Data subject rights are the rights UK GDPR gives every person over the personal data an organisation holds about them, such as the right to see it, correct it, have it deleted or stop it being used for marketing. The “data subject” is simply the person the data is about: a customer, subscriber, website visitor or enquirer.
How data subject rights work
There are eight rights. The table shows each one with an example of how it tends to reach a marketing team.
| Right | What it means in marketing |
|---|---|
| To be informed | Your privacy notice explains what you collect, why and who receives it |
| Of access | A customer asks for a copy of everything you hold, known as a subject access request |
| To rectification | Someone asks you to correct their name or email address in the CRM |
| To erasure | Someone asks to be deleted, often called the right to be forgotten |
| To restrict processing | Someone disputes the accuracy of data and asks you to pause using it |
| To data portability | Someone asks for data they gave you in a reusable format |
| To object | Someone tells you to stop sending marketing or profiling them |
| Around automated decisions | Someone challenges a decision made about them by software alone |
Requests can arrive by any route: email, phone, a social media message, even a comment to a member of staff. They do not have to mention the law. You normally have one month to respond, which can be extended by up to two further months for complex or numerous requests, and you usually cannot charge. You may ask for proof of identity where you genuinely need it.
Most rights involve balancing. The right to erasure, for example, does not apply where you must keep records for tax or legal reasons. The right to object to direct marketing is different: it is absolute. Once someone objects, you must stop, with no exceptions and no balancing test. That is why a suppression list exists. You keep the minimum detail needed, usually the email address or a hashed version of it, so the person is never added back by a later import.
The Data (Use and Access) Act 2025 adjusts some of the rules, including how far searches for a subject access request need to go. At the time of writing (October 2026), check the ICO’s guidance for which changes have commenced.
Why it matters for a UK business
Marketing data sits in more places than people expect: the email platform, the CRM, spreadsheets, booking systems, ad platforms holding uploaded audiences, and call recordings. A request has to cover all of them, within a month, and the person making it is often already unhappy. A slow or partial response turns a minor complaint into an ICO complaint. Respecting objections everywhere also protects your sender reputation, because people who are still emailed after objecting tend to report messages as spam.
Common mistakes
- Deleting someone who unsubscribed, then re-importing them from an old list because there was no suppression record.
- Honouring an objection in the email platform but leaving the person in Customer Match or other ad audiences.
- Missing requests made by phone or on social media because staff do not recognise them.
- Starting the one-month clock only when the request reaches the right person.
- Asking for excessive ID from someone you already know well.
How to act on it
Map where personal data lives, then write a one-page process: who receives requests, how identity is checked, where each system is searched and who signs off the reply. Keep one central suppression list and sync it to every email, CRM and ad audience tool. Make sure every marketing email carries a working unsubscribe link, and log each request with its date and outcome. A digital marketing strategy I write for a client includes this map of data and suppression flows, because the same map is what keeps campaigns compliant.
