Law & ExamMay 30, 20265 min read

Privacy & Data Protection Rights: GDPR, CCPA, and Your Rights Explained

O
OIYO EditorialContributor

Privacy & Data Protection Rights

Your personal data is collected, processed, and monetized at a scale that would have seemed dystopian 20 years ago. Privacy law globally has moved to give individuals more control — but only if you know how to exercise it.


1. Your Rights Under Major Privacy Laws

GDPR (EU/EEA — applies globally to EU residents)

RightWhat It Means
Right of accessGet a copy of all data a company holds about you
Right to rectificationCorrect inaccurate data
Right to erasure (“Right to be forgotten”)Request deletion (with conditions)
Right to restrictionPause processing while a dispute is resolved
Right to portabilityExport your data in machine-readable format
Right to objectOpt out of processing for direct marketing
Rights re. automated decisionsRequest human review of automated profiling

CCPA / CPRA (California, USA)

RightWhat It Means
KnowWhat data is collected and why
DeleteRequest deletion of your personal information
Opt-outStop sale/sharing of your data to third parties
Non-discriminationCannot be denied service for exercising rights
CorrectFix inaccurate data (CPRA addition)

Applies to: California residents. But many large US companies extend these rights nationally.


2. How to Exercise Your Rights

Subject Access Request (SAR) — EU/UK

  1. Write to the company’s Data Protection Officer (DPO) — usually contact@[company].com or privacy@[company].com
  2. Provide enough information to identify yourself
  3. They must respond within 30 days (UK/EU), free of charge
  4. They can extend by 2 months for complex requests but must notify you

Data Deletion Request

Under GDPR, the right to erasure applies when:

  • Data is no longer necessary for the purpose it was collected
  • You withdraw consent (if consent was the legal basis)
  • You object and there’s no overriding legitimate interest
  • The data was unlawfully processed

Exceptions to the right to erasure: Legal obligation to retain data, public interest, or freedom of expression may override your request. A company can refuse to delete data it’s legally required to keep (e.g., tax records, fraud prevention).


3. After a Data Breach: What to Do

If you learn your data was exposed in a breach:

Immediate steps:

  1. Change your password on the affected service immediately
  2. Change the same password on any other service where you used it
  3. Enable 2FA on all important accounts
  4. Monitor your bank for unusual transactions
  5. Check haveibeenpwned.com — enter your email to see if your data appears in known breaches

Legal remedies:

  • Under GDPR: companies must notify you of a breach affecting your rights within 72 hours of discovery
  • If you suffered damages, you can seek compensation in national courts or via your supervisory authority
  • In the US: state laws vary; check your state’s breach notification law

Phishing follows breaches: After a major data breach, expect targeted phishing emails using your real name and personal details. Be extra skeptical of emails claiming to be from the affected company, your bank, or government agencies.


4. Global Privacy Law Comparison

LawJurisdictionKey Features
GDPREU/EEAStrongest globally; extraterritorial reach; fines up to 4% global turnover
UK GDPRUnited KingdomPost-Brexit, largely mirrors EU GDPR
CCPA/CPRACalifornia, USAUS’s strongest state law; sale opt-out right
PIPEDACanadaFederal law; consent-based
PDPAThailandGDPR-influenced; covers Thai residents
LGPDBrazilGDPR-inspired; enforced by ANPD
PDPBIndiaPending full implementation
APPIJapanCovers personal data; opt-out for third party
POPIASouth AfricaGDPR-aligned; effective 2021

5. Children’s Privacy

Children’s data receives extra protection globally:

LawAge ThresholdProtection
GDPRUnder 16Parental consent required (states can lower to 13)
COPPA (US)Under 13Verifiable parental consent for online services
UK GDPR / Age Appropriate Design CodeUnder 18”Best interests of the child” standard

6. Enforcement Resources

CountryAuthorityContact
EU (any member state)National Data Protection Authoritygdprhub.eu/DPA
UKInformation Commissioner’s Office (ICO)ico.org.uk
US (Federal)FTCftc.gov/privacy
CaliforniaCalifornia Privacy Protection Agencycppa.ca.gov
AustraliaOAICoaic.gov.au

Browser privacy tools: Use uBlock Origin (ad/tracker blocker), Privacy Badger, and Firefox’s Enhanced Tracking Protection. For email, use a unique alias per service (simplelogin.io, addy.io) so you know who sells your data.

O

OIYO Editorial

Editorial Desk

The OIYO editorial desk researches money, law, lifestyle, and self-understanding topics against primary sources and public statistics. Every piece carries source notes and is reviewed on a regular cycle for accuracy and usefulness.