Certix

Access, rectification, erasure and objection: what each one is and how it is handled

Certix
Certix®
· 14 Jul 2026 · 11 min read

Informative article. It does not replace individualised professional advice.

Anyone whose data your company processes can write to you to access it, correct it, ask you to delete it or refuse a specific use. This is not an optional formality or a courtesy: they are rights recognised in the GDPR and your organisation has the obligation to handle them, generally within one month. This guide explains, one by one, what each right allows, when it applies, what limits it has and how it is handled in practice from the company's side.

This is the operational detail of each right. If you are looking for an overview of all of them and how they fit into the relationship between the data subject and your organisation, start with the guide to data subject rights before the company.

In 15 seconds

  • Access (art. 15): know what data you hold on a person and what you use it for.
  • Rectification (art. 16): correct inaccurate data or complete incomplete data.
  • Erasure or "right to be forgotten" (art. 17): delete the data, save for legal exceptions.
  • Objection (art. 21): stop a specific processing operation; against marketing, unconditionally.
  • Response deadline: one month from receipt (art. 12), extendable by two months in complex cases.

Right of access (art. 15 GDPR)

The right of access allows anyone to know whether your company processes their data and, if so, obtain a copy of it together with information on how you use it. It is the starting point for all the other rights: without access, the data subject cannot know whether they need to rectify, object or request erasure.

When someone exercises access, your organisation must provide them with a copy of their personal data and, in addition, inform them of:

  • The purposes of the processing and the categories of data you handle about that person.
  • The recipients to whom you have disclosed or will disclose their data, including those in other countries.
  • The envisaged retention period or the criteria used to determine it.
  • The existence of the other rights (rectification, erasure, objection, restriction) and of the right to lodge a complaint with the supervisory authority.
  • The source of the data where it was not obtained directly from the data subject.
  • The existence, where applicable, of automated decisions, including profiling.

Limits of the right of access

The first copy is free. The company may charge a reasonable fee for additional copies, based on administrative costs. There is also an important limit: the right to obtain a copy must not adversely affect the rights and freedoms of others (art. 15(4) GDPR). If a document contains other people's data, it is provided in a way that protects that third-party data —for example, by anonymising or separating the third-party information— rather than denying access entirely.

Right to rectification (art. 16 GDPR)

The right to rectification allows the data subject to correct the inaccurate data you hold about them and complete data that is incomplete, including by means of a supplementary statement. It is probably the simplest right to handle and also one of the most frequent: a change of address, a phone number that is no longer correct, a misspelt name.

From the company's side, handling a rectification properly involves two things. First, updating the data in every system where it appears, not just in the main CRM: if the erroneous data was replicated in a spreadsheet, in the invoicing tool or in the email platform, the correction must reach all of them. Second, where that data has been disclosed to third parties, informing those recipients of the rectification, unless it proves impossible or requires a disproportionate effort.

It is worth not confusing "rectify" with "whatever the customer prefers". Rectification refers to objectively inaccurate data. An internal assessment, a history of incidents or a correct piece of data that the data subject simply does not like are not "rectified": for those situations, the route may be objection or erasure, with their own requirements.

Right to erasure or "right to be forgotten" (art. 17 GDPR)

The right to erasure —popularly known as the "right to be forgotten"— allows the data subject to ask that their personal data be deleted. It is the right that generates the most misunderstandings, in both directions: the company is neither obliged to delete everything it is asked to, nor may it refuse to do so across the board.

When erasure applies

Art. 17 GDPR lists the situations in which deletion applies. The most common in a company's day-to-day are:

  • The data is no longer necessary for the purposes for which it was collected.
  • The data subject withdraws the consent on which the processing was based and there is no other legal basis to cover it.
  • The data subject objects to the processing and there are no overriding legitimate grounds to continue it.
  • The data has been processed unlawfully.
  • It must be deleted to comply with a legal obligation.

When it does NOT apply: the limits of being forgotten

This is the key point for a company. Art. 17(3) establishes that erasure does not apply where the processing is necessary, among others, to comply with a legal obligation, to bring, exercise or defend claims, or for reasons of public interest. The most everyday case is that of mandatory retention: a company cannot delete the invoices of a customer who requests it, because commercial and tax rules require it to keep them for certain periods.

The correct response, therefore, is almost never "I delete everything" or "I delete nothing". It is a data-by-data analysis: what no longer has a legal basis is erased and what must be kept by law is blocked —keeping it available only to judges, courts or public authorities during the legal period— to be securely destroyed afterwards.

The "right to be forgotten" also has a well-known dimension in relation to internet search engines: the possibility of requesting that certain results associated with a person's name stop appearing in searches. The LOPDGDD also expressly recognises the right to be forgotten in internet searches and in social media services. This is a different area from erasure against your own database, but it shares the same basis in art. 17 GDPR.

"The most common mistake is not refusing to delete — it is deleting all at once. A company that erases without thinking may find itself without the invoice it needed to defend against a claim two years later. Being forgotten, done well, distinguishes what no longer needs to be kept from what the law requires to be retained."

Mario P. Talamillo · Managing Partner, Certix®

Right to object (art. 21 GDPR)

The right to object allows the data subject to ask that their data stop being processed for a specific purpose. It does not seek to correct or delete: it seeks to stop a use. Its scope depends heavily on which legal basis the processing being objected to relies on.

Objection on personal grounds

Where the processing is based on the company's legitimate interest or on a task carried out in the public interest, the data subject may object on grounds relating to their particular situation. The company stops processing that data unless it demonstrates compelling legitimate grounds that override the interests of the data subject, or that the processing is necessary to bring or defend claims. In other words, it is not automatic: it has to be weighed up.

Objection to direct marketing: unconditional

Against advertising and direct marketing, the objection is unconditional. If a person asks to stop receiving commercial communications, your company must stop without them having to justify anything (art. 21(2) and 21(3) GDPR). It is not permissible to ask for reasons, offer "alternatives" or delay the cessation. In practice, this translates into unsubscribe links that actually work, the effective removal of the contact in all sending tools, and keeping a record of the date so as not to reoffend.

Restriction (art. 18) and portability (art. 20)

Alongside the four rights above, the GDPR recognises two others worth knowing because they appear frequently in requests.

Right to restriction (art. 18 GDPR)

Restriction is a kind of "pause". The data subject does not ask to delete or correct: they ask that their data be marked and temporarily stop being processed, keeping it but not using it, while a situation is resolved. It applies, among other cases, where the data subject has contested the accuracy of a piece of data (for the time the company takes to verify it) or where they have objected to a processing operation and it is pending to check whether the company's grounds prevail. During restriction, the data may only be processed with the data subject's consent or for claims.

Right to portability (art. 20 GDPR)

Portability allows the data subject to receive the data they themselves provided in a structured, commonly used and machine-readable format (for example, CSV or JSON), and transmit it to another controller. It has three cumulative conditions: it only covers data provided by the data subject themselves, only where the processing is based on consent or a contract, and only where it is carried out by automated means. Inferred data or assessments the company has produced are excluded.

Summary table of the rights

Right Article What it allows Main limit
Access Art. 15 Obtain a copy of their data and information on its use. Must not harm the rights of others.
Rectification Art. 16 Correct inaccurate data and complete incomplete data. Only objectively inaccurate data.
Erasure (forgotten) Art. 17 Delete the data when there is no longer a basis to process it. Legal obligation to retain; claims.
Restriction Art. 18 Pause the processing without deleting, temporarily. Grounds exhaustively set out in the rule.
Portability Art. 20 Receive and transmit their data in a reusable format. Only data they provided; consent or contract basis.
Objection Art. 21 Stop a specific processing operation; marketing unconditionally. Compelling legitimate grounds (except marketing).

How a company responds: checklist

Receiving a rights request should not lead to improvisation. The process is always the same, regardless of the right exercised. The general response deadline is one month from receipt (art. 12(3) GDPR), extendable by a further two months in complex cases, always giving notice within the first month.

  • Record the date of entry. The one-month period runs from when you receive the request, whether it arrives by email, form, letter or any other channel. Keep a record of the day.
  • Verify identity proportionately. If you have reasonable doubts, you may request additional information to confirm that the applicant is the data subject (art. 12(6) GDPR), without turning it into a disproportionate barrier.
  • Identify which right is being exercised. Sometimes the data subject does not name it correctly; interpret the request by its content, not by the label they use.
  • Locate all the data. Search in every system, not just the main one. Here the Record of Processing Activities is the tool that tells you where the data is and who holds it.
  • Apply the correct response. Provide, correct, erase, block, restrict or stop depending on the right, analysing the limits and the legal retention obligations.
  • Communicate to third parties. If the data was disclosed to processors or recipients, pass on the rectification or erasure where appropriate.
  • Respond in writing and free of charge. Explain what has been done. If you do not handle the request, inform of the reasons and of the right to lodge a complaint with the supervisory authority.

How Certix helps you

Most problems with data subject rights do not come from bad faith, but from the lack of a procedure. A company that does not know where its data is cannot respond well to an access request, and one that deletes by reflex may breach its own retention obligations. It all starts with having the processing map in order, something worked on with the Record of Processing Activities.

At Certix we design the rights-handling procedure tailored to your organisation: the receiving channels, the response templates, the identity verification and the criteria to decide, data by data, what is erased and what is retained. And we frame it within the whole body of the regulation, which you can review in our complete GDPR guide.

Frequently asked questions

How long does a company have to respond to an access or rectification request?

The general deadline is one month from receipt of the request (art. 12(3) GDPR). It may be extended by a further two months where the request is particularly complex or where many requests build up, but the extension must be communicated to the data subject within the first month, explaining the reasons. The response is free of charge as a general rule; a fee may only be charged, or the request refused, where it is manifestly unfounded or excessive, and the burden of proving this falls on the company.

Can a company refuse to erase the data if the customer asks for it?

In some cases, yes. The right to erasure under art. 17 GDPR is not absolute: it does not apply where the company needs to keep the data to comply with a legal obligation (for example, tax or accounting retention of invoices), to bring or defend against claims, or where another legal basis covers the processing. The correct approach is neither to delete without further thought nor to refuse across the board, but to analyse data item by item: erase what no longer has a basis and block what must be kept by law for the legal period before its destruction.

How does the right to object differ from the right to erasure?

The right to object (art. 21 GDPR) allows the data subject to ask that their data stop being processed for a specific purpose, especially where the processing is based on legitimate interest or on a task carried out in the public interest. Erasure (art. 17) goes further: it seeks to remove the data. In practice, an upheld objection usually leads to the erasure or blocking of that data for that purpose. Against direct marketing, the objection is unconditional: it is enough to request it for the company to have to stop sending advertising.

How do you verify that the person requesting their data is really the data subject?

Art. 12(6) GDPR allows the additional information needed to confirm the identity of the applicant to be requested where there are reasonable doubts. This does not mean automatically demanding a photocopy of the national ID: verification must be proportionate. It is often enough to cross-check data already held in the system or to confirm the request from the email or channel the data subject already had on file. Requesting excessive documentation can become an unjustified barrier to the exercise of the right.

In short

Access, rectification, erasure and objection are not four versions of the same thing: each responds to a different need and is handled in a different way. What they share is the response framework —the one-month deadline, the free-of-charge nature, the proportionate verification of identity— and the fact that none is resolved well by reflex. Erasure is not "delete everything", objection is not always automatic and rectification does not cover any data that causes discomfort. Having a clear procedure turns a potentially conflictive request into an orderly formality.

Related reading


This content is purely informational and educational; it does not constitute specialised legal advice in any case. Applying the regulations to each specific case requires individual analysis.

Would you know how to respond today to an access or erasure request?

At Certix we design your company's rights-handling procedure from a real analysis of your activity, without generic templates.

Speak to a consultant

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →