RAJA89 home RAJA89 official siteOfficial site (opens in a new tab)
Guide 4 of 4 - Legal rights

Exercising Your Data Rights: A RAJA89 Guide

Settings control what is collected from now on. They cannot reach data that has already been uploaded, shared or sold. For that, the law is the instrument, and it gives you a small number of named rights that a company has to answer on a clock.

This guide covers access, correction, deletion, objection and portability under the GDPR, the CCPA and Indonesia's Law 27 of 2022, how to write a request that cannot be stalled, when a refusal is lawful, and where to escalate.

Last reviewed 8 October 2026Free to read, no sign-upPart of the RAJA89 guides

Visit the official RAJA89 website (opens in a new tab)Opens the official RAJA89 website in a new tab.

The Rights You Can Actually Use

Data protection law is not abstract. It gives you a small number of named rights that a company holding your data has to answer, on a clock, in writing. The details differ by country, but the shape is remarkably consistent wherever modern privacy law applies.

Two practical facts decide whether any of this works. First, a request has to go to the right recipient - the controller, meaning the organisation that decides why and how your data is processed, not a support queue that will close the ticket. Second, it has to name the right and identify you well enough to be actionable, without handing over more than necessary.

EU and UK Rights Under the GDPR

Under the General Data Protection Regulation, as retained in UK law, the core rights are set out in Articles 15 to 22.

The clock is one month from receipt, extendable by two further months for complex requests, and the extension must be explained with reasons. The response is free, and refusal or delay opens the door to a complaint with the national supervisory authority - the Information Commissioner's Office in the UK, and the equivalent body in each EU member state - and to a judicial remedy.

A point that matters in practice: the regulator is a backstop rather than a helpdesk. Its leverage is the threat of investigation, so a complaint is most effective when the company's failure is clear and documented.

California: Know, Delete, Correct, Opt Out

The California Consumer Privacy Act, as amended by the CPRA, gives residents a related but differently shaped set of rights.

The clocks differ from Europe and are worth diarising: the business must acknowledge receipt within 10 business days, respond substantively within 45 calendar days, and may extend once by a further 45 days with notice. Opt-out requests must be honoured within 15 business days. A right-to-know response reaches back twelve months, and for data collected since 1 January 2022 you can request the full history unless doing so would be disproportionately effortful.

Two mechanisms make this tractable rather than a full-time hobby.

California also runs a central platform, DROP, that lets residents send deletion and opt-out requests to participating businesses from one place. It is worth checking whether the companies you care about participate before writing each of them individually.

Indonesia: Law 27 of 2022

For readers in Indonesia, the governing instrument is Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi (Law No. 27 of 2022 on Personal Data Protection), which replaced a patchwork of sectoral rules with a single framework.

It recognises a comparable set of data subject rights: to obtain information about the processing and the identity of the parties involved, to access and obtain a copy of one's personal data, to request correction or erasure, to withdraw consent, to object to automated decision-making, to restrict processing, to port data to another controller, and to bring a claim for compensation.

Two operational points matter for a reader trying to use it:

Where a controller is outside Indonesia, jurisdiction can be awkward and the practical leverage is often the foreign law that also applies to it - which is an argument for sending the request under every regime that covers the company, not just the one closest to you.

Writing a Request That Cannot Be Stalled

Most requests fail for procedural reasons rather than legal ones. A useful template has six parts.

  1. Identify yourself with the identifiers the company can match - the account email address, and any account or customer number. Do not attach a passport scan in the first message.
  2. Name the right and the instrument. "Under Article 15 GDPR, I request access to my personal data" or "Under the CCPA, I request to know the categories and specific pieces of personal information you have collected about me". Naming the article moves the message from a support conversation to a legal request.
  3. State the scope precisely: the period, the account, the categories of processing, and whether you want the recipients and retention periods as well as the content.
  4. Specify the response format - a machine-readable export where portability applies.
  5. State the deadline and the date you are counting from.
  6. State what happens next: that you will complain to the named supervisory authority if the deadline passes, and that you are keeping the correspondence.

Send it to the controller's privacy or data protection officer address, which is usually published in the privacy policy under a heading like "how to contact us" or "your rights". Keep everything in writing and keep the timestamps. A record of a missed regulatory deadline is far more useful than a record of a frustrating phone call.

Refusing disproportionate verification

Companies are entitled to verify that you are who you say you are, especially before deleting data or disclosing sensitive categories. They are not entitled to a full identity document to answer a marketing objection. If verification feels disproportionate, ask what specific data point they are trying to match and offer the minimum that answers it. When you do send a document, redact everything that is not the identifier they asked for - a common mistake is sending an unredacted scan that adds a new copy of your ID to their systems.

When a Company Can Lawfully Refuse

Refusals are common and not always wrong. The grounds worth recognising:

How to escalate

  1. Ask for the specific basis in writing. A refusal that cites no article is often a first-line response rather than a considered legal position.
  2. Narrow the request. A broad access request is easy to refuse as excessive; a precise one is not.
  3. Complain to the supervisory authority named in your jurisdiction - the ICO in the UK, the relevant member-state authority in the EU, the attorney general or the state privacy agency in California, and the ministry or supervisory body designated under Indonesian law. Complaints are free.
  4. Keep the file. Complaint forms ask for dates and evidence, and a tidy correspondence trail is what makes them quick to decide.

Data Brokers, People-Search Sites and Search Results

The companies most people have never heard of hold the most about them. Data brokers assemble profiles from public records, loyalty schemes, warranty registrations, app data and purchased datasets, then sell access to employers, insurers, marketers and investigators. People-search sites publish a subset to the open web: your name, approximate age, former addresses, relatives and phone numbers.

Several jurisdictions now run a central route rather than requiring one request per company. California's DROP platform is the clearest example. Where you have to go directly:

  1. Find the major brokers operating in your country. Regulators have published lists, and the largest ones maintain their own opt-out pages.
  2. Use the opt-out and deletion routes they publish, and do not accept a "suppression" that only hides the record from public search while leaving the underlying profile intact. Ask explicitly for deletion.
  3. Expect to repeat the exercise. Profiles get rebuilt from new public records and fresh data purchases. A quarterly pass on the worst offenders is more effective than one heroic effort.
  4. Separately, protect against the residual. Lock down your credit file or your country's equivalent, because a broker profile is the raw material for impersonation rather than the harm itself.

De-indexing search results

Removing a page from a search index is a different action from deleting it at source. A de-indexing request removes it from results; the page itself remains, and another search engine may still show it. Where a result is genuinely harmful - personal information exposed, or material that is outdated and no longer in the public interest - the search engine's own removal process and, in some jurisdictions, the right to erasure are the routes. Document the specific URLs and the harm; general complaints about a name are rarely actioned.

What to Expect, and Where to Spend the Effort

A first access response is usually a dense, badly labelled bulk export rather than a report, and asking what particular fields mean is a normal follow-up rather than a sign you did something wrong. Deletion clears live systems while backups are overwritten on their own cycle - ask what that schedule is instead of assuming instant erasure. Opting out of sale stops the onward flow, not the company's own collection, and no right overrides a genuine legal duty to keep records.

Budget about an hour per organisation, plus a reminder, and prioritise rather than trying to be thorough:

Five companies that matter beat fifty that do not. And to work out who is likely to hold data about you in the first place, start with how online tracking works, which describes the routes by which your data leaves your device.

Questions readers ask about this page

How long does a company have to answer my data request?

Under the GDPR it is one month from receipt, extendable by two months for complex requests with an explanation. In California the business must acknowledge within 10 business days and respond within 45 calendar days, with one possible 45-day extension. Opt-outs of sale or sharing must be honoured within 15 business days. Always state the deadline in the request and note the date you sent it.

Do I have to pay for a data access request?

No, in the ordinary case it is free. A fee is only permitted where a request is manifestly unfounded or excessive - repeated requests, or an obvious attempt to burden the organisation. This is why a focused, well-documented request is stronger than a scattershot one, and why duplicating the same request weakens your position.

Can a company refuse to delete my data?

Yes, in defined circumstances: legal retention duties in tax, accounting or employment law; data needed to establish or defend legal claims; fraud prevention; freedom of expression; or because the record contains someone else's data. A refusal should cite the specific provision, and a refusal that cites nothing is often a first-line response rather than a considered position.

What is the Global Privacy Control?

It is a signal a browser or extension sends with every request saying you do not want your personal information sold or shared. California treats it as a valid opt-out, so it can replace hundreds of individual banner clicks. Limits: it applies per browser and per device, it does not follow your logged-in account, and companies outside the law's scope simply ignore it.

I am in Indonesia. Which law applies to me?

Law No. 27 of 2022 on Personal Data Protection is the main instrument, and it grants rights to information, access, correction, erasure, withdrawal of consent, objection, restriction and portability, with deadlines attached to requests. Implementing regulation followed the statute and practice is still settling, so confirm current procedure with the responsible ministry or the sectoral regulator before relying on a specific step. Where the company is foreign, its own local law may give you a second, more practical route.

Back to top ↑

Sources checked for this page

About RAJA89

RAJA89 is an independent educational project written by one person. It is not a company, an agency or a managed editorial team, and it does not pretend to be one. Edi Rahmadani writes these pages, checks them against the primary sources cited on each one, and answers corrections sent to the address on the support page.

RAJA89 is the name the site publishes under; the name above is the person accountable for what it says. Nothing here is generated and published unread: a claim either traces to a source you can open yourself, or it is marked as the author's own judgement.

How this site is funded

It is not. There is no advertising, no sponsorship, no affiliate link, no paid placement and no product for sale anywhere on this site. No company pays to be mentioned, and no page carries a commission-bearing link. Hosting is paid for out of the author's own pocket, which is the whole of the commercial relationship. If that ever changes, the change will be disclosed on this page before it appears anywhere else.

How to read this site

Editorial standards we hold ourselves to

Dates, and what they mean

The date below is the last time these pages were re-checked against the sources they cite. It is a record of what happened, not a schedule: no page here states a calendar interval for review, because a static site cannot enforce one. Pages are re-checked when something they describe actually changes — a vendor renames a setting, a standard is revised, a regulation is amended, a link breaks — and at least once a year regardless, so that nothing is left unexamined through neglect.

The date moves only when a person has re-opened the cited sources and confirmed the text still matches them. It is not the date a file was last saved. Where a passage has been left standing but is no longer certain, it is marked as uncertain rather than quietly carried forward.

If the date below looks old, that is information, not a fault. It means the pages are due for their next pass. Everything on them links its primary source precisely so you can check the current position yourself rather than relying on our copy of it.

Who is accountable for this page

Published byRAJA89, an independent educational project written and paid for by Edi Rahmadani
Written byEdi Rahmadani — an independent writer, publishing under the RAJA89 name. No employer, qualification or years of experience is claimed here, because this site asserts only what can be checked.
Reviewed byEdi Rahmadani. This site has no separate reviewer, and we do not name one to look better. Every page is self-reviewed against the sources it cites, and that is exactly what the review record below means.
CorrectionsSend a correction — specific reports are checked against a primary source and fixed or answered
First published2026-10-08
Last reviewed2026-10-08 — every page on this site carries the same review date, and each one links the sources it was checked against

Contact

Corrections, factual disputes, reports of a link that now leads somewhere harmful, and notices that a described setting has moved are all welcome at the address below. Edi Rahmadani reads them.

raja89officials@gmail.com

One person, checking messages between other work. Reports that name the passage and the source they disagree with are answered fastest — the support page sets out exactly what to include, and what we cannot help with.

We will never ask you for a password, a one-time code, a recovery code or remote access to your device, and we will never ask you to confirm account details by replying to a message. Any message claiming to come from this site and asking for any of that is not from us.

Scope and limitations

Read this before acting on anything here.

Back to top ↑