The two rights you’ll actually deal with most
In the last article in this series, we covered what happens when a customer asks you to delete their data (A Customer Asked You to Delete Their Data). This one covers the two rights you’re more likely to see day to day: someone asking what you hold about them (the right of access), or asking you to fix something that’s wrong (the right to rectification). Both are part of the broader set of rights GDPR gives every individual (What Are Your Customers’ Rights Under GDPR?).
Neither is complicated once you’ve done it once. Here’s the practical version.
Right of access: “What do you have on me?”
Anyone can ask what personal data you hold about them, and you have to give it to them — within one month (Article 12(3)), free of charge (Article 12(5)). This is called a subject access request, or right of access (Article 15), and it’s the single most common rights request small businesses receive.
What you actually need to provide:
- Confirmation that you’re processing their data
- A copy of the data itself
- In plain terms: why you’re processing it, who you might share it with, and how long you intend to keep it
You don’t need to hand over a legal document. A clear email with the information, or an export from your CRM/booking system, is enough. If a request is manifestly unfounded or excessive — particularly because it’s repetitive — you’re allowed to charge a reasonable fee or decline (Article 12(5)), but that’s the exception, not the starting assumption.
Right to rectification: “That’s wrong, please fix it”
If someone spots an error — an old address, a misspelled name, an outdated phone number — they can ask you to correct it (Article 16). This one is genuinely simple: verify the correction is legitimate, update it everywhere the data lives, and confirm back to them. There’s no real judgment call here the way there sometimes is with erasure.
The retention question access requests always raise
Answering an access request often means looking at data you’ve been holding for a while, which naturally raises the same question as a deletion request: should you even still have this? The answer comes back to the storage limitation principle — you’re only entitled to keep personal data for as long as it serves the purpose you originally collected it for, or as long as a legal obligation requires (tax records being the classic example).
This means an access request is a good moment to do a quick sanity check on your own retention practices, not just answer the question asked. If you find data that’s outlived its purpose while fulfilling the request, that’s a sign to clean it up — not a compliance failure, just good practice.
Step by step
- Confirm identity. Same principle as erasure — reasonable confidence it’s genuinely them, not a demand for full ID verification.
- Work out which right is being invoked. “What do you have on me” is access. “This is wrong, fix it” is rectification. Sometimes it’s both.
- Locate the data. CRM, email marketing tool, booking/POS system, spreadsheets — the same places you’d check for a deletion request.
- For access: compile it into something readable. For rectification: correct it everywhere it appears.
- Reply within one month, in plain language.
- While you’re in there, ask whether anything you found should have been deleted already under your own retention rules — the same lawful-basis question covered in What is a Lawful Basis Under GDPR? and A Customer Asked You to Delete Their Data.
Common mistakes to avoid
- Treating an access request like an interrogation — asking for excessive proof of identity discourages legitimate requests and can itself look like obstruction.
- Only fixing the correction in one system — the old, wrong address often survives in three other places.
- Charging a fee by default — a request is free unless it’s genuinely manifestly unfounded or excessive (Article 12(5)); “we always charge for copies” is not a valid default.
Handled well, these requests are quick, low-risk, and a genuine trust-builder with customers who are simply curious or looking out for their own accuracy.
Not sure how to handle an access or correction request? Let’s Talk GDPR.
Related reading
- What Are Your Customers’ Rights Under GDPR?
- A Customer Asked You to Delete Their Data — Here’s What to Do Next
- What is a Lawful Basis Under GDPR?
- GDPR Glossary
References
- GDPR Article 12(3) — one-month timescale for responding to requests.
- GDPR Article 12(5) — free of charge, and when a fee or refusal is permitted.
- GDPR Article 15 — right of access.
- GDPR Article 16 — right to rectification.
- GDPR Article 5(1)(e) — storage limitation principle.