Back to blog
01/09/2026

Personal data in Europe: what are your rights and how can you exercise them?

Access, rectification, erasure, portability, objection: the GDPR gives you concrete rights. Here is what they cover, their limits and the steps to take when dealing with an organisation.

Illustration of a protected digital profile in front of a circle of European stars.
Privacy8 min read
Illustration: IRSOY

Creating an account, shopping online, using an app or booking an appointment leaves data behind: identity, IP address, location, history, preferences, photos, login details or payment information. In the European Union, this data does not become the unrestricted property of the organisation that collects it.

The General Data Protection Regulation, known as the GDPR, gives everyone a set of rights to understand and control how their personal data is used. These rights also apply to companies established outside the Union when they offer goods or services to people within it or monitor their behaviour under the conditions set out in the regulation.

They do not allow you to demand any action in every circumstance. Each right has a scope, conditions and sometimes exceptions. The key is to ask precisely for what you want and keep a record of the exchanges.

What is personal data?

Personal data is information relating to an identified or identifiable natural person. A name is an obvious example, but a combination of details can also make identification possible: a customer number, advertising identifier, vehicle registration number, location data or IP address.

Some data receives greater protection, particularly data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, health, sex life or sexual orientation, as well as certain genetic and biometric data.

Information that has genuinely been anonymised irreversibly falls outside the scope of personal data. Pseudonymised data, however, remains personal when it can be linked to a person using additional information.

The right to be informed

An organisation must explain, in clear language, who processes the data, why, on what legal basis, for how long, with which recipients and which rights can be exercised. It must also disclose relevant international transfers and provide the contact details of the data protection officer where there is one.

This information usually appears in a privacy policy or at the point of collection. A vague phrase such as “improving the experience” is not always enough to explain the purposes in concrete terms.

Consent is not the only possible basis. An organisation may also process data to perform a contract, comply with a legal obligation, protect vital interests, carry out a task in the public interest or pursue a legitimate interest under certain conditions.

The right of access

You can ask whether an organisation processes data concerning you. If it does, you can obtain a copy along with information about the purposes, categories of data, recipients, retention period and, where the data did not come from you, any available information about its source.

The right of access must not adversely affect the rights and freedoms of others. A company may therefore need to redact information concerning a third party, but it cannot use this constraint as an excuse to refuse the entire request.

A useful request can refer to a specific account, period or processing activity. This makes the search easier while avoiding inadvertently limiting your rights.

The right to rectification

Inaccurate data can have real consequences: an order sent to the wrong address, a refusal based on an incorrect file or a profile built on outdated information.

You can ask for incorrect data to be corrected and incomplete data to be completed. Clearly identify the information concerned, the correction you expect and, if necessary, provide proportionate supporting evidence.

The right to erasure

The “right to be forgotten” allows you to request erasure, in particular when data is no longer needed, has been processed unlawfully, must be deleted to comply with a legal obligation, or when withdrawn consent was the basis for the processing and no other basis applies.

This right is not absolute. An organisation may need to retain certain information to comply with the law, exercise or defend a legal claim, carry out a task in the public interest or protect freedom of expression and information.

For example, closing an account may justify deleting the public profile and marketing preferences, without allowing the immediate erasure of invoices that the company is legally required to keep.

Data provided when a person was a child receives particular attention. The GDPR provides for the possibility of requesting its deletion even after the person has reached adulthood.

The right to restriction of processing

Restriction allows certain uses to be paused temporarily while the data is retained. It can be requested when you contest the accuracy of the data, when the processing appears unlawful but you prefer restriction to erasure, or while an objection is being examined.

During this period, the organisation may in principle no longer process the data beyond storing it, except in the situations provided for by the GDPR, for example with your consent or to defend a legal claim.

The right to data portability

Portability makes it easier to move from one service to another. Where it applies, you can receive the data you have provided in a structured, commonly used and machine-readable format, then transmit it to another data controller.

This right concerns automated processing based on consent or a contract. It does not automatically cover every analysis the company has created from your data and must not adversely affect the rights of third parties.

A technically usable archive is more consistent with the purpose of portability than a printed document or a file that is difficult to reuse.

The right to object

You can object to processing based on legitimate interests or a task in the public interest on grounds relating to your particular situation. The organisation must then stop processing the data unless it demonstrates overriding compelling legitimate grounds or the processing is necessary for the defence of legal claims.

For direct marketing, the right is stronger: when a person objects, their data must no longer be used for that purpose. An unsubscribe link must work without an unnecessarily complicated process.

The right to withdraw consent

When processing is based on your consent, you can withdraw it at any time. Withdrawing consent must be as easy as giving it in the first place and does not retrospectively invalidate what was lawfully done before its withdrawal.

The organisation must then stop the processing concerned if it has no other valid legal basis. It cannot turn withdrawn consent into a vague justification after the fact without explaining the basis that actually applies.

Fully automated decisions

Under the conditions set out in the GDPR, you have the right not to be subject to a decision based solely on automated processing when it produces legal effects or similarly significantly affects you.

There are exceptions, particularly when the decision is necessary for a contract, authorised by a law that provides safeguards or based on explicit consent. In the situations provided for, you must be able to obtain human intervention, express your point of view and challenge the decision.

This right does not concern every film recommendation or ranking with no significant consequences. It becomes particularly relevant when a system alone decides on credit, recruitment, essential access or a price that has a significant impact.

How to exercise a right effectively

Contact the data controller. Its contact details are usually in the privacy policy. Where a data protection officer, or DPO, is listed, you can write to them directly.

Your request should include:

  • your identity and the account or service concerned;
  • the right you wish to exercise;
  • the data, operations or periods covered;
  • the outcome you expect;
  • an address where you can receive the response;
  • the details strictly necessary to verify your identity.

Do not send a full copy of your identity card unprompted if it is not necessary. The organisation may request additional information when it has reasonable doubts about identity, but verification must remain proportionate.

Keep a dated copy of the request, the acknowledgement of receipt and every response. An online form can be convenient, but a screenshot or email allows you to keep a record.

How long does the organisation have to respond?

The response must arrive without undue delay and, in principle, within one month of receipt. For a complex request or several simultaneous requests, the deadline may be extended by a further two months. However, the organisation must inform you of this extension and its reasons within the first month.

Exercising your rights is in principle free of charge. In the case of manifestly unfounded or excessive requests, particularly repetitive ones, the organisation may, under certain conditions, charge a reasonable fee or refuse to act. It must be able to justify its decision.

If it refuses, it must explain why and inform you of the possibility of contacting the data protection authority and seeking a judicial remedy.

What should you do if there is no response?

Start with a follow-up, reminding the organisation of the date and subject of the request. Also check that you used an official channel and responded to any reasonable identity verification request.

If there is still no response or it remains inadequate, you can contact your country's data protection authority. In Belgium, the Data Protection Authority generally recommends first exercising your rights with the organisation and keeping all correspondence. It offers mediation and a complaints procedure depending on the situation.

For cross-border processing, European authorities cooperate. In principle, you can contact the authority in the place of your habitual residence, your place of work or the place of the alleged infringement.

Legal action and, where material or non-material damage is demonstrated, a claim for compensation may also be possible. A complex case warrants advice from a legal professional.

Conclusion

The GDPR is about more than a cookie banner. It gives you concrete ways to find out about, correct, retrieve, restrict or stop certain uses of your data.

To obtain a useful response, make a precise request, send it to the right controller and keep evidence of it. The organisation normally has one month to respond. If it refuses or ignores the request, it must be able to explain this, and the national data protection authority can be contacted.

This article provides general information and does not replace legal advice tailored to a particular situation.

Useful sources