← All guides

Privacy & your data

How to exercise your data rights: a practical guide to GDPR, CCPA and the rest

You have a legal right to see, correct, export, and delete the data companies hold about you. Most people never use it. Here is what the rights actually are, how to make a request that cannot be ignored, and what to do when one is.

By Sarah LeeUpdated 2026-08-22 min read

Data protection law gets covered as a compliance burden for companies. Far less is written about the fact that it hands ordinary people a set of enforceable rights — and that using them is mostly a matter of knowing what to ask for and in what words.

This guide covers the rights that exist in the major regimes, how to file a request that gets a proper response, and your options when a company stalls.

Which law applies to you

You are generally protected by the law of where you are, not where the company is. A US company serving European users is subject to the GDPR for those users.

  • GDPR (EU/EEA) and UK GDPR — the broadest set of rights. Applies to anyone in the EEA or the UK.
  • CCPA/CPRA (California) — strong rights, with a distinctive focus on the sale and sharing of personal information.
  • Other US states — Virginia, Colorado, Connecticut, Utah, Texas and a growing list have comparable regimes. The details differ; the core rights of access and deletion are broadly similar.
  • LGPD (Brazil), PIPEDA (Canada), POPIA (South Africa), APPI (Japan), Privacy Act (Australia) — all provide access rights of varying strength.

If you are outside all of these, many large platforms extend the same tooling globally because maintaining separate systems is more expensive than universal compliance. It is always worth asking.

The rights you actually have

Access. You can ask what personal data an organisation holds about you, why, who it has been shared with, and where it came from. This is broader than most people expect: it covers inferences and profiling, not just the details you typed in. The "download your data" button often satisfies only part of it.

Rectification. Inaccurate data must be corrected. Useful against credit reference agencies, data brokers, and anywhere a wrong record has consequences.

Erasure ("right to be forgotten"). Deletion, in defined circumstances. It is not absolute: an organisation can refuse where it has a legal obligation to retain, or where the data is needed to establish or defend legal claims. A bank cannot delete your transaction history on request.

Portability. A copy of the data you provided, in a structured, machine-readable format, so you can move it elsewhere. Narrower than access — it usually covers what you supplied, not what the company inferred.

Objection and restriction. You can object to processing based on legitimate interests. For direct marketing the right is absolute — no balancing test, they must stop.

Rights around automated decisions. Where a decision with legal or similarly significant effect is made solely by automated means, you can require human review.

Opt out of sale or sharing. The CCPA/CPRA framing. Under that regime, "sale" is defined broadly enough to include much of the ad-tech ecosystem.

Non-discrimination. Exercising a right must not lead to worse service or higher prices.

Making a request that works

Most requests that fail do so because they are vague, sent to the wrong address, or fail identity verification.

Find the right recipient. Look for a Data Protection Officer or privacy contact in the privacy policy. Many companies have a dedicated privacy portal — use it if it exists; it is routed to people whose job this is. Front-line support will not have the authority.

Say which right you are exercising, and name the law. "Send me my data" invites a partial answer. "I am exercising my right of access under Article 15 of the UK GDPR" starts a clock.

Be specific about scope. Under access you are entitled to ask for the categories of data, the purposes of processing, the recipients or categories of recipients, the retention period, and the source of data you did not provide yourself. Ask for these explicitly, in a list.

Expect identity verification, within limits. A company may verify who you are, and should — otherwise a request becomes an attack. But verification must be proportionate. Being asked for a passport scan to confirm an email address you are writing from is usually excessive; push back and offer to confirm from the registered address instead.

Keep a record. Date, channel, reference number, and copies of everything. This is what a regulator will want.

A serviceable template:

Dear [company],

I am exercising my right of access under Article 15 of the [UK GDPR / EU GDPR] in relation to the personal data you hold about me. My account identifier is [x].

Please provide: a copy of the personal data; the purposes of processing; the categories of data concerned; the recipients or categories of recipient, including any outside the [UK/EEA]; the retention period or the criteria used to set it; the source of any data not collected from me; and whether any automated decision-making, including profiling, is applied.

Please respond within one month as required by Article 12(3).

[Name, date, contact address]

Swap the citations for your regime — CCPA §1798.100 for California, LGPD Article 18 for Brazil.

Deadlines

  • GDPR / UK GDPR — one month, extendable by two further months for complex requests, but they must tell you within the first month and explain why.
  • CCPA/CPRA — 45 days, extendable by another 45 with notice.
  • Most other regimes — 30 to 45 days.

Requests are normally free. A fee is only permitted where a request is manifestly unfounded or excessive, typically repetitive.

When they ignore you

This happens, and there is a defined escalation path.

  1. Follow up in writing, referencing the original date and the statutory deadline. Say plainly that you will complain to the regulator. A surprising number of requests are resolved at this step.
  2. Complain to the regulator. In the EU, your national data protection authority; in the UK, the Information Commissioner's Office; in California, the California Privacy Protection Agency or the Attorney General. Complaints are free and you do not need a lawyer. Attach your log.
  3. Judicial remedy. GDPR provides a right to an effective remedy and to compensation for damage. This is a bigger step and worth advice, but the right exists.

Regulators generally cannot recover your specific data for you, and they will not act on every complaint. What they do is aggregate: repeated complaints against the same organisation is precisely what triggers investigations.

Requests worth making

Some that reward the effort:

  • Data brokers. Companies that hold detailed profiles on you that you never knowingly gave anything to. Access requests here are frequently revealing, and deletion requests work.
  • Credit reference agencies. Errors are common and consequential.
  • Former employers and old services. Retention periods are often exceeded through simple neglect.
  • Advertising profiles. Most large platforms expose the inferred interests and demographics they have assigned you. It is worth seeing once.
  • Anywhere you have a live dispute. An access request produces the internal record, including notes about you.

Realistic expectations

Two honest caveats.

Responses are often disappointing in shape: a large export of raw logs with no explanation, technically compliant and practically opaque. You can go back and ask for the contextual information — categories, purposes, recipients — which is what makes an export meaningful.

And deletion is not always complete, legitimately. Backups cycle out over time rather than instantly. Legal-hold data stays. A company saying "deleted from live systems, purged from backups within N days" is usually being accurate rather than evasive.

None of that undercuts the value of asking. These rights are only meaningful to the extent people use them, and the organisations with the worst practices are the ones least prepared for a well-drafted request.


General information, not legal advice. Data protection law varies by jurisdiction and changes regularly; check your own regulator's guidance for the current position.

Related guides