The 7 GDPR data subject rights
- Access: Right to know what data you hold
- Rectification: Right to correct inaccurate data
- Erasure: Right to deletion ("right to be forgotten")
- Restriction: Right to limit processing
- Portability: Right to receive data in machine-readable format
- Object: Right to object to processing
- Withdraw consent: Where applicable
Common B2B mistake: "but they're a business contact"
Business contact data is still personal data under GDPR if it identifies an individual. "John Smith, VP at Acme" is personal data even though it's business context. All 7 rights apply.
30-day response window
You must respond to a data subject request within 30 days. Extensions are possible (up to 60 more days) for complex cases, with notification.
Process for handling requests
- Verify identity of the requester
- Search all your systems for matching records
- Compile or delete the data
- Respond in machine-readable format (JSON or CSV)
- Document the request and response