UK GDPR Summary
Your rights under Articles 15 to 22 explained simply
The UK General Data Protection Regulation sets out your core data protection rights. These rights apply where an organisation is acting as a data controller and processing your personal data. They may be restricted in limited circumstances, including under the Data Protection Act 2018.
The rights under the UK GDPR are not absolute. They may be restricted in limited circumstances, including under the Data Protection Act 2018. Organisations must justify any refusal or restriction.
Article 15 – Right of Access
You have the right to:
- Confirm whether your personal data is being processed
- Receive a copy of that data
- Receive supplementary information
This includes the purposes of processing, categories of data, recipients, retention periods, your rights, and the right to complain to the ICO.
Time limit: One month from receipt, extendable by up to two months for complex or numerous requests.
Fee: No fee unless the request is manifestly unfounded or excessive.
This is commonly known as a Subject Access Request.
Article 16 – Right to Rectification
You have the right to have inaccurate personal data corrected without undue delay. You may also request completion of incomplete data. Controllers must take reasonable steps to verify accuracy before amending records.
Article 17 – Right to Erasure
You may request deletion of your personal data where:
- The data is no longer necessary
- Consent is withdrawn and no other lawful basis applies
- You object and there are no overriding legitimate grounds
- The data was processed unlawfully
Key limitations: The right does not apply where processing is necessary for legal obligations, defence of legal claims, archiving in the public interest, or public health purposes.
Article 18 – Right to Restriction of Processing
You may request restriction where:
- Accuracy is contested
- Processing is unlawful but you oppose erasure
- The controller no longer needs the data but you require it for legal claims
- You have objected and verification is pending
When restricted, data may generally only be stored.
Article 20 – Right to Data Portability
You may receive your personal data in a structured, commonly used, machine-readable format, and transmit it directly to another controller where technically feasible.
This right applies only where processing is based on consent or contract, and processing is carried out by automated means.
Article 21 – Right to Object
You may object to processing based on legitimate interests or public task. The controller must stop processing unless it demonstrates compelling legitimate grounds that override your interests.
You have an absolute right to object to direct marketing.
Article 22 – Rights Related to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing, including profiling, where it produces legal effects or similarly significantly affects you.
Exceptions apply where the decision is necessary for a contract, authorised by law, or based on explicit consent.
Safeguards: You have the right to obtain human intervention and to challenge the decision.
Time Limits for Responses
Controllers must respond without undue delay, and in any event within one month. The period may be extended by up to two additional months where necessary due to complexity or volume. Controllers must inform you within the first month if an extension applies.
Refusing or Restricting a Request
An organisation may refuse to act where a request is manifestly unfounded or excessive. They must explain their reasons and inform you of your right to complain to the ICO and to seek a judicial remedy.
Rights may also be restricted under the Data Protection Act 2018 where necessary and proportionate, including for:
Restrictions must have a lawful basis and be applied narrowly.
Complaints and Remedies
If you are dissatisfied:
- 1 Complain to the organisation first
- 2 Escalate to the Information Commissioner's Office
- 3 You may bring a claim before the courts for compensation if you suffer material damage or distress
In Summary
Under the UK General Data Protection Regulation, you have enforceable rights to:
- ✓ Access your personal data
- ✓ Correct inaccurate information
- ✓ Erasure in certain circumstances
- ✓ Restrict processing
- ✓ Data portability
- ✓ Object to processing
- ✓ Challenge automated decisions
These rights are legally binding. Organisations must justify any refusal or restriction.
- Legislation.gov.uk – UK GDPR (View original)
- ICO Guide to Data Protection – ico.org.uk
- Data Protection Act 2018 – Legislation.gov.uk
Last reviewed: March 2026. This page provides a factual summary of the legislation and does not constitute legal advice.