What Are Your Customers’ Rights Under GDPR?

Date: 29/07/2026

The eight data subject rights under GDPR — hexagon illustration

Why every business owner should know these

Somewhere in GDPR’s fine print are eight rights that belong to every person whose data you hold — customers, subscribers, job applicants, anyone. You don’t need to memorise the legal text. You do need to recognise a rights request when it lands in your inbox, because most of them come with a one-month clock attached.

This is the first in a short series. Here, we’re covering all eight at a glance. In the next two pieces, we go hands-on with the two that come up most in practice: deleting a customer’s data, and correcting or handing over what you hold.

The eight rights, briefly

  • The right to be informed. People have a right to know, in plain language, what data you collect about them and why — usually covered by your privacy policy. (Articles 13–14)
  • The right of access. Anyone can ask what personal data you hold about them and get a copy. This is the most common request small businesses receive. (Article 15)
  • The right to rectification. If something’s wrong or incomplete — an old address, a misspelled name — the person can ask you to fix it. (Article 16)
  • The right to erasure. Also called the “right to be forgotten.” People can ask you to delete their data, though this right has real limits. (Article 17)
  • The right to restrict processing. Instead of deleting data outright, someone can ask you to “pause” using it — for example, while a dispute about accuracy is being resolved. (Article 18)
  • The right to data portability. People can ask for their data in a format they can take elsewhere, mainly relevant if you process data by consent or under a contract, using automated means. (Article 20)
  • The right to object. Individuals can object to certain processing — most commonly direct marketing. An objection to marketing must be honoured immediately, no exceptions. (Article 21)
  • Rights related to automated decision-making and profiling. People have the right not to be subject to a purely automated decision with legal or similarly significant effects on them (think automated credit scoring) without some form of human involvement. (Article 22)

None of these rights are unconditional

This trips people up in both directions. Some business owners panic and think any request means immediate, total compliance no matter what. Others assume they can always say no. Neither is right. Each right has its own conditions and exceptions — the right to erasure, for instance, doesn’t override a legal obligation to keep invoice records. Understanding the specific right being invoked is what determines your actual obligation.

What this means day to day

A request can arrive as a casual email — “can you tell me what you have on me?” — and still be a formal exercise of a GDPR right, response clock included. A few habits keep this manageable:

  1. Know the eight rights well enough to recognise which one a request maps to.
  2. Have a simple internal process for locating a person’s data across your systems.
  3. Track the one-month deadline from the day the request arrives.
  4. When in doubt about an exception or limit, ask before you refuse or before you delete something you’re legally required to keep.

We’ll go deeper into the two most common scenarios — erasure, and access/rectification — in the next two articles in this series.

Not sure how to handle a rights request? Let’s Talk GDPR.

Related reading


References

  1. GDPR Chapter III (Articles 12–23), Rights of the Data Subject.
  2. GDPR Articles 13–14 (right to be informed); Article 15 (access); Article 16 (rectification); Article 17 (erasure); Article 18 (restriction); Article 20 (portability); Article 21 (object); Article 22 (automated decision-making).
  3. EDPB Guidelines & Recommendations.
Latest Articles & Insides