GDPR
Chapter III - Rights of the Data Subject

GDPR GDPR-Art.16: Right to rectification

On request, rectify inaccurate personal data concerning the data subject without undue delay, and, having regard to the purposes of the processing, complete incomplete personal data, including by means of the data subject providing a supplementary statement.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 48 controls across 39 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • AUCDR-PS-11 Privacy Safeguard 11 - Quality of CDR data
  • AUCDR-PS-13 Privacy Safeguard 13 - Correction of CDR data
  • APP-10 APP 10 - Quality of personal information
  • APP-13 APP 13 - Correction of personal information

ISO 27701:2019 · 2 controls

  • 7.3.6 Access, correction and/or erasure
  • 7.4.3 Accuracy and quality

NIST SP 800-53 Rev 5 · 2 controls

  • NIST800-PM-22 Personally Identifiable Information Quality Management. Develop and document organization-wide policies and procedures for: Reviewing for the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle; Correcting or deleting inaccurate
  • NIST800-SI-18 Personally Identifiable Information Quality Operations. Check the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle [organization-defined] ; and Correct or delete inaccurate or outdated personally identifiable information

SOC 2 · 2 controls

  • SOC2-P5.2 Corrections to personal information are processed timely
  • SOC2-P7.1 Personal information collected is limited to what is necessary and relevant

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion
  • MALABO-Art19 Data Subject Right of Rectification and Erasure
  • AO-PDPL-8 Right of Rectification, Erasure and Blocking
  • MYHR-GOV-5 Retention, destruction and correction obligations of the System Operator
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AZ-DPA-7 Article 7 - Rights of the data subject

Bahrain PDPL · 1 control

  • BH-PDPL-07 Right to rectification of inaccurate data
  • BB-DPA-11 Section 11 - Right to Rectification

CCPA/CPRA · 1 control

  • §1798.106 Right to Correct Inaccurate Personal Information

Canadian PIPEDA · 1 control

  • CAYDPA-s14 Rectification, Blocking, Erasure or Destruction (s.14)
  • CSL-Art43 Right to Correction and Deletion - Art. 43
  • CCM-DSP-11 Personal Data Access, Reversal, Rectification and Deletion
  • CDR-PS-13 Privacy Safeguard 13: Correction of CDR Data
  • CZ-110-§28-29 Prava subjektu udaju v trestnim rizeni (access, rectification, erasure under LED)
  • MU-DPA17-s39 Rectification, erasure or restriction of processing
  • ESRB-PC-12 Parental access, review and deletion rights

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter III - Rights of the Data Subject

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.16 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 40 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 48 it maps to, and the evidence behind each claim, over MCP and REST.