惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
博客园_首页
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 叶小钗
A
About on SuperTechFans
量子位
G
Google Developers Blog
云风的 BLOG
云风的 BLOG
T
Threat Research - Cisco Blogs
Spread Privacy
Spread Privacy
Hacker News - Newest:
Hacker News - Newest: "LLM"
N
News and Events Feed by Topic
C
Cybersecurity and Infrastructure Security Agency CISA
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
T
Tenable Blog
V
V2EX
月光博客
月光博客
L
Lohrmann on Cybersecurity
W
WeLiveSecurity
Webroot Blog
Webroot Blog
H
Hacker News: Front Page
酷 壳 – CoolShell
酷 壳 – CoolShell
T
The Exploit Database - CXSecurity.com
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 三生石上(FineUI控件)
T
Troy Hunt's Blog
Google Online Security Blog
Google Online Security Blog
AI
AI
腾讯CDC
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Google DeepMind News
Google DeepMind News
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
V2EX - 技术
V2EX - 技术
Martin Fowler
Martin Fowler
博客园 - Franky
I
Intezer
Project Zero
Project Zero
I
InfoQ
P
Privacy International News Feed
C
Check Point Blog
T
The Blog of Author Tim Ferriss
P
Palo Alto Networks Blog
L
LINUX DO - 最新话题
有赞技术团队
有赞技术团队
Cloudbric
Cloudbric
人人都是产品经理
人人都是产品经理
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
S
SegmentFault 最新的问题
Latest news
Latest news
小众软件
小众软件

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations TikTok Faces Lawsuit Over Tracking Non-Users What’s the Digital Markets Act (DMA) and how will it affect you? | iubenda Simplifying Cookie Consent: The European Commission's Approach | iubenda Google Settles Landmark Privacy Lawsuit for $5 Billion | iubenda Navigate GDPR Compliance with Confidence: Lessons from Recent Fines in Italy Simplifying the Commission's New Reporting Template for Digital Market Gatekeepers | iubenda Understanding the GDPR Complaint Against X (Twitter) for Illegal MicroTargeting | iubenda Spanish Media Giants Take On Meta in a Groundbreaking $600 Million Lawsuit | iubenda DPO Newsletter: Data Protection & Privacy News (issue #126) | iubenda Belgian DPA Mandates Cookie Banner Changes for Major Media Websites | iubenda UK's Top Websites Warned by ICO to Revise Cookie Practices | iubenda Understanding the European Union's Data Act | iubenda Google Announces Consent Mode v2 – here’s what it means for your business and advertising Noyb Challenges EU Commission Over Controversial Ad Campaign | iubenda OECD Updates AI Definition: A Step Forward in Shaping EU’s AI Law Firefox To Introduce Simplified Global Privacy Control Berlin Court Cracks Down on LinkedIn’s Privacy Violations The YouTube Ad Blocker Controversy: A Test of the ePrivacy Directive? | iubenda DPO Newsletter: Data Protection & Privacy News (issue #125) Facebook and Instagram Subscription: Meta adds a paywall | iubenda GDPR Violation: Lack of Transparency in Data Processing via Google Fonts Amazon Introduces AWS European Sovereign Cloud to Address EU Regulations | iubenda Texas New Data Privacy Law TDPSA: Everything you need to know How to Make Money with a Website Without Selling Anything Oregon Consumer Privacy Act: Overview | iubenda Google’s Move to Disable Third-Party Cookies: What Advertisers Need to Know IMY Fines H&M for GDPR Violations: A Closer Look EU Commission Requests Information from X Under Digital Services Act: What You Need to Know | iubenda Understanding California’s “Delete Act” and Data Broker Regulations TCF v 2.2 Initial Layer (Banner) Requirements | iubenda Grindr Faces €5.8 Million Fine: A Reminder on the Importance of GDPR Compliance | iubenda Newly Enacted Iowa Consumer Data Protection Act (ICDPA) | iubenda The Witch’s Brew of Privacy: A Halloween Tale of Compliance and Consequences IAB TCF 2.2 – What you need to do DPO Newsletter: Data Protection & Privacy News (issue #124) Blog Ideas That Make Money: How To Make Money From Your Blog + Examples | iubenda Maximize your Growth with Online Presence Management | iubenda Meta's New Pivot in Europe: To Pay or Not to Pay for an Ad-Free Experience? | iubenda Consumer Reports Launches Free ‘Permission Slip’ App to Protect Your Data | iubenda DAZN’s Access Request Saga Personal Brand Logo: How to Stand Out in a Crowded Marketplace UK-US Data Bridge: A New Era for Secure Data Transfers 7 Ways How to Promote Affiliate Links Effectively (And Boost Commissions) | iubenda Mastering LinkedIn Personal Branding: A Guide to More Opportunities Meta's New Approach: Pay for Your Privacy? | iubenda No Return, No Refund Policy Template & Guide GDPR in the US: a GDPR Checklist for US Companies Crafting a Niche with Branding and Identity Design | iubenda The Online Safety Bill: A Leap Towards a Safer Digital United Kingdom Understanding Google's $93m Settlement over Consumer Location Data Accusations | iubenda CCPA vs CPRA: Key Differences You Need to Know | iubenda How To Use Ecommerce Retargeting to Grow Your Business | iubenda PECR: Everything you need to know | iubenda How Mobile Apps Illegally Share Your Personal Data: A Deep Dive | iubenda Legal Spotlight: Privacy Concerns Surrounding OpenAI’s ChatGPT and Microsoft’s Involvement Legal Scrutiny Looms Over Transatlantic Data Deal: French MEP Takes Action Understanding the Digital Markets Act: A Comprehensive Guide Block AI Crawlers: Here’s How To Stop Your Site From Being Used for AI Training (OpenAI and Google Bard Irish Regulator Slaps $368M Fine on TikTok DPO Newsletter: Data Protection & Privacy News (issue #123) | iubenda The Privacy Pitfalls of Vehicle Data Collection: What You Need to Know | iubenda Twitter customer’s data on the menu for xAI models Update: Revised Swiss Privacy Law Takes Effect Fitbit and the GDPR Hurdle: What You Need to Know About Your Data Privacy | iubenda Terms of Service Template for your site | iubenda Senators Urge FTC to Investigate YouTube and Google for Violating Children's Privacy: What You Need to Google AdSense Requirements: Here's What You Need to Know | iubenda Users can’t opt out from marketing emails: FTC fines Experian $650,000 | iubenda DPO Newsletter: Data Protection & Privacy News (issue #122) | iubenda 7 Ways Business Process Automation Can Increase Your Profits
Data Protection: Navigating GDPR Data Subject Rights | iubenda
Alice Perseval · 2023-02-08 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

You must have already heard of the GDPR, the most robust data protection law to date in the EU. At its most basic level, the regulation lays out what constitutes lawful processing of personal data (how it is collected, used, protected, or interacted with in general) and grants individuals whose personal data is processed some rights, called “data subject rights”.

👀 In this article, we take a look at what these rights are and how you can lawfully respect them as a business.

In this post, we explain ⬇️

  • “Data Subject”: Who Does it Refer to?
  • What are Data Subject Rights under the GDPR?
  • Your Role as a Business: Appointment of a Data Protection Officer (DPO)
  • Your Role as a Business: Fulfill Data Subject Access Request (DSAR)
  • Your Role as a Business: Honor Data Subject Rights

Before diving in, let’s define what a data subject is. Who does it even refer to?

“Data Subject”: Who Does it Refer to?

The term “Data subject” has been used in the GDPR text to describe an “identified or identifiable natural person”. It is essentially the individual whose personal data (i.e. email address) is being collected, processed or stored by a business.

Personal data under the GDPR includes pieces of information that, when collected together, can lead to the identification of a person.

🔍 Read our article to learn more about what is considered personal information across major privacy laws.

data subject rights

What are Data Subject Rights under the GDPR?

The GDPR recognizes the necessity to protect personal data and to ensure individuals have control over it.

It allows data subjects to take some steps toward the personal data businesses have on them and has granted them a list of 8 data subject rights: right to be informed, right of access, right to rectification, right to erasure, right to restrict processing, right to data portability, right to object, rights related to automated decision-making and profiling. Keep reading for more detail.

📎 The Right to be Informed (GDPR Article 13, 14)

You need to inform users that their data is being collected, what data in particular, and why. This also means that your privacy notices should be concise, easy-to-understand and easily accessible throughout your website/app.

📎 The Right of Access (GDPR Article 15)

Users have the right to access their personal data and information about how their personal data is being processed.

📎 The Right to Rectification (GDPR Article 16)

Users have the right to have their personal data rectified if it is inaccurate or incomplete.

📎 The Right to Erasure (GDPR Article 17)

When data is no longer relevant to its original purpose or where users have withdrawn consent, users have the right to request that their data be erased.

📎 The Right to Restrict Processing (GDPR Article 18)

Users have the right to restrict the processing of their personal data in specific cases.

📎 The Right to Data Portability (GDPR Article 20)

Under certain conditions, users have the right to obtain (in a machine-readable format) and use their personal data for their own purposes.

📎 The Right to Object (GDPR Article 21)

Users have the right to object to certain activities in relation to their personal data.

📎 Rights Related to Automated Decision-Making and Profiling (GDPR Article 22)

Users have the right to not be subjected to a decision that’s based on automated processing or profiling, and which produces a legal or a similarly significant effect on the user.

🔍 You can find full details on the rights above in simplified terms in our GDPR guide here, or you can read the official GDPR text here.

Your Role as a Business Regarding Data Subject Rights

What do these rights mean for your business, in practice?

Appointment of a Data Protection Officer

A Data Protection Officer (DPO) is usually appointed by a company to ensure that personal data is processed following the applicable data protection rules. This includes personal data:

  • of the organization’s employees;
  • of the organization’s customers;
  • of the organization’s providers;
  • of data subjects; and
  • processed by data processors.

You must know that if the GDPR applies to your company and if you process a significant amount of personal data, you are legally required to designate a DPO.

When it comes to data subjects and data subject rights, a DPO often acts as the main point of contact and needs to handle requests from individuals who would like to exercise their rights.

🔍 We have compiled a quick guide for what to look for when choosing your DPO. Check it out here!

Fulfill Data Subject Access Request (DSAR)

To comply with GDPR requirements, it’s essential to fulfill Data Subject Requests (DSRs), which encompass a range of rights that individuals can exercise under the regulation. These include the right to access, rectify, erase, restrict processing, data portability, object to processing, and not be subject to automated decision-making.

While fulfilling DSRs, organizations must respond promptly and effectively, adhering to the legal timelines (typically within one month). Among these, Data Subject Access Requests (DSARs)—where individuals request access to their personal data—are particularly common and must be handled with care to ensure compliance. However, honoring DSRs goes beyond DSARs, as it involves respecting all rights granted under GDPR.

Filing a Data Subject Access Request is a step individuals can take to exercise their key right of access, under the GDPR. Data subjects can send a written request and ask for the following info

🔍 Learn more about how to handle DSAR here.

Honor Data Subject Rights

Honoring all Data Subject Requests (DSRs), including DSARs, requires a robust and organized approach. Start by ensuring clear internal procedures for identifying, tracking, and responding to requests. Here’s a practical roadmap:

  1. Establish a DSR Process: Implement processes to handle DSRs, from initial receipt to fulfillment. Consider creating a dedicated team or assigning specific roles for managing these requests.
  2. Verify the Requester: Ensure the identity of the individual making the request is verified to prevent unauthorized data access or misuse.
  3. Respond Within Legal Timelines: Respond to all DSRs promptly, providing the required information or taking action within one month, with extensions only when necessary and justified.
  4. Maintain Transparency: Clearly communicate the actions taken in response to a DSR, especially in cases of denial or partial fulfillment, providing the rationale and informing the individual of their right to appeal.

Needless to say, you should:

✅ Take these rights seriously and have appropriate technical and organizational measures in place to respect them;
✅ Oversee the training of your staff (if any) on data protection matters and handling data subject requests;
✅ Make sure your privacy documents are complete and up-to-date!

Failure to honor these rights can result in fines and reputational damage.

Ready to Simplify Your Data Subject Rights Management Process?

Streamline your data subject rights management with our powerful, intuitive tool and see the benefits for your business

Activate Now

Learn more