GDPR data subject rights give individuals in the European Union control over the personal information that businesses collect and hold on them. Since May 2018, the General Data Protection Regulation has required every data controller, meaning any organization that decides why and how personal data gets processed, to honor these rights on request.
For US companies running surveys, market research, or customer feedback programs that reach EU respondents, this is not optional. Enforcement keeps growing sharper. Cumulative GDPR fines have passed €7.1 billion since 2018, with roughly €1.2 billion issued in 2025 alone.
This guide breaks down each of the eight rights, what controllers must do to respond, and how these obligations shape the way you collect survey and research data today.
What is a data subject under GDPR?
A data subject is any identifiable person whose personal data is collected, stored, or processed by an organization. This covers customers, survey respondents, employees, and website visitors located in the EU.
It helps to separate the three roles GDPR defines. The data subject is the individual the data belongs to. A data controller decides why and how that data gets processed, while a data processor is a third party, such as a survey platform or cloud host, that processes data on the controller’s behalf and under its instructions.
One company can act as both a controller and a processor depending on the activity. A business surveying its own customers is a controller for that data, while a software vendor hosting those survey responses is typically a processor.
The 8 GDPR data subject rights at a glance
GDPR groups individual privacy protections into eight distinct rights, set out in Chapter III of the regulation. Each one gives the data subject a different form of control over their personal data, and each carries its own conditions and exceptions.
| Right | GDPR article | What the data subject can do |
|---|---|---|
| Right to be informed | 12-14 | Know how and why their data is used |
| Right of access | 15 | Request a copy of their processed data |
| Right to rectification | 16 | Correct inaccurate or incomplete data |
| Right to erasure | 17 | Ask for their data to be deleted |
| Right to restrict processing | 18 | Pause processing without deleting the data |
| Right to data portability | 20 | Receive their data and move it elsewhere |
| Right to object | 21 | Stop processing for specific purposes |
| Rights related to automated decisions | 22 | Avoid solely automated decisions with legal effect |
The European Data Protection Board treats these eight rights as the practical core of what transparent, compliant data handling requires from any organization operating in the EU.
Right to be informed
The right to be informed means data subjects must know, before or at the point of data collection, who is processing their data and why. Every other right depends on people knowing their data is being collected in the first place.
Under Articles 13 and 14, controllers must disclose:
- Who the data controller is and how to reach them
- The purpose of collection and its legal basis
- Any third parties the data might be shared with
- How long the data will be retained
- What rights the data subject holds and how to use them
Most organizations meet this through a privacy notice or a consent screen shown before anyone submits personal data. Regulators are watching this closely. The EDPB picked transparency under Articles 12 through 14 as its 2026 coordinated enforcement priority across 25 data protection authorities.
Right of access, or the data subject access request
The right of access lets a data subject confirm whether an organization is processing their data and, if so, request a copy of it. This is commonly called a data subject access request, or DSAR, and it is the most frequently exercised GDPR right.
Here is how a typical DSAR moves through an organization:
- The data subject submits a request by email, form, or letter. No specific wording or legal language is required.
- The controller verifies the requestor’s identity to prevent exposing someone else’s data.
- The controller compiles the personal data held, along with details on why it is processed and who it has been shared with.
- The controller delivers the data in a commonly used electronic format, typically within one calendar month.
For example, a US retailer that surveys EU shoppers might receive a DSAR asking for every response tied to one email address. The retailer has one month to verify the requestor and return the data, and the first copy must be provided free of charge. Respondents typically start this process by raising a data rights request directly with the survey owner.
Right to rectification
The right to rectification lets a data subject ask a controller to correct inaccurate personal data or complete information that is missing. It exists to uphold GDPR’s accuracy principle, which requires that personal data stay correct and current.
A rectification request can come in verbally, by email, or in writing, and it does not need to reference a specific article or use formal language. Controllers must act without undue delay and, at the latest, within one calendar month of receiving the request. If the controller doubts the requestor’s identity, it can ask for extra verification before making any changes.
Right to erasure, also called the right to be forgotten
The right to erasure lets a data subject ask a controller to delete their personal data when there is no longer a legitimate reason to keep it. Common triggers include withdrawn consent, data collected unlawfully, or data that has simply outlived its original purpose.
This right is not absolute. A controller can decline or limit an erasure request when:
- The data supports freedom of expression or information
- Legal obligations require the controller to keep processing it
- The processing serves the public interest, including public health
- The data supports the exercise of legal claims
Controllers that host survey or research data should pair every erasure workflow with the same secure data handling standards they use for the rest of their systems, since deletion has to be verifiable and complete.
Right to restrict processing
The right to restrict processing lets a data subject pause how their data is used without requiring full deletion. It works as a middle ground between doing nothing and invoking the right to erasure.
A data subject can request restriction while they contest the accuracy of their data, while a controller assesses an objection, or when processing is unlawful but the individual would rather limit use than delete the data outright. Once restriction is in place, the controller can still store the data but cannot process it further until the underlying issue is resolved.
Right to data portability
The right to data portability lets a data subject receive the personal data they provided to a controller in a structured, machine-readable format, and lets them transfer that data to a different controller. Article 20 limits this right to data processed based on consent or a contract, and only when the processing is carried out by automated means.
This right complements the right of access. Access lets someone see their data. Portability lets them take it somewhere else, whether that means downloading it to their own device or moving it directly to a new provider when technically feasible. It does not apply to processing carried out for a public task or under official authority.
Right to object
The right to object lets a data subject stop a specific type of processing, even when the controller has a legitimate basis to continue it otherwise.
Two situations come up most often:
- Direct marketing: the objection is absolute. Processing must stop immediately, with no balancing test required.
- Legitimate interest or public task processing: the controller can continue only if it demonstrates compelling grounds that override the individual’s rights.
Any organization running marketing surveys or promotional campaigns needs a straightforward opt-out mechanism to honor this right in real time.
Data subjects have the right not to be subject to decisions based solely on automated processing, including profiling, when those decisions produce legal or similarly significant effects. Automated decision-making means a computer system, not a person, makes the final call, such as an algorithm that approves or denies a loan application without human review.
This right matters more each year as AI-driven scoring, hiring tools, and eligibility systems spread. Where these systems fall under the EU AI Act’s high-risk categories, organizations may need to satisfy both AI Act transparency requirements and Article 22 obligations at the same time. Data subjects affected by a fully automated decision can request human intervention, express their point of view, and contest the outcome.
What data controllers must do when a rights request arrives
Every data subject rights request puts the clock on the controller. Article 12 sets the procedural baseline that applies across all eight rights.
| Requirement | Standard timeline |
|---|---|
| Initial response | One calendar month from receipt |
| Complex requests | Extendable by two further months, with notice |
| Cost | Free for the first request in most cases |
| Format | Clear, accessible language; electronic requests answered electronically |
Controllers bear primary responsibility for processing a data rights request correctly, though data processors must support them in meeting these obligations. Most mid-sized and large organizations appoint a data protection officer to manage this process and serve as the point of contact for data subjects and supervisory authorities.
Common mistakes controllers make with data subject rights
A handful of avoidable errors show up in enforcement cases again and again.
- Treating privacy notices as a one-time task instead of updating them as data practices change
- Missing the one-month response window because no internal process tracks incoming requests
- Deleting data on request without checking legal retention obligations first
- Assuming anonymous survey data is exempt when demographic fields still make respondents identifiable
- Failing to document the legal basis for processing before collection begins
Transparency failures alone, covered under Articles 12 through 14, account for a meaningful share of the fines regulators issue each year. Building a documented, repeatable process is far cheaper than responding to a complaint after the fact.
How GDPR rights affect survey and research data collection
Not every survey triggers full GDPR obligations. A truly anonymous survey, one that never collects an email, name, or IP address, generally falls outside GDPR’s scope because no individual can be identified from the responses.
The moment you ask for identifying details, even indirectly, GDPR applies. Asking employees for their age, job title, and length of tenure can be enough to identify someone in a smaller team, even without a name attached. A GDPR compliant survey platform can build these safeguards into the data collection workflow itself instead of leaving them to a manual checklist.
Getting proper consent for research data
Article 7 requires that survey respondents give clear consent before an organization collects and processes their data. A GDPR compliant survey typically opens with an unchecked consent checkbox, explains the purpose of the research in plain language, and lets respondents withdraw at any time.
Practicing data minimization
Article 5 asks controllers to collect only the data they genuinely need. If age is the relevant variable, skip the extra questions about income bracket or exact birthdate. Many teams manage this directly inside their research software platform by building consent and retention rules into the survey design itself, rather than bolting compliance on afterward.
The rights are the point, not the paperwork
GDPR data subject rights were never meant to be a checklist buried in a privacy policy nobody reads. They exist so people can find out what an organization knows about them, fix what is wrong, and walk away when they want to. Controllers that build simple, documented processes around these eight rights spend less time firefighting requests and more time actually using the data they are allowed to keep.
Frequently Asked Questions (FAQs)
Yes. GDPR applies based on whose data is processed, not where the company is based. A US business collecting personal data from people located in the EU, including through surveys or feedback forms, must comply with GDPR for that data.
Ignoring a request can trigger a complaint to a supervisory authority and, if unresolved, a fine of up to €20 million or 4% of global annual turnover. Documented, timely responses are the simplest way to avoid escalation.
Yes. Consent under GDPR must be as easy to withdraw as it was to give. Once withdrawn, the controller must stop the related processing unless another legal basis, such as a contractual necessity, applies.
Submitting a request costs nothing. Controllers must provide the first copy of the requested data free of charge. A reasonable fee only applies to repeat requests for the same data within a short period.
GDPR applies to any organization processing EU residents’ data regardless of location, while US laws like the CCPA apply based on where the consumer lives and a business’s revenue or data volume. Many rights overlap, but GDPR’s obligations are broader and its response deadlines stricter.



