A single email asking a company what personal data it holds on you might seem like a minor administrative request. But according to recent enforcement decisions in Europe, that one request can be the thread that unravels an entire company's data protection failures, and it can cost that company millions of euros. GDPR data subject rights, the tools that let ordinary people access, correct, delete, or transfer their personal data, are increasingly becoming the mechanism regulators use to expose much bigger problems inside organizations.
What Are Your GDPR Data Subject Rights, and Why Do They Matter
Under the GDPR, anyone whose personal data is processed by a company or organization operating in the EU has a set of enforceable rights. These include the right to know what data is being collected, the right to access a copy of that data, the right to have inaccurate information corrected, the right to request deletion (often called the "right to be forgotten"), and the right to receive your data in a portable format so it can be moved to another service.
These rights are not new. They have existed since the GDPR came into force. What is changing is how they are being used. Regulators and courts increasingly treat a single data subject request, and how a company responds to it, as a window into the company's overall data governance. If a business cannot answer a straightforward question like "what do you know about me and where is it stored" in a complete and timely way, that failure often signals deeper structural problems: data scattered across disconnected systems, unclear ownership between teams, or processes that were never designed with individual rights in mind.
How One Complaint Turned Into a Multi-Million Euro Fine
Recent European decisions illustrate exactly how this plays out in practice. A person exercises a basic right, often something as simple as asking for access to their own records or requesting that their data be deleted. The company responds incompletely, late, or not at all. What starts as a routine complaint to a data protection authority then escalates into a full investigation, and that investigation frequently uncovers issues that go far beyond the original request: data retained without justification, inconsistent handling across departments, or systems that were never properly audited for compliance.
The result is that fines tied to these cases can reach into the millions of euros, even though the trigger was a single individual asserting rights that already existed on paper. This pattern shows that data subject rights are not just a compliance checkbox. They are an active enforcement lever that regulators are willing to use, and one complaint is often enough to open the door.
This mirrors what happened with Uber's €825 million GDPR fine, which centered on automated decisions, like account suspensions, made without adequate transparency or human review. In both situations, the underlying issue was the same: personal data was being processed at scale without the systems in place to properly account for it when someone asked questions or challenged a decision.
What Companies' Scrambling to Comply Reveals About Your Data Exposure
For consumers, there is an important lesson buried in these enforcement stories. If regulators are finding that companies struggle to produce a complete, accurate picture of an individual's data when formally requested, it strongly suggests that many organizations do not have a clear internal picture either. Personal data often lives in more places than companies realize: marketing databases, support ticket systems, analytics platforms, third-party vendors, and backups that were never fully mapped.
This fragmentation is precisely why a single data subject request can expose so much. It forces a company to actually trace where your information lives, and often that exercise reveals gaps the organization did not know existed. In other words, the same request that protects your rights also functions as a practical audit of how seriously a company takes data protection.
How to Exercise Your Rights and Audit Your Own Data Footprint
You do not need to wait for a regulator to act on your behalf. GDPR data subject rights are available to you directly, and using them is often straightforward:
- Send an access request. Ask a company directly what personal data it holds about you, where it came from, and who it has been shared with.
- Request corrections. If any of the data returned is inaccurate or outdated, you have the right to have it fixed.
- Ask for deletion when appropriate. If you no longer use a service, or the company has no legitimate reason to keep your data, request erasure.
- Request portability. If you want to move your information to a different provider, ask for it in a structured, commonly used format.
- Track response times. Companies are generally expected to respond within a defined timeframe. Delays or incomplete answers can be reported to your national data protection authority.
What This Means For You
The growing enforcement risk tied to GDPR data subject rights is ultimately good news for individuals. It means the rights on paper are backed by real consequences when ignored. If you have ever wondered how much of your personal information is floating around in a company's systems, filing a data access request is a legitimate, low-effort way to find out. It costs you nothing, and companies are legally obligated to respond.
At the same time, these cases are a reminder that data protection failures rarely stay contained. A company that mishandles one person's access request is often mishandling data governance more broadly, which affects everyone whose information passes through its systems.
As a starting point, consider identifying two or three services that hold significant personal information about you, such as a former employer, a subscription service you no longer use, or a platform tied to sensitive data, and submit a formal access or deletion request. Pay attention to how quickly and completely they respond. That response will tell you a lot about how seriously that organization treats GDPR data subject rights, and whether your data is truly under control.




