Data subject rights

The UK General Data Protection Regulation (UK GDPR), Assimilated Regulation (EU) 2016/679 provides for enhanced rights for data subjects including providing rights of access, rectification, erasure and restriction of processing, Rights of data portability, and a right of data subjects, with strict time limits for complying.

Right of access

Data subject access requests (also called DSARs) are relatively common and are seen as the gateway right, enabling data subjects to exercise other rights such as the right to rectification or erasure. They can be particularly onerous for businesses.

Article 15 of the UK GDPR entitles data subjects to:

  1. confirmation of whether their personal data is being processed

  2. access to the personal data that is being processed

  3. receive additional information, broadly commensurate with the information required to be provided in your privacy notice

  4. a copy of the personal data in question

The UK GDPR sets out mandatory categories of information which must be supplied in connection with a data subject access request. See Practice Note: Rights of data subjects—Right of access (Article 15 of the UK GDPR).

In

To view the latest version of this document and thousands of others like it, sign-in with LexisNexis or register for a free trial.

Powered by Lexis+®
Latest Risk & Compliance News

ICO publishes letter on progress against economic growth commitments and work planned for 2026

The Information Commissioner’s Office (ICO) has published a letter to the Prime Minister, the Chancellor of the Exchequer, and the Secretary of State for Business and Trade setting out a one-year update on its five economic growth commitments made in January 2025. These commitments are to: (1) give businesses regulatory certainty on artificial intelligence (AI); (2) cut costs for small and medium-sized enterprises (SMEs); (3) enable greater innovation through its Regulatory Sandbox and Innovation Advice services; (4) unlock privacy-preserving online advertising; and (5) make it quicker and easier to transfer data internationally. The letter confirms that the ICO is working with the government on legislation to introduce a statutory code of practice on AI and automated decision-making, and that its expanded data essentials platform for SMEs is due to launch in spring 2026. It also states that the ICO has secured funding to design an experimentation regime to support the testing of emerging technologies, with research findings due by mid-February 2026. In addition, the ICO says it is assessing low-risk online advertising activities that could operate without consent under the Privacy and Electronic Communications Regulations (PECR) and will provide evidence to the government in the spring. The letter also highlights that the ICO published updated guidance on international data transfers in January 2026, aimed at simplifying requirements and supporting cross-border data flows, which underpin around 40% of UK exports. The ICO adds that it will continue to issue further guidance and improve regulatory clarity throughout 2026.

View Risk & Compliance by content type :

Popular documents