DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk5 min

How to Handle a User’s Data Access, Correction, and Erasure Request

Learn how to recognise and route a privacy-rights request, check identity proportionately, apply the right deadline, and handle access, correction and erasure as separate decisions.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When someone asks what personal data you hold, says it is wrong, or asks you to delete it, log the request, identify the law and deadline that apply, verify identity proportionately, and assess each requested right separately. Under UK GDPR guidance from the Information Commissioner’s Office (ICO), a request can be verbal or written and does not need to use legal terminology. The UK and California examples below are not universal rules: confirm the applicable jurisdiction, exemptions, and deadline calculations with your privacy lead or local counsel.

Start by recognising and logging the request

Do not wait for a person to submit a form, use a particular mailbox, or write “subject access request.” The ICO says a person need not use that phrase or cite Article 15 to make an access request. A request to correct or erase data likewise need not cite the relevant article under ICO guidance.

At intake, record when and where the request arrived, what the person appears to want, the account or relationship involved, and who owns the next action. If one message asks for access, correction, and deletion, log all three rights separately so one is not lost inside a general support ticket. Route it promptly to the team responsible for privacy requests.

Identify the applicable law and response clock

Before promising a response date, determine which law applies to your organisation, the person, the processing, and the request. The figures below are examples for UK GDPR and California CCPA requests, not interchangeable deadlines. Do not combine one jurisdiction’s start-date rules or extension conditions with another’s.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Issue UK GDPR example (ICO guidance) California CCPA example (CPPA materials)
Rights covered by these sources Access, rectification, and erasure Know/access, correction, and deletion
Ordinary response period Generally within one month Within 45 calendar days for covered requests
Possible extension Up to two further months for a qualifying complex request or multiple requests; give notice and reasons within the initial month Up to one additional 45-day period when necessary; give notice and an explanation
Receipt confirmation The cited ICO guidance does not establish a separate California-style confirmation deadline Confirm receipt of covered know, correct, and delete requests within 10 business days
Separate deletion mechanism Apply UK rules and exemptions to the particular organisation and request DROP is a separate data-broker mechanism. California data brokers must access it at least every 45 days starting August 1, 2026, subject to the statute and exceptions.

The ICO’s access guidance was updated December 8, 2025; its brief subject-access guide reflects the UK Data (Use and Access) Act 2025 and was updated July 16, 2026. The California CPPA FAQ was accessed October 5, 2026, and the CCPA text referenced there is effective January 1, 2026. Because these rules and dates can change, check the current regulator guidance before calculating a live deadline.

Verify identity and authority only as far as needed

First consider whether the person is already identifiable through a trusted account or an ongoing relationship. If there is genuine doubt, ask only for information reasonably necessary to verify identity. If someone is acting for another person, check their authority where needed before disclosing data or acting on the request.

The ICO advises organisations to be reasonable and proportionate: formal identity documents should be requested only when necessary. Do not make a full identity document a routine prerequisite when identity is already clear. Verification itself creates personal information, so keep any material collected secure and use it for the relevant check in line with applicable law.

Clarify scope without letting the request disappear

If a request is unusually broad or unclear, ask a focused question that helps identify the information the person means. Explain why the clarification is needed and keep a record of the contact. Do not assume that asking a question automatically pauses all work: the ICO notes that it may often be possible to provide some information while clarification is pending. Whether, and how, clarification affects a deadline depends on the governing law and circumstances.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Handle an access request as a search and disclosure decision

Access is about providing a copy of the person’s personal data together with required supplementary information; it is not simply a copy of one account screen or a dump of every record in the organisation. Make a reasonable and proportionate search of systems and records likely to contain the requested information, including relevant communications and repositories. A proportionate search is not a reason to skip likely locations.

For a UK GDPR access response, the ICO identifies supplementary information that can include the purposes of processing, categories of personal data, recipients, retention information, the source when data was not collected from the person, and relevant automated-decision information. Review records for other people’s information and applicable legal restrictions or exemptions before disclosure. Then deliver the response clearly, accessibly, and securely, and record the searches and disclosure decision.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Assess correction against accuracy and purpose

Pin down which information the person says is inaccurate or incomplete, and why it matters for the purpose for which it is processed. Consider evidence they provide and the reasonable steps already taken to assure accuracy. Where appropriate, correct inaccurate data or complete incomplete data. A correction request is not automatically a direction to replace a fact merely because the person disputes it; assess the information and context.

If you refuse all or part of the request, explain the reason and identify the applicable complaint or review route. Keep a record of the information considered, the decision, and any change made.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Assess erasure grounds, exceptions, and implementation

An erasure request does not mean data must always be deleted. Determine whether a recognised ground for erasure applies and whether an exception or continuing legal obligation allows or requires retention. The applicable grounds and exceptions depend on the law and facts; do not promise deletion before completing that assessment.

If erasure is granted, identify the relevant live systems and recipients or processors that need action. Distinguish operational deletion from limited backup or archival treatment and from retention required by law or another valid basis. Plan so that erased data does not simply reappear in normal use. If refusing all or part, tell the person what was decided, why, and what challenge rights apply.

Close the request with a clear outcome and audit trail

Send the outcome securely in plain language. State what you did, or why you refused action, and include any required complaint or regulator information. Keep a record of the dates, identity and authority checks, searches, any extension notice, decision, implementation evidence, and delivery. That record lets the organisation explain how it handled the request and whether its actions matched the decision.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.