Right to Rectification: The GDPR Right to Correct Inaccurate Data
Last updated July 2026 · Obtainer
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
The right to rectification, in Article 16 of the GDPR, lets a person require you to correct inaccurate personal data about them and complete data that is incomplete. You have one month to respond, extendable by two further months for complex requests. If you have shared the data with anyone else, Article 19 usually requires you to tell them about the correction too. California grants a parallel right to correct under the CCPA as amended by the CPRA, now matched by nineteen of the twenty US state privacy laws, on a 45-day clock.
General information, not legal advice. Accuracy disputes are fact-specific, so take advice on the ones that are close.
What the right to rectification actually requires
Article 16 has two halves, and teams usually implement only the first. The first half is correction: a person can require you to fix personal data about them that is inaccurate, without undue delay. The second half is completion: a person can have incomplete data completed, including by providing a supplementary statement. That second half is the one that surprises people, because it means the fix is not always a database update. Sometimes the remedy is a note attached to the record.
"Inaccurate" is not defined in the GDPR itself, but the UK Data Protection Act offers the working definition regulators use in practice: data is inaccurate if it is incorrect or misleading as to any matter of fact. The distinction between fact and opinion carries most of the weight here. A wrongly recorded date of birth is a fact, and it is either right or wrong. A note from a support agent saying "customer was abusive on the call" is an opinion, and an opinion is not inaccurate merely because the person disagrees with it.
That does not mean opinions are untouchable. An opinion recorded as though it were a fact can be misleading, and an opinion based on demonstrably wrong facts can be challenged on that basis. But the usual outcome for a contested opinion is not deletion or rewriting. It is a supplementary statement recording that the person disputes it, which is exactly what the completion half of Article 16 contemplates.
The one-month clock
You must act without undue delay and at the latest within one month of receiving the request. You can extend by two further months where the request is complex or you have received several, but only if you tell the person within the first month and explain why. The same clock as an access request, and the same trap: it starts when the request arrives, and any time you spend verifying the requester comes out of your month.
| GDPR right to rectification | CCPA right to correct | |
|---|---|---|
| Source | Article 16 | CCPA as amended by the CPRA |
| Who can ask | Data subjects in the EU and EEA | California consumers |
| Deadline | One month | 45 days |
| Extension | +2 months for complex requests, with notice | +45 days, with notice |
| Scope | Correct inaccurate data and complete incomplete data | Correct inaccurate personal information |
| Standard applied | Accuracy as a matter of fact | Commercially reasonable efforts, considering the nature of the data and its purpose |
| Downstream duty | Notify each recipient under Article 19, unless impossible or disproportionate | Direct service providers and contractors to correct |
The CCPA framing is worth noting because it is more forgiving on its face. California asks for commercially reasonable efforts to correct, taking into account the nature of the data and the purpose of processing it, and it lets a business consider the totality of circumstances and documentary evidence when deciding whether the data is actually inaccurate. The GDPR has no equivalent reasonableness dial in the text of Article 16.
Can you refuse a rectification request?
Yes, on defined grounds, and refusing is sometimes the right answer. You can decline where the data is not in fact inaccurate, and the burden of that judgment sits with you. You can also refuse a request that is manifestly unfounded or excessive, though that bar is high and regulators read it narrowly. What you cannot do is refuse silently.
If you decline, you must tell the person without delay and at the latest within one month, explain why, and inform them that they can complain to a supervisory authority and seek a judicial remedy. Under the CCPA you must tell the consumer you are not correcting the data and explain the basis. In both cases the refusal itself is a documented act, not an absence of one.
The practical test before refusing: can you state, in one sentence, the evidence on which you concluded the data is accurate? If the answer is "it is what the system says", that is not evidence, that is a circular argument. Where a person disputes something you cannot verify either way, restricting processing of the disputed field while you check it is the mechanism the GDPR provides, under Article 18, and it is a better answer than a refusal you cannot support.
Do you have to tell other companies about the correction?
Usually, yes, and this is the half of rectification that gets skipped. Article 19 requires you to communicate a rectification to each recipient to whom the personal data has been disclosed, unless that proves impossible or involves disproportionate effort. The person can also ask you to tell them who those recipients are.
This is where a correction request stops being a database update and becomes an operational problem. The wrong address you just fixed in the CRM was synced to the billing system last month, exported to a marketing platform, copied into a warehouse, and sent to a shipping partner. Correcting the source record does not correct any of those. In most companies nobody can list the downstream copies from memory, which is why knowing how a record flows downstream through your systems turns Article 19 from a guess into a checklist.
"Disproportionate effort" is a genuine escape valve, but it is narrower than convenience. It is meant for cases where the recipients are genuinely untraceable, not for cases where tracing them is tedious. Document why you concluded it was disproportionate, at the time you concluded it.
What is the difference between rectification and erasure?
Rectification fixes data that is wrong. Erasure removes data you should no longer hold. They answer different complaints, and people routinely ask for the wrong one. A person who says "this is not my address, delete my account" is usually making a rectification request wearing a deletion request's clothes, and a person who asks you to correct data you had no lawful basis to collect in the first place is really raising an erasure question.
Read the request for what it wants, not for the verb it uses. If it is ambiguous, ask. Clarifying a request is allowed and does not pause the clock, but acting on the wrong right wastes the month you had. The right to erasure guide covers the six grounds and five exceptions on the deletion side, and the data subject rights overview maps all eight GDPR rights against the six California ones so you can tell quickly which one you are dealing with.
How to run a rectification request
The sequence is short, and only one step is hard:
- Log it and start the clock. One month from arrival, whatever form it came in and whoever it was addressed to.
- Verify the requester. Correcting a record on an unverified request is its own risk, and it comes out of your month.
- Establish what is actually inaccurate. Separate fact from opinion. Ask for evidence where the dispute is factual. Do not skip to the fix.
- Find every copy. The source record, the systems it synced to, and the recipients you disclosed it to. This is the step that takes the time.
- Correct or complete. Update the field, or attach a supplementary statement where the dispute is about an opinion you are not going to change.
- Notify recipients under Article 19, and tell the person what you did, within the month.
Step four is the reason rectification is not the trivial right it looks like. You cannot correct what you cannot find, which is the same wall every other data subject right runs into. Personal data discovery surfaces where a person's data lives across your systems and compiles it into one reviewable manifest, so a correction reaches every copy rather than the one record someone happened to remember. A human reviews and approves before anything changes, so you stay in control of what gets altered.
Rectification is the quietest of the data subject rights and the one most likely to be handled by whoever happens to read the email. That is fine until the correction lands in one system and not the five it was copied to, and the person comes back a month later to point out that you are still wrong.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.