Skip to main content

Command Palette

Search for a command to run...

GDPR and Your Right to Your Data

Updated
•3 min read•View as Markdown

Most write-ups on this topic start with the conclusion. This one starts with the thing that tripped me up, because that is the part that cost me time.

Working through the GDPR data rights, the problem I kept running into was not the one I expected to be solving. The obvious difficulty is visible from the start and mostly takes care of itself once you engage with it. The difficulty that decides the outcome never announces itself.

The rights get described as a list of seven, which makes them sound interchangeable. They are not, and the distinction matters when you actually file a request because different rights produce different obligations on different timelines.

Access gets you a copy of what is held. Rectification corrects it. Erasure removes it. Restriction freezes processing while a dispute is settled. Portability gives you a machine-readable export. Objection stops a specific use. The seventh covers automated decision-making.

The question that reframes it

The scope rule is the part most people get wrong. GDPR applies based on where the data subject is located, not where the company is registered. A company with no EU presence is still in scope if it offers services to people in the EU or monitors their behaviour.

This is why request templates that say "under EU law" work against non-EU companies more often than people expect. The obligation attaches to the activity, not the address.

Where this actually goes wrong

Requests are free in most cases. An organisation can charge a reasonable fee or refuse if a request is manifestly unfounded or excessive, which in practice means repetitive requests for the same data.

The response window is one month, extendable by two further months for complex requests, and the extension has to be communicated with reasons within the first month. Silence past the deadline is itself a compliance failure you can report.

What the timeline says

Portability and erasure are separate and it matters which you file first. A portability request produces a copy of the data you provided, in a structured machine-readable format. An erasure request removes it.

Filed in the right order, portability gives you a record of what existed before removal. Filed in the wrong order, the data may be gone before you have a copy, and the erasure obligation does not require them to give you one.

The order I would do it in

This breaks down for data held under a legal obligation, where the organisation must keep the data regardless of an erasure request. It also breaks down for data that has been aggregated or anonymised, because anonymised data falls outside the definition of personal data entirely.

Takeaways

  • The rights get described as a list of seven, which makes them sound interchangeable.
  • The scope rule is the part most people get wrong.
  • Requests are free in most cases.
  • Portability and erasure are separate and it matters which you file first.
  • This breaks down for data held under a legal obligation, where the organisation must keep the data regardless of an erasure request.

Longer version with the reference details is here: https://stillherememory.com/blog/gdpr-and-your-right-to-your-data