When a client writes asking to "exercise their ARCO rights", many companies do not even know exactly what is being requested or within what deadline they must reply. The acronym itself is part of the problem: ARCO belongs to a law that is no longer in force. This guide clarifies what those rights really mean today, what the correct catalogue is under the GDPR and, above all, how an organisation must handle a request step by step, without mistakes.
In 15 seconds
- "ARCO rights" is outdated terminology: it comes from the LOPD of 1999. The GDPR expanded and renamed the catalogue.
- Today there are seven rights (arts. 15 to 22 GDPR): access, rectification, erasure, restriction, portability, objection and automated decisions.
- The response period is one month, extendable to two in complex cases (art. 12 GDPR).
- The exercise is free of charge, except for manifestly unfounded or excessive requests.
- Before responding, you must verify the identity of the person requesting.
What ARCO rights were and why they are no longer called that
ARCO is the acronym for four rights: Access, Rectification, Cancellation and Objection. It was born with the old Organic Law 15/1999 (LOPD), which was the Spanish data protection rule until the GDPR started to apply in May 2018. For almost two decades it was the usual way to refer to citizens' rights over their data, and that is why the acronym is still so entrenched that many people still use it.
The important nuance for a company is this: today "ARCO rights" is outdated terminology. With the start of application of the Regulation (EU) 2016/679 (GDPR) and the approval of Organic Law 3/2018 (LOPDGDD), the catalogue not only changed its name, but was expanded. "Cancellation" was split and refined, and new rights appeared that the LOPD of 1999 did not contemplate. Continuing to talk about "the four ARCO rights" in 2026 falls short: it leaves out several powers that the data subject can indeed exercise.
For positioning and search purposes, the acronym is still useful —many people type it—, but for the real operation of an organisation the correct approach is to work with the updated catalogue. That is the one to know when a request arrives.
The current catalogue of GDPR rights
The GDPR regulates the rights of data subjects in its articles 15 to 22, and the LOPDGDD develops and specifies them for Spain in its articles 12 to 18. There are seven rights. The four classic ones are still there —with "cancellation" turned into "erasure"— and three are added that did not exist under the ARCO designation:
| Right | GDPR article | What it allows the data subject to do |
|---|---|---|
| Access | Art. 15 | To know whether the company processes their data and to obtain a copy, together with information about purposes, categories, recipients and periods. |
| Rectification | Art. 16 | To correct inaccurate data and complete data that is incomplete. |
| Erasure ("right to be forgotten") | Art. 17 | To request the deletion of their data when one of the situations provided for applies (no longer necessary, consent withdrawn, etc.). |
| Restriction of processing | Art. 18 | To ask for their data to be temporarily "frozen" —kept but not used— while, for example, a challenge to its accuracy is resolved. |
| Portability | Art. 20 | To receive, in a structured and commonly used format, the data they provided, and to transmit it to another controller. It only applies to processing based on consent or contract and carried out by automated means. |
| Objection | Art. 21 | To object to the processing on grounds relating to their particular situation. In direct marketing, the objection is unconditional. |
| Automated decisions and profiling | Art. 22 | Not to be subject to decisions based solely on automated processing —including profiling— that produce legal effects or significantly affect them. |
There is an eighth element that is not an autonomous right but is worth bearing in mind: art. 19 GDPR requires the company to communicate any rectification, erasure or restriction to each recipient to whom the data has been disclosed, unless this proves impossible or involves disproportionate effort. In other words, handling a right is not always exhausted within one's own database: it may drag along notices to providers or processors.
It is worth dispelling a frequent misconception here: none of these rights is absolute. The right to erasure, for example, does not require deletion if the company must retain the data to comply with a legal obligation —an invoice has its own tax periods—. Responding correctly does not mean always saying yes, but knowing when the right applies and when there is a legal basis that modulates it.
Response deadline, free of charge and identification
The rules common to all rights are in art. 12 GDPR, and they are the ones most often breached out of ignorance. Three are especially important for any company.
The deadline: one month, extendable to two
The company has one month from receipt of the request to respond. That period may be extended by two additional months when the requests are especially complex or several accumulate, but the extension must be communicated to the data subject —with its reasons— within the first month. The period runs even if the company decides not to act on the request: even in that case it must reply within one month, explaining why and reminding of the possibility of lodging a complaint with the supervisory authority.
Free of charge
The exercise of rights is, as a general rule, free of charge (art. 12.5 GDPR). The response cannot be made conditional on any payment, nor can obstacles be set that, in practice, discourage the data subject. The exception —unfounded or excessive requests— is explained below and is interpreted strictly.
Identification of the requester
Before handing over data or acting on it, the company must reasonably verify that the person requesting is the data subject. Handing one person's data to a third party posing as them would, in itself, be a breach of confidentiality. Art. 12.6 GDPR allows additional information to be requested to confirm identity when there are reasonable doubts, but that verification must be proportionate: asking for a photocopy of the national ID "by default" from everyone is usually excessive and contrary to the minimisation principle.
How your company responds, step by step
When a request arrives —by email, web form, letter or even orally—, it is worth always following the same internal circuit. This list works as a basic response protocol:
Checklist: handling a rights request
- Record the date of receipt. The one-month period starts counting from that moment; note the day so as not to lose control.
- Identify which right is being exercised. The data subject does not need to cite the article or use the correct word: if someone asks "to delete my data", it is an erasure (art. 17), even if they say "cancellation".
- Verify the identity of the requester proportionately, asking for additional data only if there are reasonable doubts.
- Locate the data in all your systems relying on the Record of Processing Activities: which processing activities are affected, in which software they are and which providers have them.
- Assess whether the right applies or whether there is a legal basis that modulates it (tax, employment retention obligation, etc.).
- Execute the action: provide the copy, correct the data, erase, restrict, export or object, as appropriate.
- Propagate the change to processors and recipients when applicable (art. 19 GDPR).
- Respond in writing and document. Reply to the data subject within the deadline and keep a record of the request and of what was done, as proof of accountability.
The step most companies neglect is the penultimate and the last one: documenting. It is not enough to do things well; you have to be able to demonstrate that they were done. Keeping the request received, the identity verification and the response sent is what allows you to prove, if ever asked, that the organisation handled the right on time and in form.
"The problem is almost never refusing to handle a right. It is not knowing where the data of the person asking is. A company that has not mapped its processing activities responds late, incompletely and without being able to prove what it did."
Mario P. Talamillo · Managing Partner, Certix®
Unfounded or excessive requests
Art. 12.5 GDPR provides an escape valve for abusive cases: when the requests from the same data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the company may choose to charge a reasonable fee —limited to the administrative costs— or to refuse to act.
That said, this exception is interpreted strictly and should be handled with caution:
- The burden of proof falls on the company. It is the organisation that must demonstrate the unfounded or excessive nature, not the data subject who must justify why they exercise their right.
- Repeating does not equal abusing. The fact that someone exercised a right months ago does not make a new request excessive if the circumstances have changed.
- Refusing also requires a response. Even if the request is rejected, you must reply within the deadline explaining the reason and reminding of the route to lodge a complaint with the supervisory authority.
In practice, invoking this exception lightly generates more risk than handling the request. It only makes sense when the pattern of abuse is evident and documented.
How Certix helps you manage them
Handling a rights request well does not depend on having a saved response template, but on the organisation knowing where its data is and who processes it. That knowledge is not improvised the day the email arrives: it is built beforehand, with a correct map of processing activities and a clear internal circuit of who receives, who verifies and who executes.
At Certix we work precisely on that foundation. We start from a real analysis of your activity, document your processing activities and establish the rights-response protocol as part of the data protection system, not as an isolated annex. When a request arrives, your team knows what to do, within what deadline and how to document it.
You can go deeper into the regulatory framework with our complete guide to the GDPR and the guide to the LOPDGDD, or talk to us directly about how to get rights management ready in your company.
Frequently asked questions
Do ARCO rights still exist under the GDPR?
The acronym ARCO (Access, Rectification, Cancellation and Objection) comes from the old LOPD of 1999 and is today outdated terminology. The GDPR and the LOPDGDD expanded and renamed that catalogue: access (art. 15), rectification (art. 16), erasure or right to be forgotten (art. 17), restriction (art. 18), portability (art. 20), objection (art. 21) and the right not to be subject to automated decisions (art. 22). When a company receives a request it must respond in accordance with this current catalogue, which is broader than the original four letters.
How long does my company have to respond to a rights request?
Art. 12 GDPR sets a general period of one month from receipt of the request, extendable by two additional months when they are especially complex or numerous. If extended, the data subject must be informed of the extension and its reasons within the first month. Even if the company decides not to act on the request, it must likewise communicate this within one month, explaining the reasons and indicating the possibility of lodging a complaint with the supervisory authority.
Can my company charge for handling a rights request?
As a general rule, no: the exercise of rights is free of charge (art. 12.5 GDPR). Only when the requests from the same data subject are manifestly unfounded or excessive, in particular because they are repetitive, may the company charge a reasonable fee for the administrative costs or refuse to act. In that case, it is the company that must demonstrate the unfounded or excessive nature of the request.
Do I have to identify the person exercising the right before giving them their data?
Yes. Before providing information or acting on the data, you must reasonably verify that the person requesting is the data subject, so as not to hand personal data to a third party. Art. 12.6 GDPR allows additional information to be requested to confirm identity when there are reasonable doubts, but that verification must be proportionate and cannot become a barrier to discourage the exercise of the right.
In summary
Talking about "ARCO rights" in 2026 is talking with the vocabulary of a repealed law. The current catalogue is broader —seven rights between articles 15 and 22 of the GDPR— and comes with very specific handling rules: a one-month deadline, free of charge and identity verification. For a company, handling them well is not a matter of having a template, but of knowing where its data is and having a clear circuit to respond on time and keep it documented. That is the work worth having done before the first request arrives.
Related reading
- Complete guide to the GDPR — the framework where the rights of data subjects are regulated.
- Guide to the LOPDGDD — how the Spanish law develops and specifies those rights.
- Record of Processing Activities (RoPA) — the data map that underpins every response to a request.
This content is purely informational and educational; it does not constitute specialised legal advice in any case. The application of the regulations to each specific case requires individual analysis.
Would your company know how to respond to a rights request tomorrow?
At Certix we get the rights-handling protocol ready based on a real analysis of your processing activities, so that you respond on time and with a record.
Speak to a consultant