Data Subject Rights
Data subject rights are the legal protections that give individuals control over how organizations collect and use their personal data. Under laws such as the GDPR, a data subject is a living person who can be identified from that data, and these rights allow them to do things like access their information, correct mistakes, or be informed about how it is used. Organizations are responsible for honoring valid requests to exercise these rights, though the specific rights and how they apply can vary by law and situation.
Data subject rights are the enforceable entitlements granted to natural persons ('data subjects') under data protection frameworks, most notably the EU and UK GDPR, that govern how controllers and processors handle their personal data. Chapter 3 of the GDPR enumerates these rights, which include transparent information and communication, the right to be informed about collection and use, the right of access (Article 15) to obtain a copy of one's personal data along with supplementary information, and the right to rectification of inaccurate data, among others. In a security leadership context, supporting these rights is a governance and compliance function: a virtual or fractional CISO may advise on designing intake, verification, and fulfillment processes and on aligning them with statutory response obligations, but legal accountability for lawful processing and for responding to valid requests remains with the client organization and its officers. The scope, applicability, and procedural conditions of each right vary by jurisdiction, regulation, and the lawful basis for processing.
Why it matters
Data subject rights sit at the intersection of legal compliance and operational readiness, and they create obligations that a security leadership function is often asked to help operationalize. Under frameworks such as the EU and UK GDPR, individuals can request access to their personal data, ask for corrections, and expect to be informed about how their data is collected and used. When an organization cannot locate, retrieve, or correct personal data in response to a valid request, the failure is rarely purely legal, it usually reflects gaps in data inventory, access controls, and process design that fall within the governance remit a virtual or fractional CISO helps address.
The practical significance is that honoring these rights depends on infrastructure and process, not just policy statements. Responding to a right of access request under GDPR Article 15, for example, requires knowing where personal data lives, being able to verify the requester's identity, and being able to compile a copy of the data along with the required supplementary information. Organizations that have not mapped their data or defined intake and fulfillment workflows tend to discover those weaknesses only when a request arrives and a statutory response deadline is running.
It is important not to overstate what a security leader delivers here. A virtual or fractional CISO can advise on designing and aligning these processes, but legal accountability for lawful processing and for responding to valid requests remains with the client organization and its officers. Engagement of qualified legal or privacy counsel is typically appropriate, because the scope and procedural conditions of each right vary by jurisdiction, regulation, and the lawful basis for processing.
Who it's relevant to
Inside DSR
Common questions
Answers to the questions practitioners most commonly ask about DSR.