People’s GDPR Rights Explained

Problem: People’s GDPR rights, as set out in the EU and UK GDPR (general data protection regulations) give control over how their personal information is used in certain circumstances. These rights are not well understood, not absolute in most instance, and are sometimes mutually exclusive.

Solution: having an understanding of what people’s GDPR rights and how they work will help ensure compliance, and maintain relationships with the people whose data you need to use.

Any organisation that processes personal data – be it of customers, employees or other individuals – must comply with people’s GDPR rights. They are a key pillar of data protection because they give people control over how their data are used.

Failure to do so is a violation of the GDPR and could lead to legal action by regulators like the information commissioner and/or civil action by data subject.

The general data protection regulation does not apply to purely personal processing e.g. when an individual posts a family photo online.

But first, what is a data subject?

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

What is a data subject?

A data subjects is a living individual whose personal information is collected, held or processed by an organisation. Personal data is any information that by itself or in combination of other data could lead to a person being identified. For example name, address or date of birth.

People’s GDPR Rights

The right to be informed

Organisations need to tell individuals what data is being collected, how it’s being used, how long it will be kept and whether it will be shared with any third parties. This information must be communicated concisely and in language that is appropriate for the intended audience.

The UK GPDR says you must tell people about their data processing activities when the data are collected or as soon as possible thereafter. Organisations typically comply with this right by publishing a comprehensive privacy statement on a specific page on their website.

Privacy statements also include the contact details of the organisation’s Data Protection Officer (if there is one) and guide people on how they can request compliance with their other rights too. Finally they should set out how people can make a complaint.

Naturally to comply with this right you must understand all of your data processing activities, whether you are a controller or processor.

Related Content: Top Five Things Organisations Get Wrong with Their Privacy Statements

The right of access

The right of access is similar to the old right to make a subject access request (SAR). When people made a SAR they got a copy of the information held about them.

This right goes further. Alongside a copy of the information held an organisation need also to explain a lot more information, including:

  • the type of information you have about an individual

  • the lawful basis for processing the information

  • whether the information is being sent abroad

  • how long the information will be retained for

in addition this right is forward looking and envisages people having access to companies’ systems so they can access information about themselves proactively.

The right of access (still often called SARs) must be complied with within one month in most instances, and must be done free of charge.

Like the old SAR someone is not entitled to information about a third party, and there are some other exemptions to disclosure, which means a lot of what is shared might be redacted or incomplete.

It is important to know that people do not have to exercise this right in writing, and they do not need to give their reasons for their requests. However in a number of cases you can ask people to clarify what they are looking for in order to help meet your obligations.

Related content: when to refuse a subject access request

The right to rectification

If an someone discovers that the information an organisation holds on them is inaccurate or incomplete, they can request that it be updated. As with the right of access, organisations have one month to do this, and it must be done free of charge.

The right to rectification is not absolute. For example if a person does not agree with opinions about them that you have in your records they are not entitled to have it changed just because they disagree. Disagreeing with opinions doesn’t mean they are inaccurate. It is still, however, important to record a person’s objection. The right only applies if opinions are not recorded accurately.

If you choose not to comply with a person’s request to rectify their data you have an obligation to explain to them why not.

If you do comply with the request you must also ensure any third party you have shared the data with also updates their records.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

The right to erasure

The right to erasure is also known as ‘the right to be forgotten’. It allows people to have their data deleted in certain circumstances.

The circumstances partly depend on the lawful basis under which you are processing personal information. For example if you are relying on consent then there is no reason not to comply if data subjects withdraw consent.

An individual cannot object to you retaining their data if you are processing it to deliver a contract, for example, and in some circumstance you might chose to retain personal data to initiate or defend yourself in a legal case.

As before if you decide not to comply with this right you must explain your decision.

The right to restrict processing

Individuals can request that an organisation limits the way it uses personal data in certain circumstances.

It’s an alternative to requesting the erasure of data and might be used when people are exercising other rights. An example is while you are making a decision on whether to rectify people’s data.

People can also apply the restriction if they want you to keep a copy of their data, but do not want you to use it.

The right to data portability

Someone can have their data transferred from one data controller to another. Like the right of access, this month be done free of charge and the time limit for compliance is one calendar month.

You can comply with this right in two ways. You can give the personal data to the individual directly, or you can pass it to the third party they nominate.

Complying with the right to data portability requires you to pass over the data in a machine readable format.

The key restriction on this right is that it only applies to data you have provided to the data controller directly, and that is help in electronic form. In addition it applies when the lawful basis for processing data is consent, or on the basis of a contract. As before requests do not need to be made in writing.

The right to object

One of people’s GDPR rights is the right to object. People can object to the use of their data for a number of reasons. This right is different to the right to restrict processing, which allows for processing to continue in some circumstances.

Unlike other rights people must explain the grounds for their objection. This will inform whether you will continue processing their personal data or not.

The grounds people can object to the processing of their personal data include for:

  • a task carried out in the public interest;

  • the exercise of official authority;

  • their legitimate interests;

  • scientific or historical research, or statistical purposes; or

  • direct marketing purposes.

Organisations have an obligation to comply with the right to object, unless they can give compelling reasons not to. That means you must show how your interests in processing the data outweigh a person’s objecting to it.

Rights related to automated decision making including profiling

This is one of the most forward-looking of people’s GDPR rights. Automated decision making is when decisions are made with no human involvement. Profiling means automating decisions on personal data to make calculated assumptions about individuals. In a number of cases this type of processing is done when people make an application online for a loan or credit care.

You have a number of obligations under the UK GDPR when it comes to automated decision making and profiling. In particular individuals are entitled to know:

You can only process data in this way if it is:

  • for the performance of a contract;
  • purposes authorised in law; or
  • with an individual’s explicit consent.

In addition you must be explicit if you do this kind of data processing.

Finally people have the right to request decisions are made about them in a different way.

Related Content: Automated Decision Making and Profiling

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial

GDPR Rights: What Happens if You Don’t Comply?

The Information Commissioner takes the obligation to comply with people’s GDPR rights very seriously. They may investigate any complaint made to them and open a case against anyone who is not compliant. You may have reasons why you could not comply with any particular obligation, like responding to requests in good time. The information commissioner will take these into account in order to decide what type of action to take. This could include a fine. However the way the information commissioner responds to complaints will depend in each case on several factors. Factors like the severity of the failure and how often breaches of the UK GDPR have occurred.