By Alison Sigsworth, Information Governance Manager
By now, almost everyone knows what a Subject Access Request (SAR) is, or that individuals can ask organisations to allow them access to, or provide a copy of, the personal data it holds about them. In data protection terms, this is known as an individual’s ‘right of access’.
It is also widely known that individuals have a ‘right to be informed’ about how organisations collect and use their personal data; bring on the privacy notices!
However, these are just two of the ‘rights’ that people have under data protection law, and it is important for all organisations know what they all are!
The rights hiding in plain sight
The introduction of the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018 (DPA) introduced several rights to give individuals more control over their personal data. Whilst the right of access and right to be informed attract the most attention, many organisations don’t realise that there are other, less prominent rights, that they need to understand, know when they apply, and how to handle them.
There will likely be times when a customer’s record has been input incorrectly or is inaccurate. Maybe they’ve changed address, bank details, or phone number, or the surname has been misspelled. If an organisation is made aware of these changes or inaccuracies, they will likely just amend their records to bring them up to date. However, all organisations should be aware that individuals have a legal right to challenge the accuracy of the data and request that it is corrected. This is called the ‘right to rectification’ and can be particularly important if you are using incorrect data to make or influence decisions about someone.
People can ask organisations not to use their personal data for specific activities, for example, to object to receiving direct marketing or where the organisation is relying on consent. However, this ‘right to object’ can also apply even where their data is being processed under an organisation’s public task or legitimate interests. If someone objects to how their data is being processed, the organisation must consider the objection and demonstrate why its continued use of the information is more important than the individual’s rights.
An organisation may be asked to delete all the personal information they hold on someone. Before pressing ‘delete’ and destroying all existence of an individual’s debt, or staff member’s employment, they should consider whether an individual’s ‘right to erasure’ or ‘right to be forgotten’ applies. They may be further asked to restrict processing of their personal data until they decide whether the data can be deleted or not, under the ‘right to restriction’.
Other rights include the ‘right to data portability’ which allows individuals to ask that one organisation transfer their information to another organisation, and rights related to automated decision-making (ADM) and profiling, where significant decisions are made based solely on automated processing with no human involvement.
Understanding and applying the rights
As if knowing that the individuals’ rights exist wasn’t tricky enough, each right can only be applied in certain circumstances. Some rights only apply depending on the lawful basis being relied on to process the data, some apply depending on the purpose of the processing, some can only be granted if the data hasn’t been used to make significant decisions, and so on. Yet, as with SARs, every individual rights request needs to be handled, recorded, and responded to in line with data protection legislation and statutory timeframes.
To find out more about individuals’ rights, including SARs, and how to comply with data protection legislation, book onto our upcoming CPD UK accredited course, Data Protection Rights, on 22 October, 9.30am – 1pm. To learn more or book your place, click the links or get in touch by emailing info@naomikorn.com.

