Everyday Your rights over your own data
Your data rights: what you can ask a company to do
Access, correction, deletion, portability and objection explained in plain terms, plus how to send a request that a company has to answer.
The short answer
- You can ask a company for a copy of your data, ask it to correct or delete what it holds, ask for a portable file, and tell it to stop using your data for marketing or profiling.
- In the EU and the UK these rights come from the GDPR, apply to almost every organization including small ones, and reach companies abroad that sell to or track people there.
- In the US there is no general federal privacy law, so your rights come from your own state, apply only to businesses above a size threshold, and vary in detail from state to state.
- A request is answered faster when you send it to the privacy contact, name the request in one sentence, and give the account identifier the company can search on.
- Deadlines are typically one month in the EU and the UK and forty five days under US state laws, each extendable once with notice to you.
- This is general information rather than legal advice, and which law applies depends on where you live, where the company operates and what kind of data is involved.
You can ask a company for a copy of the data it holds about you, ask it to correct what is wrong, ask it to delete what it no longer needs, ask for your data in a portable file, and tell it to stop using your data for marketing or profiling. Those five cover most of what people want. How strong each one is depends on where you live, because a request only carries weight when the law reaches the company. This is general information rather than legal advice.
The rights you actually have
Most privacy laws describe the same handful of requests in different words. The table gives the plain meaning of each, and how it typically looks under the European and British regime compared with the US state laws now in force.
| What you are asking for | In plain words | EU and UK | US states with a privacy law |
|---|---|---|---|
| Access | Send me a copy of my data and explain what you do with it | Broad, including sources, recipients and retention | Usually the categories held and shared, with the specific data on request |
| Correction | This is wrong, fix it | Yes, and they must tell anyone they shared it with | In most of the newer state laws, not in all |
| Deletion | Erase what you hold about me | Yes, with defined exceptions | Yes, with broader exceptions for data you gave them directly |
| Portability | Give me my data in a file I can reuse | Yes, in a machine readable format | Generally yes, where it is technically feasible |
| Objection or opt out | Stop using my data this way | Absolute for direct marketing, balanced for other uses | Opt out of sale, sharing for targeted ads and profiling |
| Limits on automated decisions | Do not let software decide this about me alone | A specific right with human review | Emerging, usually framed as opting out of profiling |
Two more are worth knowing. You can ask for processing to be restricted, meaning the company keeps the data but stops using it while a dispute is resolved. And you can withdraw consent at any time where consent was the basis for using your data, which is what sits behind the choices in what reject all actually does on a consent banner.
Who has these rights and where
In the EU and the UK, the rights come from the GDPR, and in the UK from the UK version of it alongside domestic data protection legislation. They apply to almost every organization that handles personal data, including small ones, and they reach companies based elsewhere when those companies offer goods or services to people in the EU or UK, or monitor their behavior. A US retailer selling into Germany is covered for its German customers. The rights belong to the person the data is about, whatever their nationality.
In the United States, there is no general federal privacy law. Rights come from state laws, starting with California and now running to roughly twenty states, with more arriving over time. The common shape is a right to know, delete, correct and obtain a copy, plus opt outs for the sale of personal data and for targeted ads. Two limits matter. These laws usually apply only to businesses above a size or revenue threshold, so a small local company may be outside them. And they cover residents of that state, so the law that helps you is the one where you live, not where the company is.
The US also has sector rules that often beat the general state laws: health records, credit files, student records and children's data each have their own regime. If your question is about a credit report or a medical record, start there instead.
Elsewhere the trend runs the same way. Brazil, Canada, Japan, South Korea, South Africa and India all have data laws with access and correction rights of some kind. The vocabulary changes, the core requests do not.
How to send a request that has to be answered
Find the privacy contact rather than general support. It is normally at the foot of the privacy policy, often an address beginning privacy or dpo, and many companies also run a request form in account settings or a dedicated privacy page. Use their form if they have one, because it goes straight to the team that handles this. If the form refuses you, email works: no law requires you to use a specific channel.
Keep the message short and name the request. Something like this, adapted to your situation.
- Who you are, with the email address, username or customer number the account uses.
- The request in one sentence: a copy of all personal data you hold about me, or please delete the personal data you hold about me.
- The basis in general terms: under the GDPR in the EU or UK, or under the privacy law of your state in the US. Naming it signals that you know a deadline applies.
- Anything that narrows the search, such as a date range or one service, which speeds up the answer.
- The format you want, for example a machine readable file.
- Where to send it, and a request for written confirmation of receipt.
Send it from the address on the account, keep the sent copy, and expect an identity check. Verification is legitimate and the clock can start when you satisfy it, but it should be proportionate. Being asked for a passport photo to confirm an address you are already writing from is not. Offer to confirm inside the account instead.
Requests about a particular system are best sent to that system. Data held by an AI assistant follows its own path, in how to delete your AI chat data and what deletion really means, and typing personal details into a chatbot creates records of its own, as what a chatbot does with the personal data you type sets out. The ad profile built from your browsing sits with firms you never signed up with, which is why how web tracking builds a profile of you is worth reading before you choose who to write to.
How long they have and what you should get
In the EU and the UK, the answer is due without undue delay and within one month, extendable by two further months for genuinely complex requests, and the company has to tell you it is extending and why. There is normally no fee. A charge is only allowed for requests that are excessive or repetitive.
Under the US state laws, the common pattern is forty five days with a single extension of another forty five, again with notice. Most of these laws also build in an internal appeal: if a request is refused, you can ask the company to reconsider before going anywhere else.
What arrives is often underwhelming. Access responses usually include account details, transaction history, support tickets, device and location records and any segment labels applied to you. Some firms return a tidy export, others a mass of raw files. Look for the two things a summary tends to hide: who your data was shared with, and what was inferred about you. Those are the parts most often left out, and the ones that matter most if the company is later caught up in a data breach and what it means for you.
The refusals you will meet, and which are legitimate
Some refusals are lawful. A company must keep records it is legally required to keep, so invoices, tax records and regulated financial or health files survive a deletion request. It can refuse to hand over material that would expose another person's data, and it can withhold some investigative or legally privileged material. It can refuse where it genuinely cannot verify who you are. Deleting your account data will usually not delete a record of a transaction that has to exist.
Other refusals are just friction. We do not offer that in your country, said to someone who lives somewhere that does. Use our paid tier to download your data. Deletion means deactivation. We only hold anonymous data, said about records tied to your email address. Silence. In each case reply once, in writing, asking for the specific legal exception they rely on and for a decision you can appeal. That sentence resolves a surprising number of them, because it moves the request from a support queue to a compliance one.
Escalating to a regulator
Regulators are free to use and they take individual complaints seriously, but they are slow and they enforce the law rather than acting as your personal representative. Complain once you have a written refusal or a missed deadline, and attach your original request, their reply and the dates.
In the EU, complain to the data protection authority where you live and it will coordinate with the authority where the company is established. In the UK the Information Commissioner's Office handles complaints and expects you to have asked the company first. In the US enforcement sits with the state attorney general, with California also having a dedicated privacy agency, and most state laws require you to use the internal appeal first. The result is usually pressure on the company rather than compensation for you.
The request worth sending today
Pick one company that knows an uncomfortable amount about you, a retailer, a data broker, a social platform, and send an access request. Reading a real response teaches more about the trade than any explanation, and it shows you which requests are worth sending next.
Then use the rights in order. Access first, because you cannot sensibly ask for deletion until you know what exists. Correction next, since wrong data does more damage than surplus data. Opt outs for marketing and profiling, which are quick and rarely refused. Deletion last, after exporting anything you want to keep, following how to delete an online account properly rather than just deactivating it. Keep every request and reply in one mail folder with the dates visible. That folder is what makes a complaint work later, and it is the record that helps whoever deals with your accounts one day, the practical side of what happens to your accounts after you die.
Common questions
How do I ask a company for all the data they have on me?
Email the privacy contact listed in the privacy policy, or use the request form in your account settings if there is one. Write from the address on the account, state that you are requesting a copy of the personal data they hold about you, and give the username or customer number they can search on. Keep the sent copy and note the date, because the response deadline runs from then.
Do I have GDPR rights if I live in the United States?
Generally not, because the GDPR protects people in the EU and the UK rather than customers of European companies everywhere. You would rely on your own state law instead, if your state has one and the business meets its threshold. In practice many international companies run one process for everyone because it is cheaper than several, so it is often worth asking regardless of where you live.
Can a company refuse to delete my data?
Yes, in defined situations. Records it must keep by law, such as invoices and regulated financial or health files, survive a deletion request, as does material needed to defend a legal claim or protect someone else's data. What it cannot do is refuse without a reason. Ask which specific exception applies and how much data it covers, because the exception rarely covers everything they hold.
How long does a company have to respond to a data request?
In the EU and the UK, one month, with an extension of up to two further months for complex requests if they tell you. Under US state privacy laws, usually forty five days with one extension of the same length. If the deadline passes in silence, send one written reminder that notes the date of your original request, then complain to the regulator.
What do I do if they ignore my request?
Send one short follow up quoting the original date and asking for a written decision you can appeal. If that produces nothing, complain to the relevant regulator: your national data protection authority in the EU, the Information Commissioner's Office in the UK, or your state attorney general in the US, after using the company's internal appeal where the law requires it. Attach your request, any reply and the dates.