// Level 3 · Controls

Chapter 3: Rights of the data subject

Rights of the data subject

Art. 12Medium

Transparent information, communication and modalities for the exercise of the rights of the data subject

Information must be concise, transparent, intelligible, easily accessible, plain language; respond within one month.

Art. 13Medium

Information to be provided where personal data are collected from the data subject

Privacy notice requirements when collecting directly: identity, purposes, legal basis, recipients, retention, rights.

Art. 14Medium

Information to be provided where personal data have not been obtained from the data subject

Privacy notice requirements when data obtained indirectly, including source of data.

Art. 15Medium

Right of access by the data subject

Right to confirmation of processing and a copy of personal data plus context (purposes, recipients, retention, rights).

Art. 16Medium

Right to rectification

Right to obtain correction of inaccurate personal data without undue delay.

Art. 17High

Right to erasure ('right to be forgotten')

Right to deletion when data no longer needed, consent withdrawn, unlawful processing, etc.

Art. 18Medium

Right to restriction of processing

Right to limit processing in defined circumstances (accuracy contested, unlawful, etc.).

Art. 19Medium

Notification obligation regarding rectification or erasure of personal data or restriction of processing

Controller must notify each recipient of any rectification, erasure, or restriction unless impossible/disproportionate.

Art. 20Medium

Right to data portability

Receive personal data in structured, commonly used, machine-readable format and transmit to another controller.

Art. 21Medium

Right to object

Right to object to processing based on legitimate interests, public task, direct marketing, or research.

Art. 22Medium

Automated individual decision-making, including profiling

Right not to be subject to solely automated decisions producing legal/significant effects, with safeguards.

Art. 23Medium

Restrictions

Member States may restrict rights when necessary for national security, defence, public security, etc.