These are the standard rights every individual has under GDPR.

  • The right to be informed = before the personal data is gathered and reasons for it – ‘opt-in

  • The right of access = any personal data you hold on them – in written records, on the computer, hand-written, in an email, in a filing cabinet etc. Company must comply within 30 days of receiving the request. No longer a need for the person requesting access to pay for this

  • The right to rectification = if out of date, invalid, inaccurate etc.

  • The right to be forgotten = if no longer a customer, or have withdrawn their consent – they retain the right to have their personal data deleted

  • The right to data portability = the right to request your transfer their personal data to another business. This must be in a commonly used and readable format

  • The right to object to processing and direct marketing = they can request that their personal data is not used for processing = personal data can remain in place but not used

  • The right to be notified = of any breach of their data within 72 hours of its discovery

  • The right to be informed of who else you have transferred / shared their date to/with and the consent given for this, or how you collected the data in the first place. How long you have held the data and how long you intend to keep it for – reasonable and practicable and within guidelines