person can read and understand (usually a high school reading level). If your site attracts younger visitors, the GDPR expects you to go a step further and write in the appropriate level as a your youngest user (usually the age of consent in the countries where you operate).

Additionally, you should format your Privacy Policy in a way that's easy to read. Don't use tiny print size or an unreadable font. Make it as scrollable as possible and easy to read.

The best policy is to publish your Privacy Policy using the same care as marketing materials. How would you display something that you thought would win you new customers? Use the same logic when uploading your Privacy Policy.

Your Privacy Policy also needs to be easy to find. Data subjects should be able to access it from your home page - not just your legal section. You should also link to it as necessary and ask users to re-affirm their consent every time you update it.

Finally, your Privacy Policy should always be transparent. To be GDPR-compliant and uphold user rights, it must reflect your processing activities as they currently occur.

If you make changes to any part of your processing activities, you need to update your Privacy Policy and share those updates with your data subjects through a consent mechanism or another type of communication.

What Does a GDPR Compliant Privacy Policy Look Like?

A GDPR-compliant Privacy Policy resembles the Privacy Policy you already needed to comply with laws like CalOPPA. However, it does come with new requirements that address novel sections of the law.

In addition to details about your data processing activities, you also need clauses that reflect:

  • Third-party disclosures
  • Cross-border data transfers
  • Data Protection Officer (DPO) (if applicable)
  • User access request mechanisms
  • User rights

Here are a few examples from current Privacy Policies that reflect not only the new required clauses but also the goals of being concise, intelligible, easy to find, and transparent:

Nuffield Health, who processes special categories of data as a health service provider, offers a good example of times when it might disclose personal data to third parties:

Nuffield Health Privacy Policy: Disclosure of your personal data to third parties clause excerpt

Lloyd's Bank provides the conditions upon which it will send your personal data outside of the European Economic Area (EEA). It meets the condition that any transfers meet the same legal requirements placed on data within the EEA:

Lloyds Bank Privacy Policy: Sending data outside the UK and EEA clause

The British Heart Foundation (BHF) is a public body and charity dedicated to funding cardiovascular research. As such, it must have a Data Protection Officer and list the details of the DPO within its Privacy Policy. It does so under the header "Contact Us":

British Heart Foundation Privacy and Cookies Policy: Contact us clause with DPO information

The University of Sheffield discusses user rights including access rights, portability, erasure, restriction/objection, and withdrawal of consent in different sections across its Privacy Policy.

It also added a clause on the consequences of not providing data, which is also required by the GDPR. In this case, the university warns that it could hold incorrect or incomplete records, which could cause headaches for students and staff.

University of Sheffield Privacy Notice: Menu showing GDPR user rights and consequences of not providing data excerpt

Finally, John Lewis, a retailer, discusses the mechanisms by which data subjects can withdraw their consent for direct marketing including clicking unsubscribe links, changing preferences in the "My Account" area or writing to the company:

John Lewis Privacy Notice: Opt out of direct marketing clause with methods

2. The Right of Access

2. The Right of Access

Article 15 outlines the first named right found in the GDPR: the right to access.

The right to access allows the data subject to access the personal data belonging to them that you process.

What does the GDPR say customers have a right to access? In addition to asking specifically about their personal data file, they can ask about:

  • Why and how you process the data
  • Categories of personal data involved
  • Who sees the data (including and especially in countries outside the EU)
  • How long you intend to store the data
  • How to exercise their rights
  • Any available information to the source of data when you do not collect the data from the data subject
  • Your use of profiling and automated decision-making

The right to access adds an extra layer of transparency to your processing activities because it allows data subjects to confirm what data you have compared to the data you say you have. It also sets them up to exercise further rights, like the right to rectification or the right to erasure.

You should know that the law allows data subjects to request a copy of the data at no cost to them. However, if they request multiple copies, you can begin to assess a "reasonable fee based on administrative costs." In other words, you can't ask for an amount of money that would prevent the user from upholding their rights or be seen as punitive.

Provide a Method for Data Requests

The GDPR requires you to have a method by which you handle data access requests from subjects. However, you must also provide a clear and detailed instructions for the mechanism within your Privacy Policy.

You can choose an existing method or create something new and GDPR-specific.

For example, TopShop uses its Privacy Policy to direct all customers to its DPO, who handles the request on the company's behalf. It also allows customers to contact Customer Care at TopShop if they so choose:

Topshop Privacy Policy: User rights and how to use them clause

Alternatively, the University of Manchester created a Subject access request form for data subjects to fill out and provide. It also accepts requests emailed to a data protection office email address:

University of Manchester: Accessing Your Information section with link to subject access request form

Both methods are GDPR-compliant. Whatever you use, be sure to add it to your Privacy Policy and make it freely available on your site.

Don't for to respond to all access requests. See our article for guidance: How to Handle Privacy Access Requests Under the GDPR.

3. The Right to Rectification

3. The Right to Rectification

Article 16, the right to rectification, provides European data subjects with the right to change or modify the data they provide you when they believe the data is inaccurate or out-of-date. You need to provide this "without undue delay."

The right to rectification also goes hand-in-hand with one of the six GDPR Privacy Principles - Data Accuracy - because it places added emphasis on the need for keeping accurate data.

Why is holding accurate data so important for you and your data subjects? Because incorrect data threatens the privacy of other individuals.

For example, if you hold data subject phone numbers, you need to acknowledge that people change their phone numbers from time to time. If you hold old phone numbers that were then given away to new customers, you risk contacting a customer who didn't provide consent.

Holding data and contacting customers without their consent is a GDPR violation.

Moreover, holding outdated or inaccurate data is bad for business. You aren't learning about or reaching your customers if half your email address list bounces.

Processes for Rectification

You need a way for data subjects to come to you with requests to update the data you hold about them.

For many companies, data subjects can update their information on their own time through a customer account and profile.

However, you should also provide a mechanism for the subject to exercise their right either verbally or in writing.

For example, Delta Airlines provides detailed directions in its Privacy Policy regarding correcting or updating personal information or marketing preferences:

Delta Airlines Privacy Policy: Correcting or Updating Your Information or Marketing Preferences clause

Delta makes it easy to update information or correct bad information by allowing users to do it themselves and by providing a number to call for issues they can't correct through their online profile.

4. The Right to Erasure

4. The Right to Erasure

Article 17 describes the user right to erasure, which is better known as the right to be forgotten.

The article says that the data subject has the right to ask a data controller to erase their data without undue delay in the following circumstances:

  • "The personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed"
  • "The data subject withdraws consent on which the processing is based..."
  • "The data subject objects to processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing"
  • "The personal data have been unlawfully processed"
  • "The personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject"

When you make the decision to erase a data subject's data according to the right to erasure, you also need to share the request. All other controllers or processors with whom you have a contract also need to be aware of the erasure so that they can also erase:

  • Links to...
  • Copies of...
  • Replication of the personal data

Do I Have to Comply with a Right to Erasure Request?

In some cases, you do not need to comply with a request to access the right to erasure. The GDPR outlines these circumstances as follows:

  • When your processing involves as a right to the freedom of expression and information
  • When your processing involves compliance with a legal obligation and the public interest
  • When your processing includes reasons of public interest within the realm of public health
  • When your processing meets the guidelines published in Article 89(1) (or public interest, historical or scientific purposes, or statistics purposes)
  • When your processing is for the "establishment, exercise, or defence of legal claims"

If your processing falls under one of these categories and you can demonstrate the case, then you can deny the request for erasure by citing the necessary reason for the rejection in your notice.

How to Share a Data Subject's Right to Erasure

Right to erasure is a complex right that's worth getting to know so as to avoid falling on the wrong side of the law.

In addition to declaring the right to erasure, you should list any reasons why you might not comply with the request as well as how to exercise it.

Northern Rail does an exemplary job of this within its Data Protection Rights section in the company's Privacy Policy.

It says customers can request deletion by contacting Northern:

Northern Rail Privacy Policy: Your Data Protection Rights clause - excerpt about how to access, correct, update or delete personal information

This is a simple and clear way of letting your users know how to exert their rights.

5. The Right to Restriction of Processing

5. The Right to Restriction of Processing

Article 18 outlines the data subject's right to request the restriction of processing under certain conditions. That means you must temporarily stop processing their data as requested as long as their requests meets one of the following:

  • The data subject contests the accuracy of the data
  • The data subject objects to unlawful processing and the data subject prefers you to restrict the processing rather than erasing their data
  • The data controller does not need the data for processing but they need to keep the data pursuant to the "establishment, exercise, or defence of a legal claim"

Article 18(3) states that if you temporarily stop processing data, then you must inform the data subject before lifting the restriction and resuming the processing, if you choose to do so.

What the Right to Restrict Processing Looks Like

To get started, you'll need a method for recognizing and acknowledging the right to restrict processing so that you can honor requests. The right also comes with more communication than others might because it may warrant an investigation as well as several follow-up notices saying that you temporarily suspended processing and informing the subject you started up again.

The user's right to restrict processing also needs to find a home in your Privacy Policy. It's a good idea to not only mention the right but note that it does come with limitations.

Translink, a public transport operator in the UK, lists user rights within its Privacy Policy and then provides a link to a fuller description to the right to restriction processing.

Translink Privacy Policy: GDPR User Rights clause

It provides a direct link to the UK's Information Commissioner's Office for a fuller explanation of the rights.

It then provides a Data Protection Officer contact for the company at the bottom of the Privacy Policy:

Translink Privacy Policy: Contact Us clause

Alternatively, you can list the right to restriction with all the other rights within your Privacy Policy with a short explanation and a guide to accessing the right as Boohoo does:

Boohoo Privacy Notice: GDPR User Rights clause

Further detailed information is set out below the list as noted. Here's the relevant details for the right to restrict processing:

Boohoo Privacy Notice: Request restriction of processing your personal data clause

6. The Right to Data Portability

6. The Right to Data Portability

The right to data portability outlined in Article 20 refers to the data subject's right to receive the personal data held by the data controller in a commonly used format and send the data to another controller or use it for their personal purposes, under certain circumstances.

The law says:

"The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided"

There are conditions to this. It only applies in situations where:

  • Processing is based on consent or a contract, and
  • Processing is done with automated means

Data portability sounds strange. Why would your customers want a copy of their data to send to another company? It is true that the right is a novelty, but experts say that data portability also creates a more user-centric privacy experience and encourages businesses to remain competitive and strive for platforms that coincide with each other.

How to Comply with the Right to Data Portability

To comply with the right to data portability, you need to have a policy in place to receive and recognize the request if it ever comes to you.

Additionally, you'll need to meet technological requirements to do it safely. You need to be able to send the data to the subject's requested controller in a structured format, using a secure method, and within a month of receiving the request.

To demonstrate the right in your Privacy Policy, all you need to do is provide the right and a method of communicating it.

HCA Healthcare UK does exactly that within its Privacy Policy:

HCA Healthcare UK Privacy Policy: GDPR User Rights clause

It notes the "right to move, copy or transfer your personal data ('data portability') and directs users to the relevant email address to make the request.

Note that the email address is customized for such requests as it's "[email protected]" instead of a general contact email address. This isn't necessary but it's a nice touch and will help ensure data rights requests don't get lost in a general inbox.

7. The Right to Object

7. The Right to Object

Article 21 outlines what is known as the right to object.

In simple terms, it says that data subjects have the right to object to your data processing, including profiling, when it is on relevant grounds.

If a data subject uses their right to object, the GDPR says that:

"The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims."

Do you engage in direct marketing? If so, Article 21(2) says the data subject can object at any time when the processing you do relates to direct marketing, and you must comply. For example, if a data subject unsubscribes from your marketing emails, you must not send them any more emails until and unless they provide consent for you to do so.

The GDPR takes the right to object seriously. You need to share the right to object with every data subject ASAP or "at the latest at the time of the first communication with the data subject."

The only real exceptions to the rule are when you process data for research purposes (historical, scientific, or statistical) and in cases when the data is essential for the public interest.

Disclosing the Right to Object

When you have policies in place for handling verbal and written requests to object to data processing, you also need to place it in our Privacy Policy to inform individuals of their right and your process.

Another example from Delta Airlines demonstrates a well-thought out meaning of the right:

Delta Airlines Privacy Policy: Right to object to processing clause

The clause notes that:

  • Customers can object at any time when the objection relates to marketing
  • Customers can object when the data processing is in Delta's interest and Delta must suspend the processing
  • Delta has the right to establish grounds for continued processing that allow it to continue using the data

8. The Right to Avoid Automated Decision-Making

8. The Right to Avoid Automated Decision-Making

The eighth and final right offered by the GDPR lies in Article 22: Automated decision-making, including profiling. It says:

"The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly affects him or her"

The right to avoid automated decision-making comes with three exceptions when it cannot be exerted:

  1. When automated decision-making is necessary to enter into or complete a contract
  2. When the control has authorization from the EU or a Member State and uses safeguards to protect the subject's interests and freedom
  3. When the profiling or decision-making occurs with the subject's explicit consent

Although the GDPR applies to any and all individual decision-making, the most common examples that the right supports tend to be financial. For example, if you are a EU resident who applies for a loan using a bank's online application, then you can appeal the decision because the outcome impacts your legal rights and freedoms.

If you use automated decision-making in any form, you need to identify it and then:

  • Tell data subjects you use it
  • Create ways to request human intervention
  • Update and maintain your systems to avoid malfunction

Deploying the Right to Avoid Automated Decision-Making

Generally, you'll need to do three things to uphold the eighth user right.

First, you need to complete a Data Protection Impact Assessment (DPIA) for your current and any future profiling or automated decision-making tools. Your DPIA should also ensure there are checks in place to protect children and other vulnerable groups.

Second, you need to share how the decision-making process works and how you access the data subject information used for profiling.

Third, you need to explain to customers that you use the mechanism and why it is relevant to your legal processing basis.

You should list this at a minimum within your Privacy Policy with a discussion of your practices, if they play a large role in your operations.

Bank of Ireland uses automated decision-making as part of its core work when making lending decisions, so it dedicates an entire section of its Data Privacy Notice to the topic:

Bank of Ireland Data Privacy Notice: Automated Processing clause excerpt

The section clearly describes the processes, including what data it uses to complete the process.

To supplement this, Bank of Ireland also created a Data Subject Rights page that provides mechanisms for each right including the right to object to profiling:

Bank of Ireland Object to Automated Decision Making request screen


GDPR logistics may largely apply to businesses (as data controllers and processors), but the spirit of the law lies in protecting your customers and data subjects.

Each of the user rights reflects the principles of accountability and transparency woven through the entire text of the legislation. Each principle allows data subjects to not only see what data you have but it allows them to update it appropriately and even stop you from processing it in some cases.

The eight user rights enshrined in the GDPR must be upheld through your business practices and on display in your Privacy Policy. Failing to uphold any of these rights among EEA residents will lead to a GDPR violation and significant fines.