Data Subject Rights Explained
The UK GDPR gives individuals a set of rights over their own personal data. Understanding them helps you respond correctly and build systems that make compliance straightforward.
This is general guidance to orient your team; specific requests can raise nuances worth checking carefully.
The Main Rights
- To be informed about how their data is used.
- To access a copy of their data.
- To have inaccurate data corrected.
- To have data erased in certain circumstances.
- To restrict or object to certain processing.
- To data portability in some cases.
Time Limits Matter
You generally have one calendar month to respond to a request, which can be extended for complex cases. Acting promptly and keeping a record of the request and your response is essential.
Designing for Rights
Systems that can find, export and delete a person's data quickly turn a stressful obligation into a routine task. We build this capability into the products we deliver.
| Right | Typical action |
|---|---|
| Access | Provide a copy of their data |
| Rectification | Correct what is wrong |
| Erasure | Delete where there is no overriding reason to keep it |
| Objection | Stop the processing unless justified |
If you need a hand with any of this, your Progressive Robot delivery team is ready to help. Raise a ticket from the Support area of your client portal or speak to your account manager and we will guide you through the next steps.