The Rights You Can Actually Use
Data protection law is not abstract. It gives you a small number of named rights that a company holding your data has to answer, on a clock, in writing. The details differ by country, but the shape is remarkably consistent wherever modern privacy law applies.
- Access. Ask what they hold, why, where it came from and who else received it.
- Correction. Have inaccurate data fixed, and in some jurisdictions have incomplete data completed.
- Deletion. Have it erased where there is no overriding reason to keep it.
- Objection. Stop certain processing, including in most places direct marketing. Objection to marketing is close to absolute.
- Portability. Receive what you gave them in a structured, machine-readable format - and in some jurisdictions have it sent to another provider.
- Withdrawal of consent, where consent was the basis. It must be as easy to withdraw as it was to give.
- Restriction. Have processing paused while a dispute about accuracy or lawfulness is resolved.
- Non-discrimination. Exercising a right must not cost you a worse price or service.
Two practical facts decide whether any of this works. First, a request has to go to the right recipient - the controller, meaning the organisation that decides why and how your data is processed, not a support queue that will close the ticket. Second, it has to name the right and identify you well enough to be actionable, without handing over more than necessary.
EU and UK Rights Under the GDPR
Under the General Data Protection Regulation, as retained in UK law, the core rights are set out in Articles 15 to 22.
- Article 15 - access. A copy of your personal data, plus the purposes, categories, recipients, retention period, the source of the data, and whether automated decision-making is involved.
- Article 16 - rectification. Inaccurate data corrected without undue delay.
- Article 17 - erasure. The "right to be forgotten", available where the data is no longer needed, consent was withdrawn with no other basis, an objection succeeded, or processing was unlawful. It is not absolute: legal obligations, freedom of expression and public-interest grounds can override it.
- Article 18 - restriction. Processing paused while accuracy or lawfulness is contested.
- Article 20 - portability. Data you provided, in a structured, commonly used, machine-readable format, where processing rests on consent or contract.
- Article 21 - objection. Stop processing based on legitimate interests or public interest, and stop direct marketing outright and unconditionally.
- Article 22 - automated decisions. Protection against decisions made solely by automated means that produce legal or similarly significant effects.
The clock is one month from receipt, extendable by two further months for complex requests, and the extension must be explained with reasons. The response is free, and refusal or delay opens the door to a complaint with the national supervisory authority - the Information Commissioner's Office in the UK, and the equivalent body in each EU member state - and to a judicial remedy.
A point that matters in practice: the regulator is a backstop rather than a helpdesk. Its leverage is the threat of investigation, so a complaint is most effective when the company's failure is clear and documented.
California: Know, Delete, Correct, Opt Out
The California Consumer Privacy Act, as amended by the CPRA, gives residents a related but differently shaped set of rights.
- Know what categories and specific pieces of personal information have been collected, and who received it.
- Delete personal information, subject to exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information, and limit the use and disclosure of sensitive personal information.
- Not be discriminated against for exercising these rights - no worse price or service.
The clocks differ from Europe and are worth diarising: the business must acknowledge receipt within 10 business days, respond substantively within 45 calendar days, and may extend once by a further 45 days with notice. Opt-out requests must be honoured within 15 business days. A right-to-know response reaches back twelve months, and for data collected since 1 January 2022 you can request the full history unless doing so would be disproportionately effortful.
Two mechanisms make this tractable rather than a full-time hobby.
- An authorised agent - a friend, a lawyer or a paid service - can submit requests on your behalf with signed permission. The business may still verify you directly, and it may refuse an agent who cannot prove authorisation.
- The Global Privacy Control is a browser or extension setting that sends a do-not-sell-or-share signal with every request. California treats it as a valid opt-out, which replaces hundreds of banner clicks. Its limits are real: it applies per browser and per device, it does not follow a logged-in account, and businesses outside the law's scope ignore it. See hardening your browser for where to switch it on.
California also runs a central platform, DROP, that lets residents send deletion and opt-out requests to participating businesses from one place. It is worth checking whether the companies you care about participate before writing each of them individually.
Indonesia: Law 27 of 2022
For readers in Indonesia, the governing instrument is Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi (Law No. 27 of 2022 on Personal Data Protection), which replaced a patchwork of sectoral rules with a single framework.
It recognises a comparable set of data subject rights: to obtain information about the processing and the identity of the parties involved, to access and obtain a copy of one's personal data, to request correction or erasure, to withdraw consent, to object to automated decision-making, to restrict processing, to port data to another controller, and to bring a claim for compensation.
Two operational points matter for a reader trying to use it:
- There are deadlines attached to requests, and controllers are expected to respond within them rather than at their convenience. State the deadline in your request and keep the date you sent it.
- The implementing regulation arrived later than the statute, so transitional arrangements governed parts of the framework during its early application. Before relying on a specific procedural step, check the current status with the ministry responsible and with the relevant sectoral regulator, because practice has been settling rather than fixed.
Where a controller is outside Indonesia, jurisdiction can be awkward and the practical leverage is often the foreign law that also applies to it - which is an argument for sending the request under every regime that covers the company, not just the one closest to you.
Writing a Request That Cannot Be Stalled
Most requests fail for procedural reasons rather than legal ones. A useful template has six parts.
- Identify yourself with the identifiers the company can match - the account email address, and any account or customer number. Do not attach a passport scan in the first message.
- Name the right and the instrument. "Under Article 15 GDPR, I request access to my personal data" or "Under the CCPA, I request to know the categories and specific pieces of personal information you have collected about me". Naming the article moves the message from a support conversation to a legal request.
- State the scope precisely: the period, the account, the categories of processing, and whether you want the recipients and retention periods as well as the content.
- Specify the response format - a machine-readable export where portability applies.
- State the deadline and the date you are counting from.
- State what happens next: that you will complain to the named supervisory authority if the deadline passes, and that you are keeping the correspondence.
Send it to the controller's privacy or data protection officer address, which is usually published in the privacy policy under a heading like "how to contact us" or "your rights". Keep everything in writing and keep the timestamps. A record of a missed regulatory deadline is far more useful than a record of a frustrating phone call.
Refusing disproportionate verification
Companies are entitled to verify that you are who you say you are, especially before deleting data or disclosing sensitive categories. They are not entitled to a full identity document to answer a marketing objection. If verification feels disproportionate, ask what specific data point they are trying to match and offer the minimum that answers it. When you do send a document, redact everything that is not the identifier they asked for - a common mistake is sending an unredacted scan that adds a new copy of your ID to their systems.
When a Company Can Lawfully Refuse
Refusals are common and not always wrong. The grounds worth recognising:
- Legal retention duties. Tax, accounting, financial and employment records must be kept for set periods, and deletion requests cannot override them.
- Legitimate interest or legal claims. Data may be kept to defend or bring a legal claim, or to prevent fraud.
- Freedom of expression and journalism. Relevant to some access requests against publishers.
- Manifestly unfounded or excessive requests. Repeated requests, or an obvious attempt to burden the organisation. A fee or a refusal is then permitted - and this is the one place where a careless, duplicated request strategy actively hurts you.
- Someone else's rights. A record may contain another person's data, which can be redacted rather than disclosed.
How to escalate
- Ask for the specific basis in writing. A refusal that cites no article is often a first-line response rather than a considered legal position.
- Narrow the request. A broad access request is easy to refuse as excessive; a precise one is not.
- Complain to the supervisory authority named in your jurisdiction - the ICO in the UK, the relevant member-state authority in the EU, the attorney general or the state privacy agency in California, and the ministry or supervisory body designated under Indonesian law. Complaints are free.
- Keep the file. Complaint forms ask for dates and evidence, and a tidy correspondence trail is what makes them quick to decide.
Data Brokers, People-Search Sites and Search Results
The companies most people have never heard of hold the most about them. Data brokers assemble profiles from public records, loyalty schemes, warranty registrations, app data and purchased datasets, then sell access to employers, insurers, marketers and investigators. People-search sites publish a subset to the open web: your name, approximate age, former addresses, relatives and phone numbers.
Several jurisdictions now run a central route rather than requiring one request per company. California's DROP platform is the clearest example. Where you have to go directly:
- Find the major brokers operating in your country. Regulators have published lists, and the largest ones maintain their own opt-out pages.
- Use the opt-out and deletion routes they publish, and do not accept a "suppression" that only hides the record from public search while leaving the underlying profile intact. Ask explicitly for deletion.
- Expect to repeat the exercise. Profiles get rebuilt from new public records and fresh data purchases. A quarterly pass on the worst offenders is more effective than one heroic effort.
- Separately, protect against the residual. Lock down your credit file or your country's equivalent, because a broker profile is the raw material for impersonation rather than the harm itself.
De-indexing search results
Removing a page from a search index is a different action from deleting it at source. A de-indexing request removes it from results; the page itself remains, and another search engine may still show it. Where a result is genuinely harmful - personal information exposed, or material that is outdated and no longer in the public interest - the search engine's own removal process and, in some jurisdictions, the right to erasure are the routes. Document the specific URLs and the harm; general complaints about a name are rarely actioned.
What to Expect, and Where to Spend the Effort
A first access response is usually a dense, badly labelled bulk export rather than a report, and asking what particular fields mean is a normal follow-up rather than a sign you did something wrong. Deletion clears live systems while backups are overwritten on their own cycle - ask what that schedule is instead of assuming instant erasure. Opting out of sale stops the onward flow, not the company's own collection, and no right overrides a genuine legal duty to keep records.
Budget about an hour per organisation, plus a reminder, and prioritise rather than trying to be thorough:
- Accounts holding health, financial, employment or precise location data.
- Brokers republishing your address, phone number and family relationships.
- Anyone generating marketing you never asked for, where an unconditional objection to direct marketing is the fastest available win.
Five companies that matter beat fifty that do not. And to work out who is likely to hold data about you in the first place, start with how online tracking works, which describes the routes by which your data leaves your device.
Questions readers ask about this page
How long does a company have to answer my data request?
Under the GDPR it is one month from receipt, extendable by two months for complex requests with an explanation. In California the business must acknowledge within 10 business days and respond within 45 calendar days, with one possible 45-day extension. Opt-outs of sale or sharing must be honoured within 15 business days. Always state the deadline in the request and note the date you sent it.
Do I have to pay for a data access request?
No, in the ordinary case it is free. A fee is only permitted where a request is manifestly unfounded or excessive - repeated requests, or an obvious attempt to burden the organisation. This is why a focused, well-documented request is stronger than a scattershot one, and why duplicating the same request weakens your position.
Can a company refuse to delete my data?
Yes, in defined circumstances: legal retention duties in tax, accounting or employment law; data needed to establish or defend legal claims; fraud prevention; freedom of expression; or because the record contains someone else's data. A refusal should cite the specific provision, and a refusal that cites nothing is often a first-line response rather than a considered position.
What is the Global Privacy Control?
It is a signal a browser or extension sends with every request saying you do not want your personal information sold or shared. California treats it as a valid opt-out, so it can replace hundreds of individual banner clicks. Limits: it applies per browser and per device, it does not follow your logged-in account, and companies outside the law's scope simply ignore it.
I am in Indonesia. Which law applies to me?
Law No. 27 of 2022 on Personal Data Protection is the main instrument, and it grants rights to information, access, correction, erasure, withdrawal of consent, objection, restriction and portability, with deadlines attached to requests. Implementing regulation followed the statute and practice is still settling, so confirm current procedure with the responsible ministry or the sectoral regulator before relying on a specific step. Where the company is foreign, its own local law may give you a second, more practical route.
Sources checked for this page
- EUR-Lex - Regulation (EU) 2016/679 (General Data Protection Regulation)
- UK Information Commissioner's Office - your data matters and how to complain
- California Attorney General - California Consumer Privacy Act
- California Privacy Protection Agency - Delete Request and Opt-out Platform (DROP)
- Indonesia - Law No. 27 of 2022 on Personal Data Protection (official text)
- European Data Protection Board - guidance and national authority contacts
- US Federal Trade Commission - privacy and security guidance
About RAJA89
RAJA89 is an independent educational project written by one person. It is not a company, an agency or a managed editorial team, and it does not pretend to be one. Edi Rahmadani writes these pages, checks them against the primary sources cited on each one, and answers corrections sent to the address on the support page.
RAJA89 is the name the site publishes under; the name above is the person accountable for what it says. Nothing here is generated and published unread: a claim either traces to a source you can open yourself, or it is marked as the author's own judgement.
How this site is funded
It is not. There is no advertising, no sponsorship, no affiliate link, no paid placement and no product for sale anywhere on this site. No company pays to be mentioned, and no page carries a commission-bearing link. Hosting is paid for out of the author's own pocket, which is the whole of the commercial relationship. If that ever changes, the change will be disclosed on this page before it appears anywhere else.
How to read this site
- Primary sources only. Where a claim can be checked, it links to the standards body, regulator or vendor documentation that supports it — not to another summary of it.
- Limits are stated. Where a control fails, or a setting only partly helps, the page says so in the same breath as the advice.
- Country-specific answers are labelled. Reporting routes, consumer protections and privacy law differ by country, so a passage that applies in only one is marked as such.
- No fear as a sales tool. Scaring a reader into a purchase is the behaviour this site exists to argue against.
Editorial standards we hold ourselves to
- We do not quote a statistic without naming the report and its year.
- We do not name a step-by-step settings path unless the vendor's own documentation still shows it.
- We do not present a product as the answer. Where a category of tool helps, we describe the category and what to look for in it.
- We do not write in the voice of expertise we do not have. When a question needs a lawyer, a doctor or a regulator, the page says so and stops.
- We do not silently rewrite a substantive claim. Material corrections are recorded with a dated note on the page, as described on the support page.
Dates, and what they mean
The date below is the last time these pages were re-checked against the sources they cite. It is a record of what happened, not a schedule: no page here states a calendar interval for review, because a static site cannot enforce one. Pages are re-checked when something they describe actually changes — a vendor renames a setting, a standard is revised, a regulation is amended, a link breaks — and at least once a year regardless, so that nothing is left unexamined through neglect.
The date moves only when a person has re-opened the cited sources and confirmed the text still matches them. It is not the date a file was last saved. Where a passage has been left standing but is no longer certain, it is marked as uncertain rather than quietly carried forward.
If the date below looks old, that is information, not a fault. It means the pages are due for their next pass. Everything on them links its primary source precisely so you can check the current position yourself rather than relying on our copy of it.
Who is accountable for this page
| Published by | RAJA89, an independent educational project written and paid for by Edi Rahmadani |
|---|---|
| Written by | Edi Rahmadani — an independent writer, publishing under the RAJA89 name. No employer, qualification or years of experience is claimed here, because this site asserts only what can be checked. |
| Reviewed by | Edi Rahmadani. This site has no separate reviewer, and we do not name one to look better. Every page is self-reviewed against the sources it cites, and that is exactly what the review record below means. |
| Corrections | Send a correction — specific reports are checked against a primary source and fixed or answered |
| First published | 2026-10-08 |
| Last reviewed | 2026-10-08 — every page on this site carries the same review date, and each one links the sources it was checked against |
Contact
Corrections, factual disputes, reports of a link that now leads somewhere harmful, and notices that a described setting has moved are all welcome at the address below. Edi Rahmadani reads them.
We will never ask you for a password, a one-time code, a recovery code or remote access to your device, and we will never ask you to confirm account details by replying to a message. Any message claiming to come from this site and asking for any of that is not from us.
Scope and limitations
Read this before acting on anything here.
- This is general education, not advice for your situation. It explains how data collection and privacy controls generally work, and which rights a reader may have. It is not legal advice and reading it creates no professional relationship. It is not an assessment of your situation: we do not know your accounts, devices, employer policies or past breaches. And it is not anonymity — reducing a footprint lowers how much is collected and how easily it is linked to you, and it cannot erase what has already been gathered or sold.
- We cannot see your accounts or your devices. We cannot tell you whether a particular message you received is genuine, whether an account has been compromised, or what an organisation holds about you.
- We cannot act on your behalf. We cannot contact a platform, bank, regulator or data protection authority for you, and we cannot investigate anyone. Requests like that have to go to the provider directly.
- Menus move. Settings are renamed, moved and reset by updates. A click path that was accurate on the review date may look different in your version. Treat every step here as a description of what to look for rather than a guarantee of what you will see.
- We can be wrong. Errors get through. If you find one, the support page explains what happens next.
