Privacy & Data Protection Rights: GDPR, CCPA, and Your Rights Explained
Privacy & Data Protection Rights
Your personal data is collected, processed, and monetized at a scale that would have seemed dystopian 20 years ago. Privacy law globally has moved to give individuals more control — but only if you know how to exercise it.
1. Your Rights Under Major Privacy Laws
GDPR (EU/EEA — applies globally to EU residents)
| Right | What It Means |
|---|---|
| Right of access | Get a copy of all data a company holds about you |
| Right to rectification | Correct inaccurate data |
| Right to erasure (“Right to be forgotten”) | Request deletion (with conditions) |
| Right to restriction | Pause processing while a dispute is resolved |
| Right to portability | Export your data in machine-readable format |
| Right to object | Opt out of processing for direct marketing |
| Rights re. automated decisions | Request human review of automated profiling |
CCPA / CPRA (California, USA)
| Right | What It Means |
|---|---|
| Know | What data is collected and why |
| Delete | Request deletion of your personal information |
| Opt-out | Stop sale/sharing of your data to third parties |
| Non-discrimination | Cannot be denied service for exercising rights |
| Correct | Fix inaccurate data (CPRA addition) |
Applies to: California residents. But many large US companies extend these rights nationally.
2. How to Exercise Your Rights
Subject Access Request (SAR) — EU/UK
- Write to the company’s Data Protection Officer (DPO) — usually contact@[company].com or privacy@[company].com
- Provide enough information to identify yourself
- They must respond within 30 days (UK/EU), free of charge
- They can extend by 2 months for complex requests but must notify you
Data Deletion Request
Under GDPR, the right to erasure applies when:
- Data is no longer necessary for the purpose it was collected
- You withdraw consent (if consent was the legal basis)
- You object and there’s no overriding legitimate interest
- The data was unlawfully processed
Exceptions to the right to erasure: Legal obligation to retain data, public interest, or freedom of expression may override your request. A company can refuse to delete data it’s legally required to keep (e.g., tax records, fraud prevention).
3. After a Data Breach: What to Do
If you learn your data was exposed in a breach:
Immediate steps:
- Change your password on the affected service immediately
- Change the same password on any other service where you used it
- Enable 2FA on all important accounts
- Monitor your bank for unusual transactions
- Check haveibeenpwned.com — enter your email to see if your data appears in known breaches
Legal remedies:
- Under GDPR: companies must notify you of a breach affecting your rights within 72 hours of discovery
- If you suffered damages, you can seek compensation in national courts or via your supervisory authority
- In the US: state laws vary; check your state’s breach notification law
Phishing follows breaches: After a major data breach, expect targeted phishing emails using your real name and personal details. Be extra skeptical of emails claiming to be from the affected company, your bank, or government agencies.
4. Global Privacy Law Comparison
| Law | Jurisdiction | Key Features |
|---|---|---|
| GDPR | EU/EEA | Strongest globally; extraterritorial reach; fines up to 4% global turnover |
| UK GDPR | United Kingdom | Post-Brexit, largely mirrors EU GDPR |
| CCPA/CPRA | California, USA | US’s strongest state law; sale opt-out right |
| PIPEDA | Canada | Federal law; consent-based |
| PDPA | Thailand | GDPR-influenced; covers Thai residents |
| LGPD | Brazil | GDPR-inspired; enforced by ANPD |
| PDPB | India | Pending full implementation |
| APPI | Japan | Covers personal data; opt-out for third party |
| POPIA | South Africa | GDPR-aligned; effective 2021 |
5. Children’s Privacy
Children’s data receives extra protection globally:
| Law | Age Threshold | Protection |
|---|---|---|
| GDPR | Under 16 | Parental consent required (states can lower to 13) |
| COPPA (US) | Under 13 | Verifiable parental consent for online services |
| UK GDPR / Age Appropriate Design Code | Under 18 | ”Best interests of the child” standard |
6. Enforcement Resources
| Country | Authority | Contact |
|---|---|---|
| EU (any member state) | National Data Protection Authority | gdprhub.eu/DPA |
| UK | Information Commissioner’s Office (ICO) | ico.org.uk |
| US (Federal) | FTC | ftc.gov/privacy |
| California | California Privacy Protection Agency | cppa.ca.gov |
| Australia | OAIC | oaic.gov.au |
Browser privacy tools: Use uBlock Origin (ad/tracker blocker), Privacy Badger, and Firefox’s Enhanced Tracking Protection. For email, use a unique alias per service (simplelogin.io, addy.io) so you know who sells your data.
OIYO Editorial
Editorial DeskThe OIYO editorial desk researches money, law, lifestyle, and self-understanding topics against primary sources and public statistics. Every piece carries source notes and is reviewed on a regular cycle for accuracy and usefulness.