What is the "Right to Rectification" under the GDPR?
The GDPR's right to rectification allows individuals to have inaccurate personal data corrected and incomplete data completed. This article explains Article 16, how to handle rectification requests, response deadlines, verification requirements, and when controllers may refuse a request.
Key points: (1) EU data protection law gives individuals the right to have inaccurate personal data rectified or completed if it is incomplete. (2) An individual can make a request for rectification verbally or in writing. (3) Controllers have one calendar month to respond to a request for rectification. (4) In certain circumstances, controllers may refuse a request for rectification. (5) The right to rectification is closely linked to the controller's obligations under the accuracy principle.
What is the right to rectification and why is it important?
Under EU data protection law, individuals have the right to have inaccurate personal data rectified. They may also have the right to have incomplete personal data completed, depending on the purposes of the processing. In some cases, this may involve appending a supplementary statement to the incomplete data.
Article 16 of GDPR provides:
The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
The right to rectification is closely linked to the accuracy principle, which requires controllers to take reasonable steps to ensure that personal data is accurate and, where necessary, kept up to date.
How can a Rectification Request be made?
EU data protection law does not prescribe any specific form for making a request for rectification. An individual may make a request verbally or in writing, and it may be submitted to any department within the organization. The request does not need to be directed to a specific individual or contact point, nor must it refer to the "right to rectification" or cite any particular legal provision.
A request is valid as long as the individual clearly challenges the accuracy of their personal data and asks that it be corrected or completed.
Because any employee could potentially receive a valid request, organizations should ensure that staff who regularly interact with data subjects are trained to recognize these requests.
Verifying identity
Where a controller has reasonable doubts about the identity of the person making the request, it may ask for additional information to verify the requester's identity. However, the controller should request only the information that is necessary to confirm the individual's identity. The key principle is proportionality.
The one-month period for responding to the request begins once the controller receives the additional information needed to verify the requester's identity.
When requesting additional information, the controller must inform the data subject, without undue delay, of:
- the reasons why the additional information is being requested;
- the right to lodge a complaint with a supervisory authority; and
- the right to seek a judicial remedy to enforce this right.
Assessing Accuracy and Rectifying Personal Data
Once the controller has received a valid request and verified the requester's identity, it must take reasonable steps to determine whether the personal data is accurate and, where necessary, rectify it. In doing so, the controller should consider the arguments and evidence provided by the data subject.
What constitutes "reasonable steps" depends on the nature of the personal data and the purposes for which it is processed. The more important it is that the data is accurate, the greater the effort expected of the controller to verify its accuracy and, where appropriate, correct it. For example, a controller should devote greater effort to rectifying inaccurate personal data that is used to make significant decisions affecting an individual than to data used for less consequential purposes.
EU data protection law does not define the term accuracy. In general, personal data may be considered inaccurate if it is incorrect or misleading.
Determining whether personal data is inaccurate can be more complex when the data relates to a mistake that has since been corrected. In these circumstances, it may be appropriate to retain the original record because it accurately documents what occurred at the time. Rather than deleting the original record, the controller should ensure that both the original record and the corrected information are retained so that the record accurately reflects the full history of the matter.
Example: If a GP diagnosed a patient as suffering from a particular illness or condition, but it is later proved that this is not the case, it is likely that their medical records includes both the initial diagnosis (even though it was later proved to be incorrect) and the final findings. Whilst the medical record shows a misdiagnosis, it is an accurate record of the patient’s medical treatment. As long as the medical record contains the up-to-date findings, and this is made clear in the record, it would be difficult to argue that the record is inaccurate and should be rectified.
Where the personal data records an opinion, it may be difficult to conclude that the data is inaccurate because opinions are inherently subjective. Provided the record clearly indicates that the information is an opinion and, where appropriate, identifies whose opinion it is, it may be difficult to conclude that the data is inaccurate and requires rectification.
Data subjects also have the right to request the restriction of the processing of their personal data while they contest its accuracy. As a matter of good practice, controllers should restrict the processing of the disputed personal data while verifying its accuracy, regardless of whether the individual has formally exercised their right to restriction.
If the controller concludes that the personal data is accurate, it must inform the individual that the data will not be amended. The controller should explain the reasons for its decision and inform the data subject of the right to lodge a complaint with a supervisory authority and to seek a judicial remedy to enforce their rights.
It is also good practice to record in the system that the individual challenged the accuracy of the personal data, together with the reasons for the challenge.
Best practices for handling a rectification request

Although not legally required, organizations should establish internal procedures to ensure request are handled consistently. It is also good practice to:
- have a policy for recording details of requests, particularly those made by telephone or in person;
- confirm with the requester that the organization has correctly understood the request, helping to avoid later disputes about its interpretation; and
- maintain a log of verbal requests.
Organizations may offer standard request forms to simplify the process, but individuals cannot be required to use them.
Informing Others of the Rectification or Completion: If the controller has disclosed the personal data to others, it must notify each recipient of the rectification or completion of the personal data, unless doing so proves impossible or would involve a disproportionate effort. If requested, the controller must also inform the individual about the recipients to whom the personal data was disclosed. GDPR defines a "recipient" as a natural or legal person, public authority, agency, or other body to which the personal data is disclosed. This definition includes controllers, processors, and persons who, under the direct authority of the controller or processor, are authorized to process personal data. (See Article 4)
Responsibility for complying with requests rests with the controller. Controllers must ensure that they have appropriate contractual arrangements in place with their processors to ensure that requests are handled properly, regardless of whether they are received directly by the controller or by the processor. The time limit for responding to a request cannot be extended simply because the controller must rely on a processor to assist in fulfilling the request.
Time limits, refusals, and fees
Under GDPR, controllers must respond to a request for rectification without undue delay and, in most cases, within one month of receiving the request. In certain circumstances, this deadline may be extended where permitted by GDPR.
When Can a Controller Refuse a Request?: The right to rectification is an important data protection right, but it is not absolute. A controller may refuse a request where it determines that the personal data is already accurate and complete. A controller cannot refuse a request simply because correcting the data would be inconvenient, time-consuming, or administratively burdensome.
When assessing whether personal data should be rectified, the controller must take reasonable steps to verify the accuracy of the data, taking into account the nature of the personal data, the purposes of the processing, and any arguments or evidence provided by the data subject.
Member State laws may also restrict the right to rectification in specific circumstances.
Manifestly Unfounded or Excessive Requests: A controller may refuse to act on a request—or charge a reasonable fee—if the request is manifestly unfounded or excessive, particularly where it is repetitive.
In these circumstances, the controller may:
- charge a reasonable fee to cover the administrative costs of responding; or
- refuse to comply with the request altogether.
The controller bears the burden of demonstrating that the request is manifestly unfounded or excessive and must be able to justify its decision.
Informing the Individual: If a controller refuses to comply with a request for rectification, whether in whole or in part, it must inform the individual without undue delay and no later than one month after receiving the request.
The response must explain:
- the reasons for refusing to take action;
- the individual's right to lodge a complaint with the competent supervisory authority; and
- the individual's right to seek a judicial remedy.
Additional Reading
Article 16 of GDPR
Suitable Recitals: (65) Right of Rectification and Erasure
