# Right to Rectification — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/right-to-rectification
> Sources are cited per item. Verify against the official texts before relying on them.

Right to have inaccurate personal data corrected

## Overview

## Legal Framework

Article 16 GDPR establishes the right to rectification, granting data subjects the ability to obtain from the controller, without undue delay, the correction of inaccurate personal data concerning them. The provision extends beyond mere correction: data subjects may also demand completion of incomplete personal data, including through supplementary statements, provided this aligns with the purposes of the processing. The dual structure—rectification of inaccuracy and completion of incompleteness—reflects a broader principle of data quality enshrined in Article 5(1)(d) GDPR, which requires that personal data be accurate and kept up to date.

Article 19 GDPR imposes a corresponding obligation on controllers: once rectification is carried out, the controller must notify every recipient to whom the personal data were disclosed, unless this proves impossible or involves disproportionate effort. Upon request, the controller must also inform the data subject about those recipients. This notification duty ensures that rectification has practical effect across the data ecosystem rather than remaining confined to the controller's own records.

## Key Developments

The Court of Justice of the European Union has clarified the relationship between the right of access and rectification in *Minister voor Immigratie v. M* (Case C-393/12, 17 July 2014). The Court held that the right of access functions as a prerequisite for exercising rectification, erasure, or blocking of personal data. Access need not take the form of a full copy of records; a comprehensive summary in an intelligible form suffices, provided it enables the data subject to verify accuracy and assess compliance. This establishes a practical threshold: controllers cannot demand that data subjects pinpoint specific inaccuracies before providing access, as meaningful rectification depends on prior visibility of the data held.

In *Bara and Others* (Case C-201/14, 1 October 2015), the CJEU addressed the interplay between information obligations and data subject rights in the context of data transfers to third parties. While the case primarily concerned Articles 10 and 11 of Directive 95/46, its reasoning underscores that controllers cannot rely on generic legal provisions as substitutes for specific prior information about data recipients. This has direct implications for Article 19's notification requirement: controllers must maintain sufficient records of recipients to fulfill their downstream notification obligations after rectification.

The Dutch implementation designates the Autoriteit Persoonsgegevens as the sole supervisory authority responsible for GDPR enforcement, as permitted under Article 51 GDPR. This centralized enforcement model means that rectification complaints in the Netherlands flow through a single regulator.

## Practical Guidance

- **Establish a rectification workflow triggered by both direct requests and internal discovery of inaccuracies.** Article 16 requires action "without undue delay"—implement internal service levels that ensure prompt verification and correction, not merely acknowledgment of the request.

- **Maintain a recipient log for all personal data disclosures.** Article 19's notification obligation is only dischargeable if the controller can identify recipients. Where data has been shared with multiple processors or third parties, ensure your records are granular enough to support targeted notifications.

- **Do not gate rectification requests on prior formal access requests.** Under *Minister v. M*, access and rectification are linked rights. If a data subject identifies an inaccuracy through any channel, treat the communication as a rectification request rather than redirecting them to a separate access procedure.

- **Define "inaccurate" and "incomplete" with reference to processing purposes.** Article 16's completion right is conditioned on the purposes of processing. Document your assessment of whether supplementary statements are necessary and proportionate to those purposes before accepting or rejecting completion requests.

- **Assess disproportionality before skipping recipient notifications.** Article 19 allows an exception where notification is impossible or involves disproportionate effort, but this must be documented on a case-by-case basis rather than applied as a blanket policy.

## Legislation (full text of key provisions)

### Notification obligation regarding rectification or erasure of personal data or restriction of processing

*Source: GDPR, gdpr-art-19-en, 2016-04-27 — https://overview.legal/posts/90457*

The controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16, Article 17(1) and Article 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The controller shall inform the data subject about those recipients if the data subject requests it.

### Right to rectification

*Source: GDPR, gdpr-art-16-en, 2016-04-27 — https://overview.legal/posts/90424*

The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

### Recital 65 — data subject rectification and erasure rights

*Source: GDPR, gdpr-rec-65-en, 2016-04-27 — https://overview.legal/posts/91645*

A data subject should have the right to have personal data concerning him or her rectified and a ‘right to be forgotten’ where the retention of such data infringes this Regulation or Union or Member State law to which the controller is subject. In particular, a data subject should have the right to have his or her personal data erased and no longer processed where the personal data are no longer necessary in relation to the purposes for which they are collected or otherwise processed, where a data subject has withdrawn his or her consent or objects to the processing of personal data concerning him or her, or where the processing of his or her personal data does not otherwise comply with this Regulation. That right is relevant in particular where the data subject has given his or her consent as a child and is not fully aware of the risks involved by the processing, and later wants to remove such personal data, especially on the internet. The data subject should be able to exercise that right notwithstanding the fact that he or she is no longer a child. However, the further retention of the personal data should be lawful where it is necessary, for exercising the right of freedom of expression and information, for compliance with a legal obligation, for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, on the grounds of public interest in the area of public health, for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, or for the establishment, exercise or defence of legal claims.

### Recital 156 — safeguards for archiving research processing

*Source: GDPR, gdpr-rec-156-en, 2016-04-27 — https://overview.legal/posts/91827*

The processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes should be subject to appropriate safeguards for the rights and freedoms of the data subject pursuant to this Regulation. Those safeguards should ensure that technical and organisational measures are in place in order to ensure, in particular, the principle of data minimisation. The further processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes is to be carried out when the controller has assessed the feasibility to fulfil those purposes by processing data which do not permit or no longer permit the identification of data subjects, provided that appropriate safeguards exist (such as, for instance, pseudonymisation of the data). Member States should provide for appropriate safeguards for the processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. Member States should be authorised to provide, under specific conditions and subject to appropriate safeguards for data subjects, specifications and derogations with regard to the information requirements and rights to rectification, to erasure, to be forgotten, to restriction of processing, to data portability, and to object when processing personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. The conditions and safeguards in question may entail specific procedures for data subjects to exercise those rights if this is appropriate in the light of the purposes sought by the specific processing along with technical and organisational measures aimed at minimising the processing of personal data in pursuance of the proportionality and necessity principles. The processing of personal data for scientific purposes should also comply with other relevant legislation such as on clinical trials.

### Recital 73 — lawful restrictions on data subject rights

*Source: GDPR, gdpr-rec-73-en, 2016-04-27 — https://overview.legal/posts/91661*

Restrictions concerning specific principles and the rights of information, access to and rectification or erasure of personal data, the right to data portability, the right to object, decisions based on profiling, as well as the communication of a personal data breach to a data subject and certain related obligations of the controllers may be imposed by Union or Member State law, as far as necessary and proportionate in a democratic society to safeguard public security, including the protection of human life especially in response to natural or manmade disasters, the prevention, investigation and prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security, or of breaches of ethics for regulated professions, other important objectives of general public interest of the Union or of a Member State, in particular an important economic or financial interest of the Union or of a Member State, the keeping of public registers kept for reasons of general public interest, further processing of archived personal data to provide specific information related to the political behaviour under former totalitarian state regimes or the protection of the data subject or the rights and freedoms of others, including social protection, public health and humanitarian purposes. Those restrictions should be in accordance with the requirements set out in the Charter and in the European Convention for the Protection of Human Rights and Fundamental Freedoms.

### Recital 59 — modalities for data subject rights exercise

*Source: GDPR, gdpr-rec-59-en, 2016-04-27 — https://overview.legal/posts/91633*

Modalities should be provided for facilitating the exercise of the data subject's rights under this Regulation, including mechanisms to request and, if applicable, obtain, free of charge, in particular, access to and rectification or erasure of personal data and the exercise of the right to object. The controller should also provide means for requests to be made electronically, especially where personal data are processed by electronic means. The controller should be obliged to respond to requests from the data subject without undue delay and at the latest within one month and to give reasons where the controller does not intend to comply with any such requests.

## Case law

### BVwG - W291 2298748-1

*Source: Federal Administrative Court, 2025-10-31 — https://overview.legal/posts/49235 — original: https://gdprhub.eu/index.php?title=BVwG_-_W291_2298748-1*

Facts — A data subject wished to be addressed in a gender-neutral way and claimed they were misgendered by two companies (the controllers) in profile settings, tickets, and train announcements. They initially sent a tweet to one of the involved controllers asking whether gender-neutral options would be available and later filed a complaint with the Equal Treatment Commission and the Austrian Data Protection Authority (DSB), claiming a violation of their right under Article 16 GDPR. The DPA rejected the complaint, arguing that the data subject had not submitted a formal request for rectification to the controllers. The complainant then appealed to the Federal Administrative Court. Holding — The Court dismissed the appeal, holding that there was no violation of the GDPR because the data subject had not submitted a formal request for rectification. Article 16 GDPR requires a clear and specific request for correction, and vague or indirect statements, such as tweets or general demands for a change of the controller’s practice, do not satisfy this requirement. During the proceedings, it became clear that the data subject’s statements, primarily concerned the implementation of a future change of the controller’s practice to allow a gender-neutral option for all users, rather than a concrete request to correct their own personal data. In addition, some corrections had already been made to the data subject’s profile and invoices, while oral misgendering in trains and via loudspeaker announcements was found to fall outside the scope of the GDPR, as such statements were not stored in any personal data filing system. Finally, the Court noted that the minutes of the Equal Treatment Commission hearing could not be relied upon as full proof, as the hearing had been recorded only in audio form and not documented in accordance with the requirements of Austrian administrative procedure law (AVG). Statements made during the Equal Treatment Commission proceedings therefore did not constitute a formal exercise of the right to rectification under Article 16 GDPR.

### Data Protection Commissioner v. Schrems and Facebook

*Source: CJEU, 2015-10-06 — https://overview.legal/posts/6144 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=6144*

Independence of DPA: The Directive seeks to ensure an effective, complete, and high level of protection of the fundamental rights and freedoms of natural persons. The guarantee of a DPA’s independence is intended to ensure effectiveness and reliability of the monitoring of compliance, and is an essential component of data protection. DPAs powers extend to their own Member State, but not to processing in third countries. However, DPAs are responsible for monitoring transfers from a Member State t

### Supreme Court upholds €300,000 fine against INPS for GDPR violations in COVID bonus data

*Source: Supreme Court, 2026-05-21 — https://overview.legal/posts/53097 — original: https://gdprhub.eu/index.php?title=Cass.Civ._-_15625/2026*

Facts — Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its data processing activities linked to a subsidy given during the pandemic (also called “the COVID bonus”). The DPA found that the controller had postponed its second screening of verifying the eligibility of data subjects to a later stage, on the grounds that there was a need to immediately pay the subsidy. The controller considered that politicians did not fall under the scope of eligible data subjects, as they were already enrolled in a mandatory social security scheme. The controller processed their personal data from databases to cross reference them with data subjects who had applied for the subsidy. The DPA found a violation of several GDPR principles: the principle of lawfulness (Article 5(1)(a) GDPR), data minimisation (Article 5(1)(c) GDPR), accuracy (Article 5(1)(d) GDPR) and accountability (Articles 5(2) and 24 GDPR). According to the DPA, the controller had not limited the cross referencing to data subjects that had received the allowance, but to those whose applications had already been rejected. In addition, the DPA found a violation of Articles 25 and 35 GDPR, as the controller failed to conduct a data protection impact assessment (DPIA). The DPA ordered the controller to erase all personal data that had been processed unlawfully and to carry out a DPIA before resuming its processing activities. The controller appealed the decision to the Court of Rome, and argued that the DPA’s decision was unfounded. The court upheld the appeal and dismissed the DPA’s decision. The court considered that the controller had processed data subjects’ data lawfully, as it had limited the amount of data to what was necessary to verify data subjects’ eligibility. The court also considered that the processing posed a low risk for data subjects’ rights, as the data subjects’ names were not disclosed. The DPA appealed this decision to the court. Holding — The court dismissed the appeal. The court first stated that the controller processed the data lawfully under Article 6(1)(e) GDPR (public interest) and Article 6(3)(b) GDPR. While the controller processed data of specific data subjects (politicians), the court stated that national law allowed the controller to check the eligibility of all data subjects applying for the subsidy. The controller had also obtained the personal data through public databases provided by the Chambers of Parliament and Ministry of the Interior. The court also dismissed the DPA’s arguments on data minimisation (Article 5(1)(c) GDPR). The court stated that the principle of data minimisation is not absolute, and must be balanced with other interests at stake. The court took into consideration the fact that the data was publicly available and the need to quickly verify a high number of applications during a state of emergency. According to the court, there was also no other way to check applications still under review, and concluded that there was an overriding public interest in carrying out the verification process quickly. Finally, the court considered that the controller complied with Article 25 GDPR, as it processed data lawfully and in compliance with Article 5(1)(c) GDPR. In terms of data accuracy (Article 5(1)(d) GDPR), the court dismissed the DPA’s argument that the controller’s system did not eliminate the risk of “homocodes” (identical tax numbers between two or more people). The court considered that the data collected by the Chambers of Parliament and Ministry of Interior were presumed to be accurate. The court also noted that national law foresees the risk of “homocodes” and sets specific procedures in such cases, and that no actual inaccuracies were found in the controller’s verification process. Finally, the court did not find a violation of Article 35 GDPR. The court stated that the controller did not have the obligation to conduct a DPIA, as it did not meet all the necessary criteria. According to the court, the DPA failed to explain the potential high risks of large scale processing that would have justified the need for a DPIA. Given the previous dismissed arguments, the court considered that the controller had also complied with the principle of accountability (Articles 5(2) and 24 GDPR).

### Data Protection Commissioner v. Schrems and Facebook

*Source: CJEU, 2015-10-06 — https://overview.legal/posts/6145 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=6145*

Necessity/proportionality: The Decision does not contain any finding regarding US rules intended to limit the interference when they pursue legitimate objectives such as national security, nor refer to effective legal protection against such interference. FTC procedures and private dispute resolution mechanisms concern compliance with safe harbor principles (against US organizations) and cannot be applied with respect to measures originating from the State. Moreover, the Commission found that if

### GOOGLE SPAIN SL V. AEPD (THE DPA) & MARIO COSTEJA GONZALEZ, 13.May.2014 (“GOOGLE v. Spain”)

*Source: CJEU, 2014-05-13 — https://overview.legal/posts/6158 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0131&ref=6158*

Legitimate interest balancing test: Legitimate interest requires balancing of the interest of the controller and third party with the interest of the data subject. In this particular case, having regard to the sensitivity for data subject’s private life of information contained in announcements and the fact that the initial publication occurred 16 years earlier, the data subject has established that the links should be removed. (¶¶ 70–75, 80-81, 98)

### COLLEGE VAN BURGEMEESTER EN WETHOUDERS VAN ROTTERDAM V. RIJKEBOER, 7.5.2009 (“RIJKEBOER”)

*Source: CJEU, 2009-05-07 — https://overview.legal/posts/5979 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62007CJ0553*

Right of Access: Rules limiting the storage of information on the recipients or categories of recipient of personal data and on the content of the data disclosed to a period of one year and correspondingly limiting access to that information, while basic data is stored for a much longer period, do not constitute a fair balance of the interest and obligation at issue, unless it can be shown that longer storage of that information would constitute an excessive burden on the controller (determinati

### SMARANDA BARA ET AL. V. PRESEDINTELE CASEI NATIONALE DE ASIGURARI DE SANATATE (CNAS) ET AL., 1.10.2015 (“BARA”)

*Source: CJEU, 2015-10-01 — https://overview.legal/posts/5957 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0201*

Right to be informed: National law that does not require the specific transfer involved in the case cannot constitute “prior information” under Article 10 of Directive 95/46 (information requirement where data is collected from the data subject), enabling the controller to dispense with his obligation to inform the data subject of the recipients of the data. (¶¶ 34–38). Article 11 (information requirement where data is not collected from data subject) requires that specified information be provi

### MINISTER VOOR IMMIGRATIE V. M, 17.7.2014 (“Minister v. M”)

*Source: CJEU, 2014-07-17 — https://overview.legal/posts/5962 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0141*

Right to access: The right of access is a per-requisite to obtain rectification, erasure or blocking of personal data (¶¶ 44-46). To comply with the right of access it is sufficient for the applicant to be provided with a full summary of those data in an intelligible form, that is, a form which allows him to become aware of those data and to check that they are accurate and processed in compliance with the Directive. He need not be given a copy of the documents. (¶¶ 59-60)

### Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems

*Source: CJEU, 2020-07-16 — https://overview.legal/posts/6121 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=6121*

“although not requiring a third country to ensure a level of protection identical to that guaranteed in the EU legal order, the term ‘adequate level of protection’ must […] be understood as requiring the third country in fact to ensure, by reason of its domestic law or its international commitments, a level of protection of fundamental rights and freedoms that is essentially equivalent to that guaranteed within the European Union by virtue of the regulation, read in the light of the Charter.

### X, 12.12.2013 (“X”)

*Source: CJEU, 2013-12-12 — https://overview.legal/posts/5965 — original: http://curia.europa.eu/juris/document/document.jsf?text=&docid=145533&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=4180703*

Access: Directive 95/46 does not require Member States to levy fees when the right of access to personal data is exercised, nor does it prohibit the levying of such fees as long as they are not excessive. (¶¶ 22, 25, 28–30)

## Guidance

### Guidelines 01/2022 on data subject rights - Right of access

*Source: EDPB, edpb-guidelines-on-data-subject-rights---right-of-access, 2023-04-17 — https://overview.legal/posts/38055 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en*

The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### Guidelines 04/2022 on the calculation of administrative fines under the GDPR

*Source: EDPB, edpb-guidelines-on-the-calculation-of-administrative-fines-under-the-gdpr, 2023-05-24 — https://overview.legal/posts/38068 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-042022-on-the-calculation-of-administrative-fines-under-the-gdpr_en*

The European Data Protection Board (EDPB) has adopted these guidelines to harmonise the methodology supervisory  authorities use  when calculating of the amount of the fine. These Guidelines complement the previously  adopted Guidelines on the application and setting of administrative fines  for the purpose  of the Regulation 2016/679 (WP253), which focus on the circumstances in which to impose a fine. The calculation of the amount of the fine is at the discretion of the supervisory  authority, ...

### Guidelines 03/2021 on the application of Article 65(1)(a) GDPR

*Source: EDPB, edpb-guidelines-on-the-application-of-article-651a-gdpr, 2023-05-24 — https://overview.legal/posts/38137 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032021-on-the-application-of-article-651a-gdpr_en*

The European Data Protection Board (EDPB) adopted Guidelines 03/2021 to clarify the dispute resolution mechanism under Article 65(1)(a) GDPR, which governs the EDPB's authority to issue binding decisions when a Lead Supervisory Authority receives relevant and reasoned objections from Concerned Supervisory Authorities that it does not follow. The Guidelines address the procedural framework, the threshold for "relevant and reasoned" objections, the scope of the EDPB's substantive competence, and applicable procedural safeguards including the right to be heard, access to the file, and available judicial remedies.

### Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority

*Source: EDPB, edpb-guidelines-for-identifying-a-controller-or-processors-lead-supervisory-authority, 2023-04-17 — https://overview.legal/posts/38046 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-82022-on-identifying-a-controller-or-processors-lead-supervisory_en*

The European Data Protection Board (EDPB) adopted Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority, providing updated guidance on the criteria for determining main establishment and the one-stop-shop mechanism under the GDPR. The guidelines address key concepts including cross-border processing, the "substantially affects" threshold, and the steps controllers and processors must follow to identify their lead supervisory authority. This document serves as interpretive guidance with no fines or enforcement outcomes, replacing the prior WP244 guidelines endorsed by the EDPB in 2018.

### Guidelines 07/2022 on certification as a tool for transfers

*Source: EDPB, edpb-guidelines-on-certification-as-a-tool-for-transfers, 2023-02-24 — https://overview.legal/posts/38131 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-072022-on-certification-as-a-tool-for-transfers_en*

The GDPR requires in its Article 46 that data exporters shall put in place appropriate safeguards for transfers of personal data to third countries or international organisations. To that end, the GDPR diversifies the appropriate safeguards that may be used by data exporters under Article 46 for framing transfers to third countries by introducing, amongst others, certification as a new transfer mechanism (Articles 42 (2) and 46 (2) (f) GDPR). These guidelines provide guidance as to the applicati...

### Guidelines 06/2022 on the practical implementation of amicable settlements

*Source: EDPB, edpb-guidelines-on-the-practical-implementation-of-amicable-settlements, 2022-05-12 — https://overview.legal/posts/38072 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-062022-on-the-practical-implementation-of-amicable-settlements_en*

The EDPB adopted Guidelines 06/2022 to provide practical guidance on the implementation of amicable settlements between supervisory authorities and controllers or processors under the GDPR. The guidelines address the scope and definition of amicable settlements, the legal basis for this power, and its procedural operation within the one-stop-shop mechanism, including the roles of the complaint-receiving competent supervisory authority and the lead supervisory authority. No fines are imposed as this is a guidance document rather than an enforcement decision.

### Guidelines 04/2021 on Codes of Conduct as tools for transfers

*Source: EDPB, edpb-guidelines-on-codes-of-conduct-as-tools-for-transfers, 2022-02-22 — https://overview.legal/posts/38133 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-042021-on-codes-of-conduct-as-tools-for-transfers_en*

The  GDPR  requires  in  its  Article  46  that  controllers/processors shall  put  in  place  appropriate safeguards for transfers of personal data to third countries or international organisations. To that end, the GDPR diversifies the appropriate safeguards that may be used by organisations under Article 46 for  framing transfers  to third countries  by  introducing  amongst  others, codes  of  conduct  as a new transfer  mechanism  (articles  40-3  and  46-2-e).  In  this  respect, as  provi...

## Recent developments

### AI hallucinations: ChatGPT created a fake child murderer

*Source: noyb - European Center for Digital Rights, 2025-03-20 — https://overview.legal/posts/53159 — original: https://noyb.eu/en/ai-hallucinations-chatgpt-created-fake-child-murderer*

Artificial Intelligence OpenAI’s highly popular chatbot, ChatGPT, regularly gives false information about people without offering any way to correct it. In many cases, these so-called “hallucinations” can seriously damage a person’s reputation: In the past, ChatGPT falsely accused people of corruption, child abuse – or even murder. The latter was the case with a Norwegian user. When he tried to find out if the chatbot had any information about him, ChatGPT confidently made up a fake story that p

### CJEU clarifies GDPR principles of purpose limitation and storage limitation

*Source: NL EU Court Expert, 2022-10-30 — https://overview.legal/posts/6247 — original: https://ecer.minbuza.nl/-/eu-hof-verduidelijkt-de-beginselen-van-doelbinding-en-opslagbeperking-uit-de-avg?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-1209*

The purpose limitation principle does not preclude a controller from capturing and storing in a test database established for testing and error correction purposes personal data previously collected and stored in another database. However, such "further processing" of personal data must be compatible with the specific purposes for which the personal data were originally collected. The principle of storage limitation precludes the retention of personal data in that test database for longer than n

### What Happened to the Risk-Based Approach to Data Transfers?

*Source: Future of Privacy Forum, 2022-09-27 — https://overview.legal/posts/6271 — original: https://fpf.org/blog/what-happened-to-the-risk-based-approach-to-data-transfers/#entry-912*

The GDPR incorporates the RBA for all obligations of the controller in the GDPR. Where the transfer rules are stated as obligations of the controller (rather than as absolute principles), the RBA of Article 24 therefore applies. Other than the DPAs assume, this is not contradicted by the ECJ in Schrems II nor by the EDPB recommendations on additional measures following the Schrems II judgment, according to Lokke Moerel, Professor of Global ICT Law at Tilburg University and a Dutch Cyber Security

### AEPD publishes GDPR Risk Assessment

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/6259 — original: https://evalua-riesgo.aepd.es/index_en.html#entry-1032*

> GDPR RISK ASSESSMENT is intended to assist controllers and processors to identify the risk factors for the rights and freedoms of data subjects whose data are present in the processing, to make an initial assessment of the intrinsic risk, including the need to perform a DPIA, and to estimate the residual risk if measures and safeguards are used to mitigate the specific risk factors.

### Wizz Air: €1 for a flight, €35 for your GDPR right

*Source: noyb - European Center for Digital Rights, 2020-10-21 — https://overview.legal/posts/53341 — original: https://noyb.eu/en/wizz-air-eu1-flight-eu35-your-gdpr-right*

Data Subject Rights Wizz Air: €1 for a flight, €35 for your GDPR right On 21.10.2020 noyb filed a GDPR complaint against Central and Eastern Europe’s Largest Low Cost Airline, Wizz Air. A passenger changed her surname. Despite the free right to rectification under the GDPR, the airline charged € 35 in phone charges to update a surname. The relevant email was never updated, leading to emails by Wizz Air not being delivered. Especially during the corona crisis, keeping personal information up-to-d

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **IP Address** — https://overview.legal/topics/ip-adres
  Internet protocol addresses as personal data
- **Lawful Basis** — https://overview.legal/topics/lawful-basis-article-6
  This topic is essential as Article 6 GDPR provides the specific legal bases that determine whether processing is lawful, which is the core requirement of the 'L
- **Human Resources** — https://overview.legal/topics/human-resources
  Processing of employee and HR data

---
Generated by overview.legal · https://overview.legal/topics/right-to-rectification · 2026-08-22
