Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Data Subject Rights

Right to Rectification

Also known as: Right to have inaccurate personal data rectified, Right to rectify personal data
Simply put

The right to rectification allows individuals to ask an organisation to correct personal data about them that is inaccurate. In some cases, individuals may also have incomplete data completed. Where this right applies, the correction is generally made without undue delay and, according to the supervisory authority guidance cited, free of charge.

Formal definition

The right to rectification is a data subject right under Article 16 of the GDPR (and, in the UK, Article 16 of the UK GDPR) entitling individuals to obtain from the controller, without undue delay, the rectification of inaccurate personal data concerning them, and to have incomplete personal data completed. Under Article 19 of the GDPR, a controller communicating rectification obligations may be required to notify recipients to whom the data has been disclosed, subject to the conditions in the applicable text. This right is distinct from the right to erasure and from the right of access; its scope, exceptions, and interaction with other rights depend on the specific regulatory text and jurisdiction. The EU GDPR governs processing within its material and territorial scope, while the UK GDPR applies in the United Kingdom; practitioners should verify the operative wording and any applicable exemptions against the current authoritative text for the relevant jurisdiction, as interpretations and enforcement practice may differ.

Why it matters

The right to rectification addresses a foundational data protection principle: personal data should be accurate. Inaccurate or incomplete data can produce real consequences for individuals, from incorrect decisions about creditworthiness or eligibility to misdirected communications and reputational harm. By giving individuals a mechanism to challenge and correct errors, the right functions as a practical safeguard on the accuracy principle rather than leaving accuracy solely to the controller's internal processes.

For organisations, the right creates operational obligations that must be handled within defined timeframes. Supervisory authority guidance cited here indicates that, where the right applies, rectification is generally carried out without undue delay and free of charge. Failing to correct inaccurate data on request, or treating such requests inconsistently, can expose an organisation to complaints and regulatory scrutiny under the relevant regime. Because the right is grounded in binding law—Article 16 of the EU GDPR and, in the United Kingdom, Article 16 of the UK GDPR—it is an enforceable entitlement rather than a voluntary courtesy.

The right also carries a downstream dimension. Under Article 19 of the GDPR, a controller may be required to notify recipients to whom the data has been disclosed of a rectification, subject to the conditions in the applicable text. This means correcting an error is not always a single-record fix; it can require tracing and updating data shared with third parties. The precise scope of these obligations, along with any exemptions, depends on the operative wording and jurisdiction, and practitioners should verify against the current authoritative text.

Who it's relevant to

Data protection officers and privacy teams
Those responsible for handling individual rights requests need clear procedures for receiving, verifying, and actioning rectification requests, including determining when incomplete data should be completed and when Article 19 notification to recipients may apply. They should confirm applicable timeframes and any exemptions against the current authoritative text for their jurisdiction.
Controllers processing personal data
Because the obligation to rectify inaccurate data falls on the controller, organisations acting in that capacity must be able to locate, correct, and, where required, propagate corrections to third parties to whom data has been disclosed. The specific obligations depend on the operative wording of the EU or UK GDPR as relevant.
Individuals and data subjects
People whose personal data is held by an organisation can use this right to ask that inaccurate data be corrected and, in some cases, that incomplete data be completed. Supervisory authority guidance cited here indicates rectification is generally carried out without undue delay and free of charge, though the precise scope and any conditions depend on jurisdiction.
Compliance and legal counsel
Advisers assessing an organisation's obligations should distinguish rectification from the rights of access and erasure, evaluate how the right interacts with any applicable exemptions, and note that scope and enforcement practice may differ between the EU and UK regimes. Verification against the latest authoritative source is advisable, as regulatory texts and guidance are periodically amended.

Inside Right to Rectification

Data subject entitlement
The right of an individual to obtain from a controller the correction of inaccurate personal data concerning them, without undue delay. It is one of the data subject rights recognized under the EU GDPR and mirrored in the UK GDPR.
Completion of incomplete data
The right generally extends beyond correcting errors to having incomplete personal data completed, including by means of providing a supplementary statement, where appropriate to the purposes of processing.
Controller obligation to act
The controller is responsible for responding to rectification requests. Where processing is carried out by a processor, the processor generally acts on the controller's instructions rather than adjudicating the request itself.
Notification to recipients
The controller is generally required to communicate a rectification to each recipient to whom the data has been disclosed, unless this proves impossible or involves disproportionate effort, and to inform the data subject about those recipients if requested.
Time and cost parameters
Requests are generally handled within the response timeframe set by the applicable regulation and, in most cases, free of charge, though controllers may charge or refuse where requests are manifestly unfounded or excessive. Specific deadlines should be verified against the current official text.
Relationship to other rights
Rectification is distinct from, but interacts with, related rights such as access, erasure, and restriction of processing. It concerns the accuracy and completeness of data rather than its deletion or availability.

Common questions

Answers to the questions practitioners most commonly ask about Right to Rectification.

Does the right to rectification let a data subject demand that any information they disagree with be changed?
Not exactly. The right generally allows a data subject to have inaccurate personal data corrected and incomplete data completed. It concerns the factual accuracy or completeness of personal data, not disagreement with opinions, assessments, or lawfully recorded conclusions. Where a controller records a professional judgment or an opinion, the underlying facts may be correctable, but the assessment itself is not automatically subject to rectification simply because the data subject disputes it. Application depends on the specific facts and the relevant legal framework, so verify against the current official text and, where necessary, obtain professional judgment.
Is the right to rectification the same as the right to erasure?
No. Rectification and erasure are distinct rights that address different situations. Rectification concerns correcting inaccurate data or completing incomplete data, so the data is retained but amended. Erasure concerns the deletion of personal data under defined conditions. A rectification request does not, by itself, trigger deletion, and the two rights may apply independently or together depending on the circumstances. Readers should keep these rights separate when designing response procedures and should consult the applicable legal text for the precise conditions attached to each.
Within what timeframe must a controller respond to a rectification request?
Response timeframes are set by the applicable data protection framework and typically require action without undue delay, with defined maximum periods that may be extendable in certain cases involving complexity or volume. Because the exact periods and extension conditions vary by jurisdiction and are subject to amendment, this entry does not state specific figures. Controllers should confirm the current applicable deadlines against the authoritative text governing their operations and document the date each request is received and actioned.
How should a controller verify the accuracy of the data before making a correction?
Verification practice is fact-specific and generally involves assessing the evidence supporting the requested change against the purpose for which the data is processed. A controller may reasonably ask the data subject to substantiate the claimed inaccuracy where the existing data is not clearly wrong, while balancing that against the obligation not to impose disproportionate barriers. What counts as adequate verification depends on the sensitivity of the data and the risk of acting on an unverified change. Organizations should establish a documented, consistent process and apply professional judgment to individual cases.
Does a controller need to inform other recipients when data is rectified?
In many frameworks the controller is generally expected to communicate a rectification to recipients to whom the personal data has been disclosed, unless doing so proves impossible or involves disproportionate effort, and to inform the data subject about those recipients on request. The precise scope of this obligation depends on the applicable text and the circumstances of the disclosure. Controllers should maintain records of downstream recipients so that such notifications can be made, and verify the exact requirement against the current official source.
What should a controller do if it declines a rectification request?
Where a controller does not act on a request, it is generally expected to inform the data subject of the reasons, and typically to advise them of available avenues such as complaining to the relevant supervisory authority or seeking a remedy, within the timeframe set by the applicable framework. Refusals should be documented with the basis for the decision to support accountability. Because the specific notification requirements and available remedies vary by jurisdiction, confirm them against the authoritative text and treat contested cases as matters warranting professional judgment.

Common misconceptions

The right to rectification lets an individual change any information a controller holds, including opinions, assessments, or lawful records they disagree with.
The right generally concerns factual accuracy and completeness of personal data. It does not typically compel a controller to alter professional opinions, evaluative judgments, or records that are accurate as a statement of what was decided or recorded, though a supplementary statement may sometimes be added. Application depends on the facts.
Rectification is a universal legal right that applies the same way everywhere.
It is a statutory right under the EU GDPR and the UK GDPR and may have extraterritorial reach for organizations targeting or monitoring individuals in those territories. Other jurisdictions, including sectoral regimes in the United States, address correction differently or may not grant an equivalent standalone right. Scope varies by jurisdiction.
A controller must correct data immediately and unconditionally upon request.
Controllers act without undue delay but may take reasonable steps to verify the requester's identity and the accuracy of the claim, and may refuse or charge for manifestly unfounded or excessive requests. Obligations are fact-specific and subject to the conditions in the applicable text.

Best practices

Establish a documented intake and verification process so rectification requests are logged, the requester's identity is confirmed, and responses are issued within the applicable regulatory timeframe.
Distinguish rectification requests from related requests (access, erasure, restriction) at triage, since each carries different obligations and outcomes.
Maintain records of data recipients so that corrections can be communicated downstream, and document any case where notification is deemed impossible or disproportionately burdensome.
Define clear criteria and an escalation path for evaluating disputed accuracy, distinguishing correctable factual errors from opinions or records that are accurate as recorded.
Where a claim cannot be verified or resolved, consider adding a supplementary statement rather than refusing outright, and record the reasoning for the decision.
Verify current deadlines, fee conditions, and grounds for refusal against the latest official text of the applicable regulation, as requirements and enforcement practice may change and application to specific cases requires professional judgment.
Digital advertisement promoting the whitepaper “The State of Application Security in Modern Software,” showing the cover f the whitepaper and text highlighting AppSec risks, AI code threats, API vulnerabilities, and a button to download the whitepaper.