Your information is not simply “online”. Organisations hold it, combine it and sometimes resell it, including organisations you have never heard of. Personal data rights are the legal tools that let you find out how information is used, ask for correction or erasure, and object to certain uses.
In France and the European Union, the main framework is the GDPR, with the CNIL as France's supervisory authority. Elsewhere, other rules apply. In the United States, for example, several states provide residents with access, correction or deletion rights, but definitions and exceptions vary. This guide explains the useful concepts, practical steps, recurring difficulties with brokers and data reappearance, and habits that help you maintain control.
What your data rights cover
Information is personal data when it identifies you directly or indirectly. Examples include names, contact details, technical identifiers and, depending on the context, browsing records. Under the GDPR, rights are legal obligations for covered organisations, with response deadlines and remedies. They are not optional contractual perks.
These are the rights most commonly relevant in everyday situations. The descriptions are simplified; each has conditions and exceptions.
| Right | What it helps you do |
|---|---|
| Access | Find out what data an organisation holds about you and how it uses it. |
| Rectification | Correct inaccurate or incomplete information. |
| Erasure | Request deletion in the circumstances provided by law, including under Article 17. |
| Restriction | Limit processing while an accuracy dispute or other qualifying issue is examined. |
| Portability | Receive qualifying data in a reusable format where the GDPR's conditions apply. |
| Objection | Object to certain processing, including direct marketing and some uses based on legitimate interests. |
These rights support your ability to act on information held about you. They coexist with legal retention duties, freedom of expression and other interests, so a properly justified refusal may be lawful in some cases.
How to exercise your rights
A typical request follows these steps:
- Identify the organisation responsible for the processing, usually through its privacy page, legal notice or data protection officer (DPO) contact.
- Make a clear request, stating whether you want access, correction, erasure or another right, and referring to the GDPR where it applies.
- Verify your identity proportionately if reasonably necessary. Only send identity documents where needed and through a secure channel.
- Allow the applicable response period. Under the GDPR, this is normally one month, with extensions possible in specified circumstances.
- Follow up, then consider a complaint to the relevant authority, such as the CNIL in France, or other legal remedies.
The same basic process applies to websites, directories and data brokers. The practical experience varies considerably between a large platform with a clear form and a smaller, less transparent operator. Repeating the process across many sources takes time, which is where tools and assistance can help.
Europe and the wider international picture
The GDPR in the European Union
The GDPR applies within its territorial and material scope. This includes processing in the context of an EU establishment and, in specified cases, offering goods or services to people in the EU or monitoring their behaviour there. Its principles include lawfulness, transparency, purpose limitation, data minimisation, accuracy, retention limits, integrity and confidentiality.
The CNIL provides explanatory pages and templates for exercising rights in France. Its GDPR resources are a useful starting point for understanding and drafting a request.
Outside the European Union
There is no single worldwide equivalent to the GDPR. In the United States, privacy regulation is spread across sector-specific federal rules and state laws. California is one example of a state providing rights concerning access, deletion and certain sales or sharing of data, subject to applicable definitions and conditions. Other states have their own frameworks.
If you live in Europe, begin by checking whether the GDPR applies and consult your country's data protection authority. US state laws may be relevant if you meet their residency and other requirements. The location of a company's headquarters alone does not determine every applicable right.
Common difficulties
Brokers and the open web
Data brokers combine information from multiple sources, such as public records, social profiles and commercial partners. This creates several practical problems:
- you may not know every database containing your information;
- opt-out procedures can be hard to find or repetitive;
- data may reappear after a new collection or partnership.
Similar issues arise on the open web and in search results. Even after removal from one source, old profiles, copies or archives may remain elsewhere.
Common mistakes
- Assuming a social network privacy setting replaces a formal erasure request or marketing objection to another organisation.
- Sending one round of requests and never checking again, even though sources and broker records change.
- Confusing deletion by the data holder with Google delisting. These actions can complement each other. Read about personal information in search and the right to erasure.
A realistic aim is to reduce exposure, document requests and repeat action when necessary. Complete disappearance from the internet cannot be guaranteed.
Practical habits
- Map exposure: start with a digital footprint scan of public websites, brokers and known breaches.
- Prioritise: address exposure combining identity, location or sensitive financial information first.
- Keep evidence together: dates, screenshots and delivery acknowledgements help with follow-ups and complaints.
- Secure accounts: use unique passwords and two-factor authentication to reduce the risk of unauthorised access.
- Plan follow-up: check periodically, for example quarterly or after learning of a relevant breach, for information that has reappeared.
Tools can help maintain consistent detection, request preparation and follow-up across many organisations. They do not remove the need to review uncertain responses and distinguish what has actually been deleted from what has merely been requested.
To see how Data Knight connects the scan, target selection and request sending, read our method.
In summary
Data rights are practical tools for acting on information held in databases you do not control. In Europe, the GDPR provides the main framework; elsewhere, check the relevant local rules.
The challenge is also practical: finding brokers, navigating request processes and dealing with reappearing information. A sustained approach combines evidence, regular review and suitable tools.
Want to see where your data appears and act with clear tracking? Start a free scan, then choose your removal targets and follow your requests.
See also: GDPR Article 17 in practice · Remove broker information · Digital footprint and GDPR guide · Authorising a representative



