Every time a company suffers a data breach or gets caught mishandling personal information, the same question tends to follow: what can the people affected actually do about it? The answer lies in a set of legal protections known as GDPR rights, which apply to anyone whose personal data is collected, stored, or processed by an organisation operating in the UK or EU.
A recent explainer from Prospect360 breaks down these protections under UK GDPR, covering everything from the right to access your own data to the right to have it erased. Understanding these rights is not just a legal exercise. It is a practical tool for anyone who wants more control over how their personal information is used, especially as data breaches and regulatory fines continue to make headlines.
What Rights Do Individuals Have Under GDPR
UK GDPR gives individuals, often called data subjects, a range of rights over their personal data. These include the right to know what data an organisation holds about them, the right to request a copy of it, and the right to have inaccurate information corrected. Perhaps the most well known is the right to erasure, sometimes called the right to be forgotten, which allows people to ask organisations to delete their personal data under certain circumstances.
Other rights cover how data is used rather than just what is held. Individuals can object to certain types of processing, request that their data be restricted from further use while a dispute is resolved, and in some cases ask for their data to be transferred to another provider. These rights exist specifically because personal data, once collected, can be used in ways that affect people long after they hand it over, whether that is targeted advertising, automated decision-making, or simply being sold to a third party without clear consent.
Why These Rights Matter: Lessons from Recent Incidents
GDPR rights are not abstract legal concepts. They become urgently relevant whenever a company loses control of customer data or is found to have mishandled it. Regulators across Europe have shown they are willing to impose significant penalties when organisations fail to respect these protections. The Dutch Data Protection Authority's decision to fine Uber €825 million over a driver GDPR breach is one of the clearest recent examples of how seriously enforcement bodies treat violations of data subject rights.
Breaches involving telecom and healthcare providers illustrate why these rights matter to ordinary people, not just corporations. The Odido data breach exposing 6.2 million records left customers with stolen bank account details in the hands of attackers, while the Unimed billing breach affecting patients at German university hospitals exposed sensitive medical information through a third-party vendor. In both cases, affected individuals had the right to know what data was involved, and to demand answers about how it was being used and protected.
Even government-run systems are not immune. The breach of France's ANTS passport portal showed that identity document infrastructure can be targeted just as easily as private company databases, reinforcing why GDPR rights apply broadly across sectors, not just to tech companies.
How to Exercise Your GDPR Rights
Exercising these rights typically starts with a direct request to the organisation holding your data, often called a Subject Access Request when asking to see what information is held. Organisations are legally required to respond within a set timeframe and cannot simply ignore or indefinitely delay these requests. If a company fails to comply, individuals in the UK can escalate the matter to the Information Commissioner's Office, the regulator responsible for enforcing UK GDPR.
It helps to be specific when making a request, whether that means asking for a copy of all data held, correction of an inaccurate record, or full erasure of an account. Keeping a written record of the request and any response received also strengthens your position if a complaint becomes necessary later.
What This Means For You
If you use any online service, from a ride-sharing app to a healthcare provider's billing portal, you already have rights over the data those companies hold about you. You do not need to wait for a breach to make use of them. Requesting a copy of your data, checking it for accuracy, or asking a company to delete information you no longer want them holding are all actions available right now, regardless of whether that organisation has ever been in the news.
When breaches do happen, as seen with pharmaceutical data theft affecting Novo Nordisk's clinical trial data, knowing your GDPR rights means you are better equipped to demand transparency about what was exposed and what the company is doing in response.
Key Takeaways
Understanding your GDPR rights puts real power back in your hands as an individual, rather than leaving data protection entirely up to the companies and regulators. Review privacy policies before signing up for new services, submit a Subject Access Request if you are unsure what data a company holds about you, and do not hesitate to escalate unresolved concerns to the Information Commissioner's Office. Staying informed about GDPR rights is one of the simplest ways to protect your personal information in a landscape where breaches and regulatory fines are becoming increasingly common.




