Close Menu
  • Home
  • Higher ED
  • News
  • Regulations
    • U.S. State Privacy Legislation
    • General Data Protection Regulation
    • New York Privacy Act
    • California Privacy Rights Act/California Consumer Privacy Act
  • AI
    • AI – Info Tech News
    • Fordham Artificial Intelligence for Faculty and Staff
    • How Emory University Accelerated AI Research in the Cloud
  • Secure IT News
  • Info Tech News
  • Resources
    • Privacy Glossary of Terms
    • Privacy Policy
    • Your Privacy Questions Answered
    • NIST Privacy Framework
    • US State Privacy Legislation Tracker
    • Safeguarding Data and Student Privacy: A Handbook for Higher Education
    • Privacy Field Guides
    • Access Now Blog
    • Fordham CLIP
  • About
Facebook X (Twitter) Instagram
Trending
  • U.S. Lawmakers Push Back Against UK’s Demand for an Apple Encryption Backdoor
  • Beyond Goodbye: Safeguarding Employee Data Privacy After Death
  • AI Notetakers in Meetings: Balancing Efficiency with Privacy and Risk
  • Are You Ready for Web 3?
  • Stay Ahead of Scammers in 2025
  • What are VPNs?
  • LinkedIn Accused of Using Private Messages to Train AI Models
  • Your Data, Your Decision: How to Control Your Data Privacy
Facebook X (Twitter) Instagram
Privacy at Fordham University
  • Home
  • Higher ED

    Strengthening Website Security in Higher Education: Lessons from the FTC’s GoDaddy Settlement

    January 21, 2025

    Merging AI Innovation with IT Expertise in Risk Management

    January 6, 2025

    Staff Highlight – Marc Herzog

    January 3, 2025

    Staff Highlight – Shannon Ortiz

    January 2, 2025

    AI Guidance in Schools

    October 4, 2024
  • News
  • Regulations
    1. U.S. State Privacy Legislation
    2. General Data Protection Regulation
    3. New York Privacy Act
    4. California Privacy Rights Act/California Consumer Privacy Act
    Featured

    Reauthorized Section 702 of the Foreign Intelligence Surveillance Act

    By Josephine Law, FIP, CIPP/US, CIPMApril 22, 20242 Mins Read
    Recent

    U.S. Lawmakers Push Back Against UK’s Demand for an Apple Encryption Backdoor

    February 21, 2025

    Beyond Goodbye: Safeguarding Employee Data Privacy After Death

    February 19, 2025

    Opt-In or Opt-Out, Does it Matter?

    January 20, 2025
  • AI
    1. AI – Info Tech News
    2. Fordham Artificial Intelligence for Faculty and Staff
    3. How Emory University Accelerated AI Research in the Cloud
    Featured

    Merging AI Innovation with IT Expertise in Risk Management

    By Josephine Law, FIP, CIPP/US, CIPMJanuary 6, 20251 Min Read
    Recent

    AI Notetakers in Meetings: Balancing Efficiency with Privacy and Risk

    February 19, 2025

    LinkedIn Accused of Using Private Messages to Train AI Models

    January 30, 2025

    Opt-In or Opt-Out, Does it Matter?

    January 20, 2025
  • Secure IT News
  • Info Tech News
  • Resources
    • Privacy Glossary of Terms
    • Privacy Policy
    • Your Privacy Questions Answered
    • NIST Privacy Framework
    • US State Privacy Legislation Tracker
    • Safeguarding Data and Student Privacy: A Handbook for Higher Education
    • Privacy Field Guides
    • Access Now Blog
    • Fordham CLIP
  • About
Privacy at Fordham University
You are at:Home»Regulations»GDPR»User Rights Under the General Data Protection Regulation
GDPR

User Rights Under the General Data Protection Regulation

Josephine Law, FIP, CIPP/US, CIPMBy Josephine Law, FIP, CIPP/US, CIPMMarch 8, 2021Updated:February 2, 2022No Comments4 Mins Read
GDPR logo over a computer
Share
Facebook Twitter LinkedIn Pinterest Copy Link

The GDPR explicitly states its commitment to European citizens and data subjects early on in the legislation. Chapter 3 of the GDPR records those rights as the Rights of the Data Subject.

The Right to be Informed

The first of the eight rights lies in Articles 13 and 14 of the GDPR. Article 13 refers to information that organizations must provide when they collect personal data directly from data subjects. Article 14 covers the organization’s responsibilities when they obtain data about the data subject from a third party or indirectly.

The Right of Access

Article 15 outlines the right to access. The right to access allows the data subject to access the personal data belonging to them that organizations process, as well as the following information:

  • Why and how you process the data
  • Categories of personal data involved
  • Who sees the data (including and especially in countries outside the EU)
  • How long you intend to store the data
  • How to exercise their rights
  • Any available information to the source of data when you do not collect the data from the data subject
  • Your use of profiling and automated decision-making

The Right to Rectification

Article 16, the right to rectification, provides European data subjects with the right to change or modify the data they provided organizations when they believe the data is inaccurate or out-of-date. Organizations need to provide this information “without undue delay.”

The Right to be Forgotten

Article 17 describes the user’s right to erasure, which is better known as the right to be forgotten. The article says that the data subject has the right to ask a data controller to erase their data without undue delay in the following circumstances:

  • “The personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed”
  • “The data subject withdraws consent on which the processing is based…”
  • “The data subject objects to processing pursuant to Article 21(1), and there are no overriding legitimate grounds for the processing”
  • “The personal data have been unlawfully processed”
  • “The personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject”

In some cases, organizations do not need to comply with a request to access the right to erasure. The GDPR outlines these circumstances as follows:

  • When processing involves a right to the freedom of expression and information
  • When processing involves compliance with a legal obligation and the public interest
  • When processing includes reasons of public interest within the realm of public health
  • When processing meets the guidelines published in Article 89(1) (or public interest, historical, scientific purposes, or statistics purposes)
  • When processing is for the “establishment, exercise, or defence of legal claims”

If the organization’s processing falls under one of these categories, then they can deny the request for erasure by citing the necessary reason for the rejection in the notice.

The Right to Restrict Processing

Article 18 outlines the data subject’s right to request the restriction of processing under certain conditions. That means organizations must temporarily stop processing their data as requested as long as their requests meet one of the following:

  • The data subject contests the accuracy of the data
  • The data subject objects to unlawful processing and the data subject prefers you to restrict the processing rather than erasing their data
  • The data controller does not need the data for processing, but they need to keep the data pursuant to the “establishment, exercise, or defence of a legal claim.”

Article 18(3) states that if organizations temporarily stop processing data, then they must inform the data subject before lifting the restriction and resuming the processing if the organizations choose to do so.

The Right to Data Portability

The right to data portability outlined in Article 20 refers to the data subject’s right to receive the personal data held by the data controller in a commonly used format and send the data to another controller or use it for their personal purposes under certain circumstances.

The Right to Object

Article 21 says that data subjects have the right to object to data processing, including profiling, when it is on relevant grounds.

Rights Related to Automated Decision-Making and Profiling

The eighth right offered by the GDPR lies in Article 22: Automated decision-making, including profiling. The right to avoid automated decision-making comes with three exceptions when it cannot be exerted:

  1. When automated decision-making is necessary to enter into or complete a contract
  2. When the controller has authorization from the EU or a Member State and uses safeguards to protect the subject’s interests and freedom
  3. When the profiling or decision-making occurs with the subject’s explicit consent

 

Josephine Law, FIP, CIPP/US, CIPM
  • X (Twitter)
  • LinkedIn

Senior IT Risk Analyst, Information Security and Assurance | Fordham University Certified Information Privacy Professional/United States (CIPP/US) and Certified Information Privacy Manager (CIPM) with a strong background in IT risk, privacy, and security. A versatile writer with experience in technical, policy, marketing, and social media content, blending expertise in business writing with communications and academics. Creative, resourceful, and adaptable, with a strong work ethic, a positive attitude, and a sense of humor.

Related Posts

U.S. Lawmakers Push Back Against UK’s Demand for an Apple Encryption Backdoor

February 21, 2025

Beyond Goodbye: Safeguarding Employee Data Privacy After Death

February 19, 2025

Opt-In or Opt-Out, Does it Matter?

January 20, 2025
Privacy
  • Data Privacy FAQs
  • Your Privacy Questions Answered
  • Visions of Privacy
Search
Categories
  • AI (77)
  • CCPA (9)
  • GDPR (20)
  • Higher ED (25)
  • New Jersey Privacy (2)
  • New Jersey Privacy Law (2)
  • New York Privacy Act (7)
  • News (187)
  • Privacy (173)
  • Regulations (65)
Archives

Fordham University - The Jesuit University of New York

Founded in 1841, Fordham is the Jesuit University of New York, offering exceptional education distinguished by the Jesuit tradition to more than 15,100 students in its four undergraduate colleges and its six graduate and professional schools.
Copyright © Fordham University
Facebook X (Twitter) Instagram YouTube LinkedIn
© 2025 ThemeSphere. Designed by ThemeSphere.

Type above and press Enter to search. Press Esc to cancel.