Data Subject Rights
Data subject rights are the legally recognized abilities that individuals have to exercise a degree of control over how organizations handle their personal data. Depending on the applicable law, these can include being told when your data is processed, seeing what data an organization holds about you, correcting errors, and in some cases asking for your data to be deleted. The specific rights available, and how they must be honored, vary by jurisdiction and by the legal framework that applies.
Data subject rights are the enforceable entitlements granted to natural persons ('data subjects') that allow them to influence the processing of their personal data by controllers and, where relevant, processors. Under the EU General Data Protection Regulation (GDPR)—which sources here treat as the reference framework—these commonly enumerated rights include the right to be informed, the right of access (typically associated with Art. 15), the right to rectification (Art. 16), the right to erasure/'right to be forgotten', and the right to restrict processing, among others. The precise scope, applicable exemptions, response timelines, and enforcement mechanisms are jurisdiction- and instrument-specific; the evidence here documents the GDPR and UK data protection context, and these rights should not be assumed to apply identically under other legal regimes. Note that data subject rights are a data protection concept and are distinct from AI governance or model risk management controls, though the exercise of such rights can create obligations for organizations deploying AI systems that process personal data.
Why it matters
Data subject rights are a central mechanism through which data protection law gives individuals a measure of control over how their personal data is handled. For organizations, honoring these rights is not optional where the applicable law grants them: under the EU GDPR and the UK data protection framework documented in the sources here, controllers are expected to respond to requests such as access, rectification, erasure, and restriction of processing. Failing to operationalize these rights can expose an organization to regulatory scrutiny and enforcement, and it can erode the trust of the individuals whose data is being processed.
Who it's relevant to
Inside DSR
Common questions
Answers to the questions practitioners most commonly ask about DSR.