Skip to content
Topic Contested in court

Right to Rectification

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Right to have inaccurate personal data corrected

45 linked items 6 Laws10 Case Law20 Guidance9 News

Overview

13 sources · Jul 23, 2026

Legal Framework

Article 16 GDPR establishes the right to rectification, granting data subjects the ability to obtain from the controller, without undue delay, the correction of inaccurate personal data concerning them. The provision extends beyond mere correction: data subjects may also demand completion of incomplete personal data, including through supplementary statements, provided this aligns with the purposes of the processing. The dual structure—rectification of inaccuracy and completion of incompleteness—reflects a broader principle of data quality enshrined in Article 5(1)(d) GDPR, which requires that personal data be accurate and kept up to date.

Article 19 GDPR imposes a corresponding obligation on controllers: once rectification is carried out, the controller must notify every recipient to whom the personal data were disclosed, unless this proves impossible or involves disproportionate effort. Upon request, the controller must also inform the data subject about those recipients. This notification duty ensures that rectification has practical effect across the data ecosystem rather than remaining confined to the controller's own records.

Key Developments

The Court of Justice of the European Union has clarified the relationship between the right of access and rectification in Minister voor Immigratie v. M (Case C-393/12, 17 July 2014). The Court held that the right of access functions as a prerequisite for exercising rectification, erasure, or blocking of personal data. Access need not take the form of a full copy of records; a comprehensive summary in an intelligible form suffices, provided it enables the data subject to verify accuracy and assess compliance. This establishes a practical threshold: controllers cannot demand that data subjects pinpoint specific inaccuracies before providing access, as meaningful rectification depends on prior visibility of the data held.

In Bara and Others (Case C-201/14, 1 October 2015), the CJEU addressed the interplay between information obligations and data subject rights in the context of data transfers to third parties. While the case primarily concerned Articles 10 and 11 of Directive 95/46, its reasoning underscores that controllers cannot rely on generic legal provisions as substitutes for specific prior information about data recipients. This has direct implications for Article 19's notification requirement: controllers must maintain sufficient records of recipients to fulfill their downstream notification obligations after rectification.

The Dutch implementation designates the Autoriteit Persoonsgegevens as the sole supervisory authority responsible for GDPR enforcement, as permitted under Article 51 GDPR. This centralized enforcement model means that rectification complaints in the Netherlands flow through a single regulator.

Practical Guidance

  • Establish a rectification workflow triggered by both direct requests and internal discovery of inaccuracies. Article 16 requires action "without undue delay"—implement internal service levels that ensure prompt verification and correction, not merely acknowledgment of the request.

  • Maintain a recipient log for all personal data disclosures. Article 19's notification obligation is only dischargeable if the controller can identify recipients. Where data has been shared with multiple processors or third parties, ensure your records are granular enough to support targeted notifications.

  • Do not gate rectification requests on prior formal access requests. Under Minister v. M, access and rectification are linked rights. If a data subject identifies an inaccuracy through any channel, treat the communication as a rectification request rather than redirecting them to a separate access procedure.

  • Define "inaccurate" and "incomplete" with reference to processing purposes. Article 16's completion right is conditioned on the purposes of processing. Document your assessment of whether supplementary statements are necessary and proportionate to those purposes before accepting or rejecting completion requests.

  • Assess disproportionality before skipping recipient notifications. Article 19 allows an exception where notification is impossible or involves disproportionate effort, but this must be documented on a case-by-case basis rather than applied as a blanket policy.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 6
Art. 13(2)(b) the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concern… GDPR Art. 14(2)(c) the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concern… GDPR Art. 15(1)(e) the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data conc… GDPR Art. 58(2)(g) to order the rectification or erasure of personal data or restriction of processing pursuant to Articles 16, 17 and 18 and the notification of such ac… GDPR art 16 Right to rectification GDPR Apr 2016 art 19 Notification obligation regarding rectification or erasure of personal data or restriction of processing GDPR Apr 2016 rec 65 Recital 65 — data subject rectification and erasure rights GDPR Apr 2016 rec 73 Recital 73 — lawful restrictions on data subject rights GDPR Apr 2016 rec 156 Recital 156 — safeguards for archiving research processing GDPR Apr 2016 rec 59 Recital 59 — modalities for data subject rights exercise GDPR Apr 2016
Case Law 10
CJEU Data Protection Commissioner v. Schrems and Facebook CJEU Oct 2015 CJEU MINISTER VOOR IMMIGRATIE V. M, 17.7.2014 (“Minister v. M”) CJEU Jul 2014 CJEU GOOGLE SPAIN SL V. AEPD (THE DPA) & MARIO COSTEJA GONZALEZ, 13.May.2014 (“GOOGLE v. Spain”) CJEU May 2014 Supreme Court Supreme Court upholds €300,000 fine against INPS for GDPR violations in COVID bonus data Supreme Court May 2026 CJEU Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems CJEU Jul 2020 CJEU Data Protection Commissioner v. Schrems and Facebook CJEU Oct 2015 CJEU COLLEGE VAN BURGEMEESTER EN WETHOUDERS VAN ROTTERDAM V. RIJKEBOER, 7.5.2009 (“RIJKEBOER”) CJEU May 2009 CJEU SMARANDA BARA ET AL. V. PRESEDINTELE CASEI NATIONALE DE ASIGURARI DE SANATATE (CNAS) ET AL., 1.10.2015 (“BARA”) CJEU Oct 2015 Federal Administrative Court BVwG - W291 2298748-1 Federal Administrative Court Oct 2025 CJEU X, 12.12.2013 (“X”) CJEU Dec 2013
Guidance 20
guidelines on data subject rights right of access Guidelines 01/2022 on data subject rights - Right of access EDPB Apr 2023 guidelines on the calculation of administrative fines under the gdpr Guidelines 04/2022 on the calculation of administrative fines under the GDPR EDPB May 2023 guidelines on the application of article 651a gdpr Guidelines 03/2021 on the application of Article 65(1)(a) GDPR EDPB May 2023 guidelines for identifying a controller or processors lead supervisory authority Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority EDPB Apr 2023 guidelines on certification as a tool for transfers Guidelines 07/2022 on certification as a tool for transfers EDPB Feb 2023 guidelines on the practical implementation of amicable settlements Guidelines 06/2022 on the practical implementation of amicable settlements EDPB May 2022 guidelines on codes of conduct as tools for transfers Guidelines 04/2021 on Codes of Conduct as tools for transfers EDPB Feb 2022 guidelines on examples regarding personal data breach notification Guidelines 01/2021 EDPB Jan 2022 guidelines on restrictions under article 23 gdpr Guidelines 10/2020 on restrictions under Article 23 GDPR EDPB Oct 2021 guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 guidelines on relevant and reasoned objection under regulation 2016679 Guidelines 09/2020 on relevant and reasoned objection under Regulation 2016/679 EDPB Mar 2021 guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 guidelines on the criteria of the right to be forgotten in the search engines cases under th Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1) EDPB Jul 2020 guidelines on consent Guidelines 05/2020 on consent under Regulation 2016/679 EDPB May 2020 guidelines on certification and identifying certification criteria Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation EDPB Jun 2019 guidelines on deceptive design patterns in social media platform interfaces how to recognise Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them EDPB Feb 2023 guidelines on processing personal data in the context of connected vehicles and mobility rel Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications EDPB Jan 2020 guidelines on the use of facial recognition technology in the area of law enforcement Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement EDPB May 2023 guidelines on virtual voice assistants Guidelines 02/2021 on virtual voice assistants EDPB Jul 2021 guidelines on transparency Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01) EDPB Nov 2025
News 9
noyb - European Center for Digital Rights AI hallucinations: ChatGPT created a fake child murderer noyb - European Center for Digital Rights Mar 2025 NL EU Court Expert CJEU clarifies GDPR principles of purpose limitation and storage limitation NL EU Court Expert Oct 2022 Future of Privacy Forum What Happened to the Risk-Based Approach to Data Transfers? Future of Privacy Forum Sep 2022 AEPD AEPD publishes GDPR Risk Assessment AEPD Oct 2022 noyb - European Center for Digital Rights Wizz Air: €1 for a flight, €35 for your GDPR right noyb - European Center for Digital Rights Oct 2020 noyb - European Center for Digital Rights Open Letter: Commissioner Reynders asked to correct unacceptable accusations against NGOs noyb - European Center for Digital Rights Jul 2023 Kromann Reumert DeFine is a calculator for GDPR fines based on method of the EDPB Kromann Reumert Feb 2022 Brooklyn Law School Digital Privacy Rights and CLOUD Act Agreements between US and UK Brooklyn Law School Sep 2022 The Markup Who Is Collecting Data from Your Car?Who Is Collecting Data from Your Car? The Markup Jul 2022