- 6 June 2026
- GDPR
What Rights Do Individuals Have Under GDPR?
Most people have heard of GDPR, but far fewer could confidently name the rights it actually gives them. Since the General Data Protection Regulation came into force across the UK and EU in May 2018, individuals have held a meaningful set of legal protections over how their personal data is used, stored, and shared. These aren’t abstract legal concepts — they are practical rights that anyone can exercise.
Understanding what those rights are, and when they apply, matters whether you’re a member of the public wanting to know what a company holds about you, or a business trying to stay on the right side of the law.
How Many Individual Rights Does GDPR Actually Provide?
This is one of the most searched questions on the topic, and the answer is clear: GDPR provides eight distinct rights to individuals. Many sources refer to five or six key rights, but the full framework established under the UK GDPR contains eight in total. Each right exists to give individuals a degree of control over their personal data that simply didn’t exist in a meaningful, enforceable way before 2018.
The eight rights are: the right to be informed, the right of access, the right to rectification, the right to erasure (often called the “right to be forgotten”), the right to restrict processing, the right to data portability, the right to object, and rights related to automated decision-making and profiling. Not all rights apply in every situation, and some are subject to exemptions, but all eight are part of the legal framework that organisations operating in the UK must respect.
| GDPR Individual Right | What It Allows |
|---|---|
| Right to be informed | Know how and why your data is being used |
| Right of access | Request a copy of your personal data (Subject Access Request) |
| Right to rectification | Have inaccurate data corrected |
| Right to erasure | Ask for your data to be deleted in certain circumstances |
| Right to restrict processing | Limit how your data is used while a dispute is resolved |
| Right to data portability | Receive your data in a usable format and transfer it |
| Right to object | Object to processing, including direct marketing |
| Rights re: automated decisions | Challenge decisions made solely by automated means |
Looking for some GDPR and Data Support? Speak with a member of our Data Team Here
What Are the Five Most Commonly Exercised Individual Rights Under GDPR?
While all eight rights exist in law, five of them come up most frequently in practice. The right of access is arguably the most well-known: it allows any individual to submit a Subject Access Request (SAR) to an organisation and receive a copy of the personal data held about them, typically within one calendar month. The right to erasure is similarly prominent, particularly in contexts such as unwanted marketing databases or outdated online records.
The right to rectification allows individuals to have incorrect information put right — something that matters enormously in areas like credit referencing or medical records. The right to object gives individuals the power to stop certain types of data processing, including direct marketing, with no need to provide a reason for objecting to marketing specifically. The right to be informed underpins everything else: organisations must tell individuals clearly what data they collect, why they collect it, and how long they plan to keep it, typically via a privacy notice.
The 7 GDPR Principles Every Organisation Must Follow
The individual rights discussed above sit within a broader framework of seven core data protection principles. These principles govern how organisations must handle personal data at every stage, and they apply regardless of whether an individual has exercised any of their rights. The seven principles are: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
Each principle has practical implications. Purpose limitation means data collected for one reason cannot simply be repurposed without a fresh lawful basis. Data minimisation requires that organisations only collect what is genuinely necessary. Storage limitation means personal data should not be kept longer than needed. The accountability principle is particularly significant: it places the burden of proof on organisations to demonstrate compliance rather than simply claiming it. The Information Commissioner’s Office (ICO) publishes detailed guidance on each of these principles for organisations that need to understand how they apply in practice.
| GDPR Principle | Core Requirement |
|---|---|
| Lawfulness, fairness and transparency | Processing must have a valid lawful basis and be open with individuals |
| Purpose limitation | Data may only be used for its originally stated purpose |
| Data minimisation | Only collect what is strictly necessary |
| Accuracy | Data must be kept up to date and corrected when wrong |
| Storage limitation | Data must not be retained longer than necessary |
| Integrity and confidentiality | Appropriate security measures must protect personal data |
| Accountability | Organisations must be able to demonstrate compliance |
Organisations found to be in breach of these principles face significant consequences. The ICO has the power to issue fines of up to £17.5 million or 4% of global annual turnover under the UK GDPR, whichever is higher. For a small business, that kind of exposure is not hypothetical — it is a real operational risk that takes proper data governance to manage.
The UK GDPR legislation on GOV.UK sets out the full legal text for those who need to go beyond guidance and into the precise wording of the law.
What Your GDPR Rights Mean for You in Practice
Knowing the rights exist is one thing. Knowing how to use them is another entirely. If you want to know what personal data a company holds about you, you can submit a Subject Access Request in writing, and the organisation must respond within one month at no charge (unless the request is manifestly unfounded or excessive). If the data they hold is wrong, you can ask them to correct it. If you want your data deleted and there is no longer a legitimate reason to hold it, you can ask for it to be erased.
These rights are not optional extras that businesses can choose to offer. They are legal entitlements, and organisations that ignore, delay, or obstruct them risk complaints to the ICO and formal enforcement action. If an organisation you’ve contacted has failed to respond to a rights request within the statutory timeframe, you are fully within your rights to escalate the matter.
Understanding What Rights Do Individuals Have Under GDPR
GDPR individual rights represent one of the most significant shifts in the relationship between people and the organisations that hold their data. The eight rights, underpinned by seven core principles, create a coherent framework where individuals are not passive subjects but active participants with real legal power. Exercising those rights has become progressively more straightforward, and awareness among the general public continues to grow year on year.
For businesses, compliance is not just a legal obligation — it is a matter of trust. Organisations that handle personal data with transparency, respond to rights requests promptly, and adhere to the seven principles are better positioned to build lasting relationships with clients and customers. Those that treat GDPR as a box-ticking exercise tend to find themselves on the wrong end of ICO investigations at precisely the moment they can least afford it.
Whether you’re an individual wanting to understand what a company knows about you, or a business building its data governance from the ground up, the rights and principles laid out in UK GDPR provide a clear and fair foundation. The law is well-established, the regulator is active, and the protections it offers are yours to use.
- GDPR grants individuals eight distinct rights over their personal data, from access and rectification through to objection and protection from automated decision-making.
- The seven data protection principles govern how organisations must handle personal data at every stage, placing accountability squarely on the data controller.
- Individuals who believe their rights have been breached can complain directly to the ICO, which has significant enforcement powers including substantial financial penalties.
What Rights Do Individuals Have Under GDPR: Frequently Asked Questions
UK GDPR provides eight individual rights, covering everything from access to your own data through to the right to challenge automated decisions. Not every right applies in every situation, and some are subject to legal exemptions.
A Subject Access Request (SAR) is a formal request made to an organisation asking for a copy of the personal data they hold about you. Organisations must respond within one calendar month and cannot charge a fee for a standard request.
Yes, under the right to erasure you can ask an organisation to delete your personal data, though this right is not absolute. It applies in specific circumstances, such as when the data is no longer necessary for the purpose it was collected.
The right to data portability allows you to receive your personal data in a structured, commonly used, and machine-readable format. You can then transfer that data to another service provider if you choose to do so.
The right to erasure asks for data to be deleted entirely, whereas the right to restrict processing asks an organisation to pause what they are doing with your data while a matter is resolved. Both rights give you control, but in different ways.
GDPR only applies to living individuals, so personal data relating to someone who has died is not protected under the regulation. Some other laws and organisational policies may still apply in such cases, however.
The seven principles are lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. You can read a comprehensive explanation of each principle on Wikipedia's GDPR article.
Yes, the right to object gives you an absolute right to stop an organisation using your personal data for direct marketing. Once you object to marketing, the organisation must stop immediately with no exceptions.
If an organisation fails to respond to a valid rights request within one month, you can complain to the Information Commissioner's Office. The ICO has the power to investigate and issue enforcement action where appropriate.
Yes, some rights can be limited or do not apply in certain contexts, such as where processing is necessary for law enforcement purposes, national security, or public health. Each exemption has specific conditions and cannot be applied broadly.
The right to be informed requires organisations to tell individuals what personal data they are collecting, why they are collecting it, how long they will keep it, and who they share it with. This information is typically provided through a privacy notice or policy.
Yes, UK GDPR applies to any organisation that processes personal data, regardless of size. Small businesses handling customer or employee data are subject to the same legal obligations as large corporations.
Rights requests do not need to be made in writing — you can make a verbal request, and the organisation is still obliged to respond. However, submitting a request in writing gives you a clear record and makes it easier to escalate if the organisation does not respond.
You can report concerns or make a formal complaint to the Information Commissioner's Office via GOV.UK. The ICO is the UK's independent authority for data protection and has the power to investigate complaints and take enforcement action.
Understanding the principles and obligations is one thing; embedding them into daily operations is where compliance becomes real. For most UK businesses, the starting point is a data audit: mapping what personal data you hold, where it came from, where it is stored, who has access, and why you hold it. This exercise tends to reveal gaps that are far easier and cheaper to fix early than to defend against later.
From there, compliance becomes a matter of systematic documentation and staff culture. Privacy notices must be clear and accessible. Data subject requests must be handled within the one-month deadline. Staff need to know how to recognise a data breach and who to report it to. These are not complicated processes, but they require someone in the organisation to own them and keep them current as the business evolves.
The businesses that manage UK GDPR compliance most effectively are not necessarily the ones with the largest legal budgets. They are the ones that treat data protection as part of good business practice rather than a regulatory burden. Building that mindset across a team takes time, but it is the surest foundation for long-term compliance and the trust it brings with customers and partners alike.
- The seven principles of UK GDPR provide the framework for all lawful data processing, requiring that personal data is collected fairly, used only for its stated purpose, kept accurate and secure, and not held longer than necessary.
- Choosing the correct lawful basis for each processing activity and documenting that decision in a ROPA is one of the most fundamental and frequently overlooked steps in achieving genuine UK GDPR compliance.
- The cost of GDPR compliance in the UK varies considerably by organisation size and processing risk, but the mandatory ICO data protection fee, staff training, and clear privacy documentation are baseline requirements for virtually every business that handles personal data.
gements is £17.5 million or 4% of global annual turnover, whichever is higher. Lower-tier penalties of up to £8.7 million or 2% of global turnover apply to less severe breaches, such as failures in record-keeping or notification obligations.
It is worth noting that the ICO’s approach is generally graduated and takes organisational size and intent into account. A small business that has made a genuine effort to comply but makes an administrative error is unlikely to face the same response as a large organisation that has wilfully ignored its obligations. That said, data breaches that affect large numbers of individuals, particularly where sensitive categories of data are involved, are treated seriously regardless of the size of the organisation responsible. Organisations experiencing a personal data breach that is likely to pose a risk to individuals must notify the ICO within 72 hours under UK GDPR Article 33.