All resources
Guide 7 min read

GDPR data-subject rights: what you must deliver (Arts 15–22)

C1The Compliance One team20 September 2026

The part of GDPR your customers feel most directly is the set of rights it gives individuals over their own data. Articles 15 to 22 spell them out, and any of them can arrive in your inbox as a data-subject request (a DSR) on any given Tuesday. When one does, a clock starts: you generally have one month to respond, extendable by two further months only for complex or numerous requests, and you must tell the person about the extension.

The rights are not equally common, and they are not absolute. Knowing which is which, and where the exemptions sit, is the difference between a calm reply and a panicked one.

The rights, in order of how often you will see them

  • Access (Article 15): a copy of their personal data plus information about how and why you process it. This is by far the most common request.
  • Rectification (Article 16): correct inaccurate data, or complete data that is incomplete.
  • Erasure (Article 17), the 'right to be forgotten': delete their data where one of the listed grounds applies. It is not an unconditional right, and legal-retention obligations can override it.
  • Restriction (Article 18): pause processing while a dispute (for example over accuracy) is resolved.
  • Portability (Article 20): provide the data they gave you in a structured, commonly used, machine-readable format, where processing is based on consent or contract and is automated.
  • Objection (Article 21): stop processing based on legitimate interests or direct marketing. For direct marketing, the objection is absolute.
  • Rights around automated decisions (Article 22): not to be subject to solely automated decisions with legal or similarly significant effects, without safeguards.

The deadline is not the hard part. Finding every copy of a person's data across your systems, in a month, without a rehearsed process, is the hard part.

What answering a request really involves

The mechanics catch teams out. First you verify identity, so you do not hand someone else's data to an impostor. Then you locate the data, which for a typical SaaS means the app database, the data warehouse, support tickets, logs, backups and every third-party processor you have sent it to. Then you decide whether any exemption applies, redact third-party personal data that appears in the response, and reply in an intelligible form within the month. Do that ad hoc, per request, and it eats days.

How to make DSRs boring

The fix is a repeatable workflow with the clock built in. Compliance One gives you a data-subject-request queue where each request is logged, the one-month SLA is tracked automatically, and the steps (verify, locate, review exemptions, respond, record) are the same every time. Your Record of Processing tells you which systems and processors hold the data, so locating it is a lookup rather than an archaeology dig. The whole thing is cross-mapped to your ISO 27701 rights controls, so the evidence that you handle rights properly is a by-product of actually handling them, not a separate documentation project.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map this to your environment.