HomeSearch

Lenses
Business lenslens
Certifying body lenslens
End user / data subject lenslens
Front-line staff lenslens
Government lenslens
Human rights / privacy advocate lenslens
Policymaker (Government lens)lens
Regulator / enforcer (Government lens)lens
Africa
Egyptplanned
Ghanaplanned
Kenyaplanned
Moroccoplanned
Nigeriaplanned
Rwandaplanned
South Africaplanned
Asia-Pacific
Australiaplanned
Chinadrafting
Hong Kongplanned
Indiaplanned
Indonesiaplanned
Japanplanned
Malaysiaplanned
New Zealandplanned
Philippinesplanned
Singaporeplanned
South Koreaplanned
Thailandplanned
Vietnamplanned
Europe
European Uniondrafting
Switzerlandplanned
Türkiyeplanned
United Kingdomplanned
Latin America
Argentinaplanned
Brazilplanned
Chileplanned
Colombiaplanned
Peruplanned
Uruguayplanned
Middle East
Bahrainplanned
Israelplanned
Qatarplanned
Saudi Arabiaplanned
United Arab Emiratesplanned
North America
Canadaplanned
Mexicoplanned
United States (federal)drafting
United States
Californiadrafting
Coloradoplanned
Connecticutplanned
Delawareplanned
Floridaplanned
Indianaplanned
Iowaplanned
Kentuckyplanned
Marylandplanned
Minnesotaplanned
Montanaplanned
Nebraskaplanned
New Hampshireplanned
New Jerseyplanned
Ohioplanned
Oregonplanned
Rhode Islandplanned
Tennesseeplanned
Texasplanned
Utahplanned
Virginiaplanned
Menu

End user / data subject

What can I actually do about this today, and what does it cost me.

Handbook §61 · 29 sections

Drafting material: not yet published or verified for publication. States what the sources say; not legal advice.

61.1 /

What this handbook is

Part VII takes each of the six lenses and sustains it across the whole field. This section is the end-user lens, assembled.

Who it is for. The person the data is about. You. Not the organisation holding it, not its lawyers, and not its regulator.

Where the material comes from. Every six-lens block in this document carries an end-user lens, and they are scattered across fifteen sections in eleven volumes. Nobody reading them one at a time would encounter them together, and the assembly is the point.

What this handbook will not do. It will not tell you that you have more than you do. The instruction governing this lens throughout the document is to be unsentimental about rights that exist but are unusable, and section 61.26 collects them rather than burying them.

What it does instead. It tells you what you can actually do, in what order, and what will actually happen — including where the answer is nothing.

One structural warning before you start. Your rights depend almost entirely on where you live and, in the United States, which state. Section 43.21 and section 49.12 record two very different positions. This handbook says which is which rather than describing a global position that exists nowhere.

Vol. 39 · §61.1 · Currency 2026-09-03 · drafting

61.2 /

The honest summary

Read this before anything else, because it will tell you whether the rest is worth your time.

What works. Access, correction and deletion, in any jurisdiction with a comprehensive data protection statute. These are exercisable, they produce a response, and organisations mostly comply. They are slow.

What works better than most people know. The platform routes at section 61.16. If a platform restricted your account or your content, section 5.16A records a statement of reasons, a free internal appeal handled by people, an out-of-court dispute body and compensation — faster than any data protection route and designed to be used without a lawyer. Most people never learn this exists.

What works and is slow. Complaining to a regulator. Section 61.22.

What mostly does not work. The right not to be subject to an automated decision. Section 61.15 explains why. Portability, per section 61.13. And anything to do with artificial intelligence specifically, per section 61.18.

What you cannot find out at all. Section 61.25, and the list is longer than you would expect.

The single most useful thing in this handbook, if you read nothing else: section 61.5, finding the right respondent. More requests fail on this than on any substantive ground.

Vol. 39 · §61.2 · Currency 2026-09-03 · drafting

61.3 /

Where you are visible

A useful frame, because it predicts where you will get somewhere.

You are visible at two points in the whole lifecycle of your data, and only two.

When it is collected. Section 30.28 records it: acquisition is the one stage you see. You are present, you are addressed, and something is asked of you. That visibility is what makes the arrangement look consensual, and section 30.28 also records that the conditions are set entirely by the other party, at a moment when you want something else.

When you exercise a right. Section 35.1 records it as the second and last stage. Unlike collection, you arrive deliberately — you decided to act — and what you get is the truest measure of what the system delivers to you.

Everywhere else you are absent. Storage, security, transfer, vendor arrangements, destruction, certification, conformity assessment, standards. Section 19.29 records that transfers are the part least visible to you and least usable by you. Section 26.15 records that certification excludes you entirely. Section 53.21 records that the international layer gives you nothing at all.

Why this matters practically. Effort spent at the two visible points produces results; effort spent elsewhere does not. If you want to change what an organisation does, the leverage is at collection — refusing, withholding, choosing differently — and at the moment you exercise a right.

Vol. 39 · §61.3 · Currency 2026-09-03 · drafting

61.4 /

Before you start

Four things worth knowing before you send anything, and a note on acting for someone else.

It is free. Section 35.25: rights are exercisable without charge, and almost no organisation should be charging you. If you are asked to pay, that is very likely wrong.

There is no form. Section 35.3: a request is valid however it arrives and to whoever receives it. An organisation may prefer a form and cannot require one. If a form asks for more identifying information than they already hold, you can decline and send an email instead.

The clock starts when it arrives, not when they notice. Section 35.6. An email sitting unread in a shared mailbox is still running down their time. Note the date you sent it.

You do not have to say which right you are exercising, and you do not have to use the legal words. Section 35.4 records that organisations are supposed to recognise a request from its subject matter. “Please send me everything you hold about me” is a valid access request.

One thing that helps and is not required. Being specific. Section 35.8 records that an organisation processing a large amount of data may ask you to narrow it. Saying what you actually want — the file about a particular complaint, the recordings from a particular week — gets a faster and better answer than asking for everything and receiving a partial extract.

If you are asking on behalf of someone else, which this handbook has so far assumed you are not.

For a child. Whether a parent may exercise the child’s rights, and up to what age, is jurisdiction-specific. The organisation will check two things: your authority, and whether the child is old enough to decide for themselves. Section 35.5 records that where a third party acts for an individual, authority must be checked as well as identity, and that requests concerning children are one of the cases where more verification is legitimately warranted.

The point that surprises parents. Above a certain age the right is the child’s, not yours, and an organisation may properly refuse you and offer it to them. Sections 9.12 and 12.31 record the treatment of minors in two frameworks. That is not obstruction.

For an adult who cannot act themselves. You will need whatever authority your jurisdiction recognises — a power of attorney, a deputyship, or an equivalent — and section 35.5 records that the organisation must check it.

For someone who simply asked you to. A written authority from them, sent with the request, is usually enough. Section 35.3 records that a request made through a lawyer or a representative is valid, and so is one made through a third-party rights service.

What not to do. Do not send a request from their account or in their name. Section 35.5 records the risk it creates on the other side: disclosing someone’s data to the wrong person is itself a breach, and an organisation that suspects an impersonated request will refuse the whole thing.

Vol. 39 · §61.4 · Currency 2026-09-03 · drafting

61.5 /

Finding the right respondent

More requests fail here than anywhere else, and section 2’s lens block records why: you must identify the right respondent before you can exercise anything, and you cannot see the allocation that determines who that is.

The rule. Your rights are exercised against the controller — the organisation deciding why and how your data is used. Not against its suppliers. Section 35.21 records that a processor receiving your request should forward it and not answer it, which means a request sent to the wrong party costs you time.

Why you cannot tell from outside. The allocation is a question of fact, per section 34.2, and it is not published. The organisation you dealt with is usually the controller and that is the right default.

Where two organisations are involved. Section 34.10 records joint controllership, and section 2’s lens block gives the practical advice: you may proceed against either, so choose the one with the more responsive process rather than the one that looks more responsible.

Groups of companies. Section 34.12 records the failure — a group operating as one brand, discovering at a request that nobody can say which entity is the controller. Address it to the brand you dealt with. Working out their corporate structure is not your job and section 35.22 records that it is theirs.

The single most useful address. The data protection officer, where one exists. Section 38.16 records it as the only externally reachable accountability artefact in the whole framework, and that a request sent there gets a materially better response than one sent to general enquiries — because that person has a statutory function and a professional interest in it being handled correctly. Their details are published. Look for them first.

Vol. 39 · §61.5 · Currency 2026-09-03 · drafting

61.6 /

Making an access request

The most useful right you have, and the one everything else depends on.

What to say. That you are asking for your personal data. That is enough. Adding “under the applicable data protection law” costs nothing and signals that you know it is a legal request.

What to ask for specifically, because it improves what you get. The data itself. And the supplementary information at section 61.8, which most organisations omit and which is the part that tells you what is happening rather than merely what is held.

Identity. Section 35.5 records the balance. If you are asking from an email address they already hold, that is substantial evidence and they should not need more. Demanding photographic identity documents by default is disproportionate and section 35.5 records it as the more common failure. If they ask for more than seems reasonable, ask why.

How long. Jurisdiction-specific and recorded per jurisdiction in Part II. Roughly one month is typical, extendable for complex requests — but section 35.6 records that an extension taken without telling you inside the original period is not an extension, it is a missed deadline.

What to keep. The date you sent it. What you asked for. Everything they send back. Section 35.26 records that the organisation’s file is its entire defence in a complaint; yours is yours.

Vol. 39 · §61.6 · Currency 2026-09-03 · drafting

61.7 /

What a good response looks like

Worth knowing, so you can tell whether you got one.

A good response contains. Confirmation that they hold data about you. A copy of it, in a form you can read. And the supplementary information at section 61.8.

What most responses actually look like. A partial dataset in a format designed to satisfy the letter of the obligation rather than to inform you. Section 5.9’s lens block records it in those terms and it is the most common outcome.

The specific omissions to look for.

Email. Section 35.8 records that email and messaging usually hold more personal data about you than the systems of record. If your response contains no emails, they did not search email, and that is worth pointing out.

Inferences. Section 30.17 records that inferences about you are personal data and are routinely omitted because nobody thinks of them as data held. Scores, segments, risk ratings and predicted characteristics are all in scope.

Opinions about you. Section 35.8: in scope, including notes recorded by staff.

What to do about an incomplete response. Write back, name the omission specifically, and ask them to complete it. Naming a specific gap works much better than saying the response is inadequate, because it gives them something they can act on and gives you something concrete for a complaint later.

Vol. 39 · §61.7 · Currency 2026-09-03 · drafting

61.8 /

The supplementary information

The part nobody sends, and the part that actually tells you something.

What you are entitled to, per section 35.7. The purposes. The categories of data. The recipients or categories of recipient, including any outside your country. The retention period or how it is decided. Your rights, including the right to complain. The source, where they did not get the data from you. And whether there is automated decision-making, with meaningful information about the logic and the consequences.

Why it matters more than the data. The data tells you what they hold. The supplementary information tells you what is happening to it — who else has it, where it went, how long they will keep it, and where they got it.

The one to press on. The source. Section 30.13 and section 30.15 record that most organisations cannot say where indirectly-collected data came from. “Who told you that about me?” is a valid question and section 35.4 records that it is a valid access request in itself.

A common deflection to recognise. Being sent the privacy notice instead. Section 35.7 records that a privacy notice is not the supplementary information, however much it contains. You are entitled to information about your data — the actual recipients, the actual source, the actual retention position.

Vol. 39 · §61.8 · Currency 2026-09-03 · drafting

61.9 /

Correcting something

The cheapest right to exercise and the one most likely to work.

What it covers. Facts that are wrong. An address, a date, a name, a balance, a record of what happened.

What it does not cover. An opinion is not inaccurate because you disagree with it. Section 35.12 records the position: a record that a manager assessed your performance as poor is accurate if that assessment was made, whatever its merits.

The remedy that exists for opinions and is under-used. Section 35.12 records that several regimes provide for a statement of your disagreement to be attached to the record, and section 16.24 records the New Zealand mechanism expressly. The record stands and your disagreement travels with it. Ask for this by name; many organisations do not offer it.

What to also ask for. That the correction be passed on to anyone they gave the wrong data to. Section 35.12 records that the obligation generally exists and that organisations which cannot say who received the data cannot comply with it. Asking makes that visible.

Vol. 39 · §61.9 · Currency 2026-09-03 · drafting

61.10 /

Contesting an inference

Harder than correcting a fact, and section 35.13 gives you the framing that works.

Why it is awkward. An inference — a score, a segment, a prediction — is not a fact that is right or wrong. It was correctly computed from inputs and it may still be wrong about you. Asking to “correct” it invites the answer that a prediction cannot be inaccurate.

The four things you can contest instead, per section 35.13.

The inputs. If the inference rests on data that is wrong, correct the data and ask for the inference to be recomputed.

Whether they should have drawn it at all. Section 30.17 records that creating an inference is itself an act that needs a basis.

Whether they should still be holding it. Erasure, per section 61.11, often fits better than correction.

How they are using it. Objection, per section 61.13, or the automated decision route at section 61.14.

What to do in practice. Raise all four in one letter and do not label it. Section 35.13 records that an organisation should answer the substance rather than the label, and that refusing on the ground that a prediction cannot be inaccurate is technically defensible and reads badly to a regulator.

Vol. 39 · §61.10 · Currency 2026-09-03 · drafting

61.11 /

Getting something deleted

Available everywhere and absolute nowhere.

When it works. When they no longer need the data for the purpose they got it for. When you withdraw consent and there is no other basis. When you object successfully. When the processing was unlawful.

When it does not. When they have a legal obligation to keep it. When it is needed for legal claims. When a retention period applies to that specific data.

What to expect, and section 35.15 records why this is normal rather than obstruction. A partial answer. Financial records kept for the tax period, contact details deleted, behavioural data deleted, and a minimal record retained. That is usually correct.

The one retained record that looks like non-compliance and is not. If you asked them to stop contacting you, they must keep enough to honour that. Deleting everything would mean you are re-acquired at the next data load and marketed to again. Section 35.15 records it as a suppression record and it is the right outcome.

What to insist on. Specificity. Section 35.16: what was deleted, from where, when the rest goes, and what is retained and why. A response saying “your data has been deleted” and nothing more is not an answer, and section 61.12 explains why it may not even be true.

Vol. 39 · §61.11 · Currency 2026-09-03 · drafting

61.12 /

What deleted actually means

The most important thing in this handbook that nobody will tell you.

Section 36.2 records that four different things get called deletion. The record is removed from an index and the data remains on the disk. The data is overwritten. The medium is sanitised. The medium is destroyed. Only the last two mean what you think “deleted” means, and the first is what a database delete usually does.

Which means an organisation can tell you your data was deleted, in good faith, when it is still there.

Whether it actually happened, and this is the finding you should know. Section 36.16 records it plainly: destruction is the only stage whose success is unobservable by construction. It produces no artefact you receive and no state you can inspect. You cannot verify it, the regulator largely cannot verify it, and neither can anyone else outside the organisation.

The only self-help available. Make a fresh access request some months later and see whether the data reappears. It is weak — section 36.16 records that a well-run dereferencing removes data from the systems an access request searches while leaving it in backups, warehouses and abandoned systems that an access search does not reach — and it is the only thing you can do.

When you will find out it failed. Section 36.16: at the moment a breach discloses data you were told had been erased. You learn that destruction failed only when the failure has already harmed you.

Vol. 39 · §61.12 · Currency 2026-09-03 · drafting

61.13 /

Stopping something

Three different rights, and they behave very differently.

Objection to direct marketing is absolute. Section 35.18. Say stop and they must stop. No balancing, no exceptions, no reasons required from you. This is the strongest right you have and the easiest to exercise.

Objection to other processing is qualified. Where they rely on legitimate interests or a public task, you can object and they must stop unless they demonstrate compelling grounds overriding your interests. Section 35.18 records that the burden is on them and that an unreasoned assertion does not discharge it. Ask them to state the grounds.

Restriction is the one nobody uses and it is useful in a dispute. Section 35.17: the data is kept and not otherwise used, while something else is resolved — while you are contesting accuracy, or while an objection is being assessed. It is the right interim answer in a contested matter and section 35.17 records that many organisations cannot implement it, which is worth knowing before you rely on it.

Portability, and the honest position. Section 35.19 records it as the narrowest and least used right: it covers only data you provided, only where processing rests on consent or contract, and there is usually nowhere to send the file. Section 35.19 records two jurisdictions concluding that the right alone does not work and building transmission infrastructure instead. Ask for it if you want the file. Do not expect it to move you anywhere.

Vol. 39 · §61.13 · Currency 2026-09-03 · drafting

61.14 /

Automated decisions: what to ask

Where a system decided something about you, this is the route — and section 61.15 records what you will actually get.

Whether you have this right at all depends entirely on where you are. Section 5.2 records the European provision. Section 14.23 records Korea’s, which gives a right to refuse and, where refusal is unavailable, an explanation and human review. Section 12.12 records China’s. Section 9.3 records California’s pre-use notice, opt-out and access rights. Section 48.5 records Quebec’s, which is the only right of its kind in Canada. Section 50.4 records Brazil’s. Section 16.13 records that Australia’s is a privacy policy disclosure and not a right about your decision. Section 13.26 and section 49.4 record that India has none at all.

What to ask for, where the right exists. That they confirm the decision was made by automated means. The reasons. Human review. And the information used.

The question that gets the most useful answer. “Was a human involved, and what did they actually do?” Section 61.15 explains why.

The thing to ask for that most people do not know about. In the United States, if you were refused credit, insurance or employment, you are entitled to the specific principal reasons. Section 61.19 covers it and section 43.10 records that it is the most heavily used explanation right in the world.

Vol. 39 · §61.14 · Currency 2026-09-03 · drafting

61.15 /

Automated decisions: what you will get

The unsentimental part, and it is the widest gap between a right on paper and a right in practice in the whole framework.

The provision protects you only where the decision was made solely** by automated means.** Section 35.20 records the consequence: a nominal human in the loop removes the decision from the right entirely.

Which means the answer you will usually receive is that a person reviewed it. Sometimes that is true and meaningful. Often the person approved the system’s output without the time, the information or the authority to depart from it.

What to do with that answer. Ask what the reviewer actually did. How long they had. What information they saw beyond the score. Whether they have ever reached a different conclusion from the system. Section 55.13 records that the override rate is the only meaningful measure of whether review is real, and an organisation that cannot answer has told you something.

The scale of the problem, recorded so you know it is not just you. Section 5.9’s lens block records Article 22 as the widest gap between right and reality in the European framework: very few people have used it successfully, because the exceptions cover most commercial deployments and because you rarely know an automated decision was made.

Section 40.21 records that the AI Act tried to close this by requiring systems to be built so a person can genuinely override them. It has not closed it, because the design obligation sits on the provider and whether the reviewer has authority is a matter for the deployer’s organisation.

Vol. 39 · §61.15 · Currency 2026-09-03 · drafting

61.16 /

The routes that work better than data protection

If a platform is involved, use these first. Section 5.16A records that this cluster gives you more usable rights than any other, and the reason is that two of them do not depend on a regulator.

If a platform restricted your content or your account. Section 5.16A records what the Digital Services Act gives you: a statement of reasons, a free internal appeal handled by people rather than only by machines, an out-of-court dispute settlement body, and compensation. Section 5.16A records the assessment plainly: faster than any data protection route and designed to be used without a lawyer.

Why this matters so much in practice. Most people whose account or content was restricted reach for a data protection complaint, wait months, and get nothing useful. The platform route is quicker, more specific to what actually happened to you, and produces an outcome.

The recommender option. Section 41.3 records that very large platforms must offer at least one recommender option not based on profiling, and explain the main parameters of the one they use. You have to go and turn it on.

Health records, where they apply. Section 5.17 records the strongest set of individual rights in the field: immediate free access to your own record in a consolidated readable form, which section 5.17 records is more than the general access right delivers in practice.

Vol. 39 · §61.16 · Currency 2026-09-03 · drafting

61.17 /

The access log

The single most interesting right in this document, and almost nobody has it yet.

What it is. Section 5.17 records it: the right to see which professional accessed your record and when.

Why it is different in kind from everything else in this handbook. Every other right lets you request data. This one lets you detect misuse. Section 5.17 records the assessment: it is the only right here that lets you find out that something wrong happened, rather than merely asking what is held.

Why that matters, and section 33.10 explains it from the other side. Insider access — a member of staff looking up someone they know — generates no security alert at all, because every individual action is authorised. The organisation will not detect it. An access log right is the only mechanism in this document that puts detection in the hands of the person affected.

Where it exists. Currently in health records in the jurisdictions section 5.17 covers. If it applies to you, use it, and if you are ever asked what would improve individual rights generally, this is the answer with the best evidence behind it.

Vol. 39 · §61.17 · Currency 2026-09-03 · drafting

61.18 /

If a system decided about you

The artificial intelligence framework, and the honest position is that it gives you very little.

What you are called. Section 27.15 records it: the AI Act calls you an affected person, not a data subject and not a consumer. You are the job applicant screened, the borrower scored, the student assessed, the traveller checked.

What you get. An explanation of the role the system played in a decision with legal or similarly significant effect, exercisable against the organisation that used it. Disclosure that you are interacting with a system, and labelling of synthetic content. The right to complain to a market surveillance authority.

What that complaint route actually is, per section 40.40. A product safety process with no individual remedy at the end of it. The authority may withdraw a product from the market; it will not compensate you.

The one genuine gain. Section 27.9 and section 27.15: a public database of high-risk systems, including public authority deployments. You can look up what is deployed. Section 27.15 records that this is the one place in the whole conformity framework where an individual can find out anything.

Where the gap is widest. Section 40.40: classification. Whether a system is high risk determines whether any of this applies, the determination is made by the organisation itself, and you have no way to discover that the classification was the reason you got nothing.

The blunt comparison. Section 40.40 records that under the AI Act your position is closer to that of a consumer of a regulated product than to that of a data subject. Your actual remedies remain the data protection ones in this handbook, plus product liability at section 41.7.

Vol. 39 · §61.18 · Currency 2026-09-03 · drafting

61.19 /

If you are in the United States

A different system, with a genuinely different profile, and section 43.21 states the comparison.

What is weaker. Coverage. Your rights depend on your state and on what the decision was about. Employment data is exempt from most state comprehensive laws. There is no pre-market scrutiny of anything.

What is stronger, and this is the part usually omitted.

The adverse action notice. Section 43.10 and section 43.22: if you are refused credit, and in related contexts, you are entitled to the specific principal reasons. Not a description of an algorithm — actual reasons. Section 43.22 records it as the most heavily used algorithmic explanation right in the world by volume, and it has worked for decades. Ask for it by name.

Biometrics. Section 9.9 and section 43.17: in some states, if an organisation took your fingerprint, faceprint or voiceprint without written consent beforehand, there is a private right of action with damages fixed by statute and you do not have to prove harm.

Litigation and discovery. Section 43.19 and section 43.22: an American claimant can compel production of training data documentation, validation studies and internal assessments. Section 40.40 records that a European individual can obtain none of those.

What removes all of it. An arbitration clause with a class action waiver. Section 43.19 records it as the single most consequential fact about American AI governance. Check the terms of service. If you agreed to arbitration, the strongest part of this system is closed to you.

Vol. 39 · §61.19 · Currency 2026-09-03 · drafting

61.20 /

If your jurisdiction has no functioning regulator

Stated because it is a very common position and no other handbook will tell you.

What section 18.31 and section 52.10 record. Three failures recur. No authority constituted — the statute provides for a supervisor and none exists. An authority inside another body, so it exists and its independence does not. An authority that is independent and unfunded, which produces nothing and appears in every survey.

What that means for you. The rights exist and there is nowhere to bring a complaint about them. Section 52.10 records the position: a statute conferring rights with no constituted supervisor gives you a claim and nowhere to take it.

What still works. The request itself. An organisation may well comply, because complying is cheaper than arguing and because its parent company or its suppliers may require it.

And the constitutional routes, which are stronger in some jurisdictions than the statutory ones. Section 50.8 records habeas data across Latin America: a constitutional action, generally fast, available directly, and available against private entities in several jurisdictions. Section 50.8 also records its limit: it reaches data that is held and does not naturally reach an inference or a model. Section 49.9 records public interest litigation in India, which reaches diffuse harm and is brought by civil society rather than by you.

Vol. 39 · §61.20 · Currency 2026-09-03 · drafting

61.21 /

When they refuse

A refusal is a decision and it has to meet requirements. Section 35.23 records them.

What a proper refusal contains. That they are refusing, in whole or part. The reasons. Your right to complain to a supervisory authority and your right to a judicial remedy. And it must arrive within the deadline.

Reasons that do not work, and section 35.23 lists them. “Commercially confidential.” “Internal document.” Neither is an exemption anywhere. A refusal that does not say which exemption they rely on is not a reasoned refusal.

The refusal you should expect and should test. That another person’s data is mixed with yours. Section 35.9 records that this is a balancing exercise, not a prohibition, and that withholding an entire document because it contains another name is an avoidance of the balance rather than a performance of it. Ask them to redact and provide the rest.

“Manifestly unfounded or excessive.” Section 35.24 records that the bar is high and the ground is invoked too readily. It is not made out because your request is inconvenient, because you are in dispute with them, or because they think you have an ulterior purpose. Section 35.24: your motive is generally irrelevant — a request made to help a grievance or a legal claim is a valid request.

What to do. Write back naming the ground you dispute and why. Then complain, per section 61.22, and attach the refusal.

Vol. 39 · §61.21 · Currency 2026-09-03 · drafting

61.22 /

Complaining to a regulator

Free, slow, and the main route where one exists.

What actually happens. Section 39.3 records it. Most complaints are resolved informally: the authority contacts the organisation, the organisation responds, and the matter closes. A large proportion concern rights handling and are resolved by the organisation providing what it should have provided. That is a success and it leaves no public record.

What is unlikely to happen. Formal enforcement. Section 39.3 records the ratio: complaints in the tens of thousands a year, enforcement outcomes in the tens or low hundreds. That is not a scandal and it is the reality to plan against.

How long. Long. Section 39.3 records delay as the near-universal complaint about authorities and section 39.11 records why: resourcing.

What makes your complaint more likely to produce something, per section 39.3. Evidence attached. A pattern rather than a single incident. A clear, specific breach of a documented obligation — a missed deadline is the easiest thing in the world to prove. And overlap with the authority’s published priorities.

The procedural right worth knowing. Section 39.3 and section 38.16 record that several regimes give you a right to a decision on your complaint and a remedy if the authority fails to decide. That reaches delay, which is the thing most likely to happen to you.

Vol. 39 · §61.22 · Currency 2026-09-03 · drafting

61.23 /

Going to court

Available, expensive, and worth it in narrower circumstances than you would hope.

What you can claim. Compensation for material and non-material damage. Section 3.4 records the comparative position across jurisdictions and it varies enormously.

What constrains it. Requirements that damage be more than trivial. Difficulty of proof. And cost relative to the likely award, which is the binding constraint. Section 39.10 records the position: the economics only work at scale, which is why the availability of a collective mechanism largely determines whether private enforcement exists in a jurisdiction at all.

Which means the practical question is whether you can join something. Section 3.4 records collective redress. A representative action, a consumer body action or a class action changes the arithmetic completely, and section 43.17 records the American statutory damages regime that makes it work best.

The route people miss. Product liability, per section 41.7. If an AI system caused you harm, the revised European regime reaches software and eases the burden of proof, and it does not require you to establish any breach of the AI Act at all — defectiveness is the test. Section 40.40 records that this, not the AI Act, is where an individual remedy actually lives.

Vol. 39 · §61.23 · Currency 2026-09-03 · drafting

61.24 /

Arbitration clauses

A short section on the thing most likely to have removed your options without your noticing.

What it is. A term in a service agreement requiring disputes to go to arbitration rather than court, usually with a waiver of any right to join a class action.

Why it matters more than any statute in this handbook. Section 43.19 records it: the litigation route is the American system’s principal protective mechanism, and it is switched off by a term of service. Section 43.22’s advocate lens records that an assessment of that system should treat arbitration as the central issue.

What to do about it. Check the terms of any service where the stakes are meaningful. Some agreements offer a limited window to opt out of arbitration after signing up, and almost nobody uses it. If you are ever offered that window, take it.

Where it does not reach. Regulatory complaints, per section 61.22. An arbitration clause binds you against the company; it does not bind the regulator.

Vol. 39 · §61.24 · Currency 2026-09-03 · drafting

61.25 /

What you will never find out

Collected here rather than scattered, because knowing the boundary saves you effort.

Whether your data was actually deleted. Section 61.12 and section 36.16.

Whether a system that decided about you was classified correctly. Section 40.40: the determination is internal and you cannot see it.

What the impact assessment said. Section 38.16 records that you have no right to see an impact assessment, that it is frequently withheld from an access response on the ground that it is not your personal data, and that this is technically correct. Section 38.16 records this as the widest gap in the accountability framework: the instrument by which the risk to you is assessed, and you are not a party to it.

Which specific organisations received your data. Section 19.29 records that responses typically name categories of recipients rather than recipients, and identify the transfer mechanism generically.

Whether a state accessed your data. Section 5.9’s lens block records that the redress mechanism does not tell a complainant whether they were surveilled, and that a remedy which cannot be inspected is hard to distinguish from no remedy.

Anything about certification. Section 20.17 and section 26.15: you have no right to the report, no right to the scope, no standing to challenge a decision and no claim against the body. Section 26.15 records the sharpest version: your data may leave the Union on the strength of a certificate you cannot see, issued by a body you cannot challenge, under criteria approved by a regulator you cannot petition on the point.

The one place with a public register. Section 27.9, per section 61.18.

Vol. 39 · §61.25 · Currency 2026-09-03 · drafting

61.26 /

Rights that exist and are unusable

Named plainly, because the instruction governing this lens is to be unsentimental about them.

The right not to be subject to a solely automated decision. Section 61.15. Defeated by a nominal reviewer, and section 5.9’s lens block records it as the widest gap between right and reality in the European framework.

Portability. Section 35.19. Narrow scope, no format standards, nowhere to send the file.

Your status as a beneficiary of certification. Section 26.15 and section 20.17: named as a beneficiary, no role, no rights, no standing.

Any right at all under the cybersecurity instruments. Section 5.12A records it and it is worth quoting as a finding rather than an omission: you have no rights under any of the three, that is the finding, and it is not a drafting oversight. They protect service continuity and product integrity. An organisation can lawfully report a severe incident to three regulators within 72 hours and tell you nothing, where the data protection threshold is not met.

Anything in the international layer. Section 53.21: no instrument confers a right on you, there is no body to complain to, and there is no forum in which you have standing.

Why this list matters. Not to discourage you. Because effort spent on an unusable right is effort not spent on section 61.16’s routes, which work.

Vol. 39 · §61.26 · Currency 2026-09-03 · drafting

61.27 /

What actually happens, and when

Realistic timelines, so you can plan.

An access request. Acknowledged within days if at all. Answered around the deadline, rarely early. Roughly one month in most jurisdictions; section 16.24 records shorter periods in New Zealand. Expect a partial response and one round of follow-up.

A correction. Fast, often days, and frequently handled outside any formal process. Section 35.12 records that this is the right most likely to be dealt with correctly and without record.

A marketing objection. Should be immediate. If you are still contacted after a reasonable interval, that is a clear, provable contravention and among the easiest complaints to make.

A deletion request. One month, and expect a partial answer per section 61.11.

A platform appeal. Section 5.16A: days to weeks, which is why section 61.16 says to use it first.

A regulator complaint. Months at best. Frequently more than a year. Section 39.3.

Litigation. Years, per section 39.8’s note that investigation, decision, appeal and final resolution routinely span several.

Vol. 39 · §61.27 · Currency 2026-09-03 · drafting

61.28 /

The checklist

Identify the controller, per section 61.5, and send it to the data protection officer if there is one.

Note the date you sent it. Section 61.4.

Ask for the data and the supplementary information, per section 61.8, and name the source specifically.

Be specific about what you actually want, per section 61.4.

Do not pay, and do not fill in a form that demands more than they already hold, per section 61.4.

When the response arrives, check for email, inferences and opinions, per section 61.7, and name any gap specifically rather than calling it inadequate.

If a platform is involved, use the platform route first, per section 61.16.

If you were refused credit or employment in the United States, ask for the principal reasons, per section 61.19.

If they refuse, check the refusal names an exemption, per section 61.21.

If you complain, attach evidence and point at a deadline, per section 61.22.

And check whether you agreed to arbitration, per section 61.24, before assuming litigation is available.

Vol. 39 · §61.28 · Currency 2026-09-03 · drafting

61.29 /

Sources and confidence

This section assembles material already recorded in Volumes 01 to 38 and introduces no new facts. It inherits the confidence of everything it cites.

The one caution that governs the whole handbook. Rights, deadlines and available routes are jurisdiction-specific and dated. Every position here is cited to the Part II or Part III section that researched it, so there is one copy to verify rather than two. Section 40.4, section 40.39, section 51.9, section 45.9, section 43.18, section 48.2 and section 50.2 are all flagged, and where a right in this handbook depends on one of them the citation carries the flag.

The specific items a reader should verify before relying on them. Section 16.13, the Australian automated decision obligation, which commences after this currency date. Section 15.6, Singapore’s portability provision, enacted and not commenced. Section 6.3, the United Kingdom changes to automated decision-making, which section 45.6 records as load-bearing. And every response deadline, which section 35.6 records is jurisdiction-specific and which this handbook deliberately states only approximately.

What this handbook is confident about, because it rests on structure rather than on current text. That you are visible at two points in the lifecycle and absent everywhere else, at section 61.3. That destruction is unverifiable by you and that you will learn it failed only when a breach has already harmed you, at section 61.12. That a nominal reviewer defeats the automated decision right, at section 61.15. That the platform routes are faster and more usable than the data protection routes, at section 61.16. That the access log is the only right in this document that lets you detect misuse rather than request data, at section 61.17. That under the AI framework you are closer to a consumer of a regulated product than to a data subject, at section 61.18. And the whole of section 61.25 and section 61.26.

Forward reference. Section 62 is the business handbook, section 63 government, section 64 certifying bodies, section 65 front-line staff and section 66 human rights and advocacy — which section 53.21 hands the standards participation argument, recorded there as the single highest-leverage and least-used item in the advocacy toolkit. Part VII carries no six-lens blocks; section 53.21 was the last in the document.

Vol. 39 · §61.29 · Currency 2026-09-03 · drafting