The 7 GDPR data subject rights

  1. Access: right to know what data you hold and why
  2. Rectification: right to correct inaccurate data
  3. Erasure: right to deletion ("right to be forgotten")
  4. Restriction: right to limit processing without full deletion
  5. Portability: right to receive data in a machine-readable format
  6. Object: right to object to processing, most relevant where legitimate interest is your legal basis
  7. Withdraw consent: where consent was the legal basis in the first place
Secure EU data infrastructure for GDPR-compliant LinkedIn prospecting
Run LinkedIn sourcing and outreach from one place.

Which rights actually come up in prospecting

The full list of seven matters for knowing your obligations, but in day-to-day B2B prospecting, two rights account for nearly every real request: access ("send me what you have") and objection/erasure ("stop processing my data and delete it"). Portability is the one worth calling out specifically because it's the most commonly misunderstood: Article 20 only covers data the subject actively provided to you, and only where the legal basis is consent or a contract with that person. Data extracted from a public LinkedIn profile under legitimate interest meets neither condition, so portability essentially doesn't apply to a typical prospect list. Rectification and restriction come up occasionally, usually when someone's title changed or they want outreach paused without full deletion. Build your operational process around access and erasure first; the others are good to know but rarely drive the actual workload.

Common B2B mistake: "but they're a business contact"

Business contact data is still personal data under GDPR if it identifies an individual. "John Smith, VP at Acme" is personal data even though it appears in a business context, since GDPR's definition turns on whether a natural person is identified or identifiable, not on whether the data relates to their job. All seven rights apply exactly as they would to a consumer's data. France's CNIL, often the most permissive EU regulator on the outreach side (explicitly allowing B2B cold email to a professional address without prior opt-in), is equally explicit on the rights side: professional contact data gets full data subject rights protection. The two positions aren't contradictory, they're answering different questions, lawful basis to contact someone versus rights over data you're holding.

30-day response window

You must respond to a data subject request within 30 days of receipt. Extensions are possible, up to 60 additional days, for complex or high-volume cases, but you have to notify the requester of the extension and the reason within the original 30-day window, not after it's already expired.

Process for handling requests

  1. Verify the identity of the requester, proportionate to the request; you don't need notarized ID for a simple access request
  2. Search all your systems for matching records: CRM, outreach sequencing tool, exported spreadsheets, backups
  3. Compile or delete the data depending on which right was exercised
  4. Respond in a reasonably usable format, plain text or CSV covers nearly every access request
  5. Document the request, your response, and the date, in case a regulator asks later

Frequently asked questions

Does portability actually apply to a prospecting list?

Rarely. The right to portability only covers data the subject actively provided to you and that you process on the basis of consent or a contract. Data sourced from a public LinkedIn profile under legitimate interest doesn't meet either condition, so most B2B prospecting data falls outside Article 20 entirely. Access and erasure are the rights that actually come up.

Is a business contact's data really "personal data" under GDPR?

Yes. GDPR defines personal data as anything relating to an identified or identifiable natural person, and a named individual's job title and employer identifies them just as clearly in a B2B context as a home address does in a B2C one. "They gave me this for work purposes" isn't an exemption anywhere in the regulation.

What does the CNIL say specifically about B2B prospecting data?

France's CNIL has published specific guidance treating professional contact data as personal data subject to the same core rights, while also being the regulator most explicit that B2B cold outreach to a professional address, on a professional topic, doesn't require prior consent the way B2C marketing does. The two positions aren't in tension: lawful basis for collecting and outreach is one question, and data subject rights over what you collected is a separate one.

Do I need special software to handle these requests at scale?

Not necessarily, but you do need a documented process and a fast way to search every system a contact's data could be sitting in. Below a few dozen requests a month, a checklist and a shared CRM search is usually enough. Past that volume, most teams build a simple internal form that fans out a search across CRM, email tool, and backups automatically.

General information only, not legal advice; confirm current requirements with counsel for your specific situation.

GDPR-positioned tooling.

Leadsforlinked supports a 30-day deletion SLA on subject requests.

Start free