CHAPTER III — RIGHTS OF THE DATA SUBJECT
Article 16 — Right to rectification
Official text
The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
Commentary
1. Introduction
Article 16 of the General Data Protection Regulation (GDPR) establishes one of the most fundamental rights available to data subjects, the right to rectification. It provides that every individual has the right to obtain from the controller, without undue delay, the correction of inaccurate personal data concerning them. It further grants the right to have incomplete personal data completed, including through the submission of a supplementary statement.
Although Article 16 consists of only two concise sentences, its legal significance extends far beyond its textual brevity. The provision embodies the principle that personal data should faithfully represent reality. In a digital society where personal data forms the basis for employment decisions, credit assessments, healthcare treatment, government benefits, law enforcement activities, education, insurance underwriting, and automated decision-making, even a minor factual error may produce profound legal, economic, and social consequences.
The right to rectification therefore performs a corrective function within the GDPR's framework of data subject rights. Unlike the right of access under Article 15, which enables individuals to discover what personal data is being processed, Article 16 empowers them to ensure that such data is accurate, complete, and capable of supporting fair decision-making. Together, these rights reinforce the overarching objective of the GDPR, placing individuals in meaningful control over information concerning them.
The importance of Article 16 is also reflected in Article 8(2) of the Charter of Fundamental Rights of the European Union (CFR), which expressly guarantees that every person has the right to access personal data concerning them and to have it rectified. Consequently, rectification is not merely a procedural entitlement created by secondary legislation but constitutes afundamental right recognised under European constitutional law.
2. Legislative Framework and Purpose
Article 16 provides:
"The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement."
Despite its concise wording, the provision establishes two distinct but closely related rights:
-
the right to rectify inaccurate personal data; and
-
the right to complete incomplete personal data.
Both rights pursue a common objective: ensuring that the information used to make decisions about individuals corresponds as closely as possible to reality.
The provision must not be interpreted in isolation. Rather, it forms part of a broader legal architecture comprising:
-
Article 5(1)(d) (Principle of Accuracy);
-
Article 12 (Modalities for exercising data subject rights);
-
Article 15 (Right of Access);
-
Article 18 (Right to Restriction of Processing);
-
Article 19 (Notification of rectification or erasure to recipients);
-
Article 23 (Restrictions upon data subject rights where justified).
Accordingly, Article 16 is simultaneously an independent individual right and an operational mechanism through which controllers fulfil their broader obligation to maintain accurate personal data.
3. Relationship with the Principle of Accuracy (Article 5(1)(d))
The right to rectification derives much of its practical significance from the principle of accuracy contained in Article 5(1)(d), which requires personal data to be:
-
accurate;
-
kept up to date where necessary; and
-
corrected or erased without delay whenever inaccuracies are discovered.
This relationship is central to understanding Article 16.
Article 5 imposes an affirmative obligation upon controllers. Controllers must proactively take reasonable steps to maintain accurate records, even if no data subject submits a request. Their compliance with the GDPR therefore does not depend solely upon reacting to complaints.
Article 16, by contrast, creates an individual enforcement mechanism. It enables the data subject to intervene whenever the controller has failed to fulfil the broader obligation imposed by Article 5.
Thus, the two provisions complement one another.
Article 5 answers the question:
What standard must controllers maintain?
Article 16 answers:
How can individuals enforce that standard?
This interaction ensures that data quality remains a continuous legal obligation rather than merely an administrative aspiration.
4. Accuracy as a Foundation of Fair Processing
Accuracy is not simply a technical requirement.
Rather, it constitutes one of the essential conditions for lawful and fair processing.
Recital 39 emphasises that every reasonable step should be taken to ensure inaccurate personal data is rectified or deleted. The recital links accuracy with several foundational GDPR principles, including:
-
fairness;
-
transparency;
-
data minimisation;
-
storage limitation; and
-
integrity and confidentiality.
Inaccurate information undermines each of these principles.
For example:
-
an incorrect home address may result in confidential documents being delivered to another individual;
-
an incorrect criminal record may prevent employment;
-
inaccurate medical information may lead to dangerous treatment decisions;
-
outdated financial information may wrongly affect creditworthiness;
-
inaccurate immigration records may interfere with travel or residence rights.
Thus, maintaining accurate personal data protects not only informational privacy but also numerous other fundamental rights, including dignity, equality, employment opportunities, healthcare, and freedom of movement.
5. Why the Right to Rectification Matters
Modern organisations increasingly rely upon automated systems that continuously reuse existing personal data.
Once inaccurate information enters a database, it often spreads rapidly across multiple systems through:
-
automated synchronisation,
-
cloud storage,
-
internal databases,
-
external processors,
-
government information exchanges,
-
marketing platforms,
-
financial institutions.
This phenomenon is sometimes described as the "snowball effect" of inaccurate data.
A single incorrect entry may therefore influence hundreds or even thousands of subsequent decisions.
Examples
include:
- rejection of loan applications;
- denial of insurance coverage;
- incorrect tax assessments;
- mistaken police investigations;
- wrongful immigration alerts;
- inaccurate employment evaluations;
- improper academic records. The right to rectification interrupts this cycle by allowing individuals to demand that inaccurate information be corrected before it continues producing harmful consequences. Consequently, Article 16 serves not merely an informational purpose but also an important preventive function.
6. Rectification as an Expression of Informational Self-Determination
European data protection law increasingly recognises that individuals should possess meaningful control over information concerning them.
Article 16 contributes directly to this objective.
Without the ability to correct inaccurate information, access rights would possess only limited practical value.
Knowing that incorrect information exists does little to protect an individual unless they also possess the legal ability to require its correction.
Accordingly, Article 16 transforms passive transparency into active control.
The Court of Justice of the European Union has recognised that Article 16 gives concrete expression to Article 8(2) CFR.
In C-247/23 (Deldits), the Court observed that Article 16 specifically implements the Charter's guarantee that every individual enjoys both:
-
access to personal data; and
-
the right to have inaccurate personal data rectified.
Thus, rectification represents an essential component of informational self-determination within European constitutional law.
7. Scope of the Right
Article 16 applies whenever three conditions exist.
(a) Personal data
Only information qualifying as personal data under Article 4(1) GDPR falls within the scope of Article 16.
The information must relate to an identified or identifiable natural person.
Examples
include:
- names;
- addresses;
- identification numbers;
- photographs;
- email addresses;
- employment records;
- educational qualifications;
- medical diagnoses;
- financial information;
- online identifiers. Anonymous information falls outside Article 16 because it is no longer personal data.
(b) Data concerning the data subject
The individual may request rectification only of data concerning themselves.
One person generally cannot request correction of another individual's information.
Nevertheless, where a single record concerns several individuals, for example:
-
family records,
-
joint bank accounts,
-
business partnerships,
each data subject may exercise rights regarding the information relating to them.
(c) Inaccuracy
Most importantly, the personal data must actually be inaccurate or incomplete.
This raises one of the most difficult interpretative questions under Article 16:
When is personal data inaccurate?
The GDPR deliberately refrains from defining "accuracy."
Instead, the assessment depends upon:
-
the purposes of processing;
-
the factual context;
-
the intended use of the data.
The CJEU confirmed in Deldits that accuracy must always be evaluated in light of the purposes for which the personal data was collected and processed.
Consequently, identical information may be accurate for one processing purpose but inaccurate for another.
8. What Constitutes Inaccurate Personal Data?
Determining whether data is inaccurate requires examining whether it truthfully reflects the relevant reality that the processing intends to represent.
Several categories may be distinguished.
(i) Objective factual inaccuracies
These represent the clearest examples.
Examples
include:
- incorrect birth date;
- incorrect passport number;
- incorrect address;
- incorrect salary;
- incorrect employment history;
- wrong nationality;
- incorrect marital status. Such errors can ordinarily be verified through documentary evidence. Controllers are generally expected to correct them promptly.
(ii) Outdated information
Data originally collected correctly may subsequently become inaccurate.
Examples
include:
- new residential address;
- changed surname;
- updated qualifications;
- new telephone number;
- revised immigration status. Controllers must determine whether maintaining outdated information remains compatible with the processing purpose. Where current information is required, outdated records should normally be updated. However, historical information may legitimately remain unchanged where it accurately records past circumstances.
Example
a payroll record correctly showing an employee's salary in 2022 does not become inaccurate merely because the employee received a salary increase in 2024.
Historical accuracy differs from present accuracy.
(iii) Incomplete information
Data may also become misleading because important contextual information has been omitted.
The GDPR recognises that incompleteness may itself produce inaccuracy.
This issue is expressly addressed by the second sentence of Article 16, which will be examined in greater detail in the next part of this commentary.
9. The Right to Complete Incomplete Personal Data
The second sentence of Article 16 expands the scope of the right to rectification by recognising that personal data may be factually correct yet nevertheless incomplete. It provides:
"Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement."
This provision demonstrates that accuracy under the GDPR is not confined to correcting factual errors. Rather, the Regulation adopts a broader understanding whereby personal data must present a sufficiently complete and balanced picture in light of the specific purposes for which it is processed.
Accordingly, incompleteness itself may amount to inaccuracy where the omission of relevant information creates a misleading or distorted representation of reality.
Purpose-Oriented Assessment
Unlike objective factual errors, determining whether personal data is incomplete depends upon the purposes of processing. The same dataset may be adequate for one purpose yet incomplete for another.
For example:
-
A delivery company may only require a customer's name and address to fulfil an order. For this purpose, the dataset may be complete.
-
However, a bank assessing creditworthiness may require significantly more information, including income, liabilities, repayment history and current employment status. Omitting any of these elements could materially affect the assessment and therefore render the data incomplete.
Consequently, completeness cannot be evaluated in the abstract. It must always be assessed in relation to the controller's legitimate processing purposes.
10. Supplementary Statements
One of the most distinctive features of Article 16 is its express recognition that incomplete personal data may be completed "by means of providing a supplementary statement."
This is particularly important because many information systems contain rigid database fields that cannot easily accommodate contextual explanations.
The GDPR therefore allows the data subject to supplement existing records by adding explanatory information.
This mechanism prevents controllers from arguing that a database cannot technically accommodate additional context.
For example:
Example 1
Credit Records A credit reporting agency records that an individual failed to pay an invoice. Although the statement is factually correct, it omits the fact that:
- the invoice was disputed because defective goods had been delivered;
- litigation concerning the debt remains pending. Without this context, the record presents an incomplete picture that could unjustifiably affect future lending decisions.
The data subject may therefore request that the record be supplemented with an explanatory statement.
Example 2
Employment Records An employee's personnel file records several months of absence. Standing alone, this information may suggest poor attendance. However, the absences resulted from approved maternity leave or medical leave protected by law. The employee may request that this contextual information be added so that future evaluations are based upon complete information.
Example 3
Academic Records A university transcript records that a student repeated a semester. Without additional context, this may appear academically negative. However, the repetition occurred because the student participated in an officially recognised international exchange programme. A supplementary statement ensures that future readers correctly interpret the academic record. The possibility of submitting supplementary statements reflects one of the GDPR's central objectives:ensuring that personal data accurately represents reality rather than presenting isolated facts capable of misleading subsequent decision-makers.
11. Exercising the Right to Rectification
Unlike the controller's proactive obligations under Article 5(1)(d), Article 16 is generally exercised upon request by the data subject.
The individual must communicate the request to the controller using one of the communication methods provided under Article 12.
The GDPR deliberately avoids imposing formal requirements.
Accordingly, the request:
-
need not refer expressly to Article 16;
-
need not use technical legal language;
-
need not follow any prescribed form;
-
may generally be submitted electronically or in writing.
Any communication clearly indicating that personal data is inaccurate and requesting correction should ordinarily be treated as a valid Article 16 request.
12. Must the Data Subject Provide Evidence?
One practical issue concerns the burden of proving that personal data is inaccurate.
Article 16 itself does not expressly regulate this question.
However, the Court of Justice addressed the matter in Case C-247/23, Deldits.
The Court held that a controller may require the data subject to provide relevant and sufficient evidence where this is reasonably necessary to establish the alleged inaccuracy.
Importantly, this does not impose an excessive evidentiary burden.
Rather, the controller may only request documentation reasonably appropriate in the circumstances.
For example:
A request to correct:
-
a spelling mistake may require no evidence at all;
-
an incorrect date of birth may require production of an identity document;
-
an incorrect academic qualification may require educational certificates;
-
an incorrect address may require recent proof of residence.
The proportionality principle governs these evidentiary requirements.
Controllers cannot insist upon excessive documentation where the correction is straightforward or where the controller already possesses reliable evidence.
13. What if Accuracy Cannot Be Determined?
Some rectification requests concern disputed facts rather than objectively verifiable information.
Examples
include:
- disputed allegations;
- contested disciplinary findings;
- conflicting witness statements;
- disputed contractual obligations. Here the controller may be unable to determine with certainty which version of events is objectively correct. Legal scholars have debated how Article 16 applies in such situations. One influential view argues that, because Article 5 requires controllers to demonstrate compliance with the principle of accuracy, uncertainty should generally operate against the controller. Where significant doubts remain regarding accuracy, the controller should consider:
- correcting the record;
- deleting disputed information;
- restricting processing under Article 18;
- recording that the information remains disputed. Such approaches minimise the risk that uncertain or misleading information will continue influencing decisions.
14. No Need to Demonstrate Damage
Another important feature of Article 16 is that the data subject need not prove actual harm.
The right exists independently of whether the inaccurate data has already caused measurable damage.
Example
an individual may request correction of:
-
an incorrect telephone number;
-
an outdated address;
-
an inaccurate job title;
-
an incorrect educational qualification,
even where no adverse consequences have yet occurred.
The GDPR recognises that preventing future harm is preferable to compensating harm after it has already materialised.
15. "Without Undue Delay"
Article 16 requires controllers to rectify inaccurate data "without undue delay."
This expression reflects the potentially serious consequences that inaccurate personal data may produce.
Every day during which incorrect information remains in circulation increases the possibility that further decisions will rely upon inaccurate data.
Nevertheless, Article 16 must be read together with Article 12(3), which establishes the procedural framework governing all data subject rights.
Accordingly, controllers must:
-
respond without undue delay; and
-
in any event within one month after receiving the request.
Where necessary because of complexity or multiple requests, this period may be extended by two additional months.
However, the controller must inform the data subject within the original one-month period of:
-
the extension;
-
the reasons for it.
Thus, the maximum response period generally becomes three months, although routine rectification requests should normally be resolved considerably sooner.
16. Restriction of Processing During Verification
Rectification requests often require investigation.
The controller may need to:
-
verify documentation;
-
contact third parties;
-
review archived records;
-
consult internal departments.
During this period, continuing to process disputed information may expose the data subject to further harm.
Article 18(1)(a) addresses this concern by allowing the data subject to request restriction of processing while the controller verifies the contested data.
This creates an important procedural safeguard.
Rather than allowing potentially inaccurate information to continue influencing decisions, the controller temporarily suspends most processing activities until the dispute has been resolved.
This mechanism illustrates how different GDPR rights operate together to provide comprehensive protection.
17. Consequences of Rectification
Once inaccurate data has been corrected, the controller's obligations do not end.
Article 19 GDPR requires the controller to communicate the rectification to every recipient to whom the personal data has previously been disclosed, unless doing so proves impossible or involves disproportionate effort.
This obligation is crucial because inaccurate information often exists simultaneously across numerous organisations.
For example:
-
payroll providers;
-
insurers;
-
banks;
-
cloud service providers;
-
government authorities;
-
affiliated companies.
If only the controller corrected its own database, inaccurate copies held elsewhere could continue producing adverse consequences.
Article 19 therefore extends the practical effectiveness of Article 16 by helping ensure that corrected information propagates throughout the processing chain.
Moreover, if requested, the controller must inform the data subject of those recipients.
This strengthens transparency and enables individuals to monitor whether rectification has been effectively implemented.
18. Refusal of a Rectification Request
Controllers are not obliged automatically to accept every rectification request.
Where the controller concludes that:
-
the personal data is already accurate;
-
the requested amendment lacks sufficient evidence;
-
the request is manifestly unfounded or excessive under Article 12(5);
the request may be refused.
However, Article 12(4) imposes strict procedural obligations.
The controller must inform the data subject:
-
that the request has been refused;
-
the reasons for refusal;
-
the right to lodge a complaint with the supervisory authority;
-
the right to seek an effective judicial remedy.
Thus, refusals must be reasoned, transparent and subject to independent review.
19. Objective Facts, Opinions and Value Judgments
The application of Article 16 becomes more difficult where the personal data being processed is not a straightforward factual statement. Modern data processing frequently involves opinions, assessments, predictions, evaluations and inferences. The right to rectification cannot mean that a data subject is entitled to compel a controller to replace every unfavourable assessment with one that the data subject considers preferable. At the same time, controllers cannot avoid Article 16 merely by describing objectively erroneous information as an “opinion”.
The crucial question is therefore whether the information is capable of being assessed for accuracy in light of the purpose for which it is processed.
A useful distinction may be drawn between objective facts, predictions or assessments based on factual information, and purely subjective value judgments.
19.1 Objective Facts
Objective factual information is the clearest category of data to which Article 16 applies.
Examples
include:
- date of birth;
- residential address;
- passport number;
- employment dates;
- salary;
- academic qualification;
- bank account number;
- marital status;
- nationality. If a controller records that an individual was born on 12 January 1990 when the correct date is 12 January 1991, the information is objectively inaccurate. The data subject can request its correction. Similarly, if an individual's address has changed and the controller continues to use the former address for a purpose requiring current information, rectification may be required. The principle is straightforward: where a factual statement does not correspond with reality, the data subject should ordinarily be able to have it corrected.
19.2 Predictions, Assessments and Inferences
The position becomes considerably more complicated where a controller processes information generated through prediction or assessment.
Examples
include:
- credit scores;
- fraud-risk scores;
- insurance risk classifications;
- employee-performance assessments;
- algorithmic risk assessments;
- estimated income;
- predicted purchasing behaviour. Such information may not represent an objectively observable fact. Nevertheless, it may still be subject to Article 16 where its purported accuracy can meaningfully be assessed.
Example
suppose a bank's system assigns a person a low credit score because its database incorrectly associates that person's financial history with another individual. The resulting assessment cannot simply be defended as an “opinion”. Its underlying factual basis is objectively erroneous.
The same principle may apply where an algorithm generates an inference from incorrect personal data. If the controller's system identifies an individual as having a particular financial liability because it has confused that individual with another person, the resulting personal data is fundamentally defective.
Article 16 therefore cannot be circumvented merely because inaccurate information has been generated by an algorithm.
20. Value Judgments and Opinions
Pure value judgments present a different problem.
A statement such as:
“The employee has poor leadership skills”
may involve a subjective assessment rather than an objectively verifiable fact.
Likewise, statements such as:
-
“the applicant is charismatic”;
-
“the customer is difficult”;
-
“the candidate lacks creativity”;
may represent opinions or professional judgments.
Article 16 should not ordinarily be transformed into a mechanism through which data subjects can require controllers to adopt a particular opinion.
However, describing information as an “opinion” does not automatically take it outside the GDPR's accuracy requirement.
The surrounding factual circumstances remain relevant.
Suppose an examiner writes that a candidate gave an incorrect answer to a particular question. If the candidate's answer was in fact correct, the assessment may contain an objectively verifiable error.
Similarly, if a performance assessment concerns the wrong employee because two personnel records were accidentally mixed, the resulting assessment cannot be protected simply by labelling it an evaluative judgment.
The important distinction is therefore between:
a disagreement with an opinion, which will not necessarily establish inaccuracy, and
an objectively erroneous factual basis for an opinion, which may engage Article 16.
21. The Importance of Nowak
The CJEU's judgment in C-434/16, Nowak is particularly important for understanding personal data consisting of assessments and evaluations.
The case concerned examination scripts and comments made by an examiner. The Court recognised that information contained in an examination script and examiner's comments could constitute personal data.
The broader significance of Nowak is that the concept of personal data is not limited to neutral factual information. Information may remain personal data even where it reflects an assessment or evaluation.
This is important for Article 16 because a controller cannot automatically avoid data-subject rights merely because the information contains an evaluative element.
At the same time, the existence of a right to rectification does not mean that every evaluative judgment must be changed simply because the data subject disagrees with it.
Example
an examiner's assessment that an essay demonstrates weak analytical reasoning may constitute an evaluation. The candidate cannot necessarily invoke Article 16 merely because they believe the assessment was unfair.
However, if the examiner's assessment was based on the wrong examination script, missing pages, incorrectly recorded answers, or another objectively erroneous factual circumstance, rectification may become relevant.
This distinction preserves a necessary balance between individual control over personal data and the legitimate independence of professional or academic judgment.
22. Historical Data and Temporal Accuracy
Another important issue concerns information that was once correct but later became outdated.
Article 16 does not require controllers to rewrite history.
Consider an employee whose salary was €40,000 in 2023 but increased to €50,000 in 2025.
A record stating:
“Employee's salary in 2023: €40,000”
is accurate and should not be changed merely because the employee's current salary is different.
The problem arises when the controller uses or presents the historical information as though it describes the individual's current circumstances.
Accordingly, temporal context is an important component of accuracy.
A historical record should clearly indicate the period to which it relates.
This distinction is particularly important for:
-
employment records;
-
medical histories;
-
financial records;
-
academic records;
-
legal proceedings;
-
insurance records.
An old medical diagnosis may accurately describe the patient's condition at the time it was made, even if the patient's condition subsequently changed. Erasing the historical diagnosis could itself distort reality.
The controller must therefore distinguish between:
historically accurate information andinformation incorrectly presented as current information.
23. Inaccuracy Through Incompleteness
Article 16 expressly recognises that accuracy cannot always be achieved simply by replacing one piece of information with another.
Sometimes the information is technically correct but incomplete in a manner that produces a misleading picture.
Consider a credit record stating:
“Payment refused.”
That statement may be factually correct.
However, suppose the payment was refused because the consumer had disputed the underlying invoice on the ground that the goods supplied were defective.
If the record omits that important context, it may create the misleading impression that the consumer simply refused to pay a legitimate debt.
The appropriate remedy may therefore not be deletion of the original information. Instead, the data subject may request that the record be supplemented with a statement explaining the dispute.
This illustrates why Article 16's second sentence is so important.
The GDPR does not insist that every record be reduced to a single binary proposition of “true” or “false”. It recognises that context can be necessary for truthful representation.
24. The Right to Rectification and Article 15
Article 16 frequently operates together with the right of access under Article 15.
A data subject cannot always identify inaccuracies without first knowing what information a controller holds.
Example
an individual may know that a bank has refused a loan but may not know that its internal database contains:
-
an incorrect address;
-
an incorrect income figure;
-
a payment default attributed to another person;
-
an outdated employment record.
An Article 15 access request may reveal these records.
The individual can then exercise Article 16 to correct them.
Importantly, however, Article 15 is not a mandatory preliminary step.
The GDPR does not establish a hierarchy requiring:
-
access;
-
rectification;
-
restriction;
-
erasure.
A data subject may exercise the appropriate right directly.
Thus, where an individual already knows what information is inaccurate, they can proceed directly under Article 16.
25. Article 16 and the Right to Erasure under Article 17
Article 16 also interacts closely with Article 17.
The two provisions address different remedial objectives.
Article 16
The objective is:
“The data is inaccurate or incomplete; make it accurate or complete.”
Article 17
The objective is:
“The data should no longer be retained or processed; erase it.”
Suppose a company has an incorrect telephone number for a customer.
Rectification is ordinarily appropriate.
But suppose the company has no lawful reason to retain the telephone number at all. Erasure may instead be appropriate.
In some circumstances, the data subject may therefore have a choice between remedies.
This is particularly relevant where the underlying processing itself is unlawful. Correcting unlawfully processed information does not necessarily cure the underlying legal problem.
26. Article 16 and Restriction of Processing under Article 18
Article 18 provides an important temporary safeguard.
Where the data subject disputes the accuracy of personal data, they may request restriction of processing for the period necessary for the controller to verify the accuracy.
This is especially significant where inaccurate information could produce immediate consequences.
Consider a bank processing an individual's credit application.
The individual discovers that the bank's database contains another person's default against their name and submits a rectification request.
If the bank continues processing the disputed information while investigating, the inaccurate record may lead to rejection of the application.
Restriction under Article 18 can therefore function as a protective bridge between the rectification request and its resolution.
Article 16 corrects the underlying information; Article 18 can temporarily prevent disputed information from being used while its accuracy is being examined.
27. Article 19 and Propagation of Rectification
Correcting the controller's own database is not always sufficient.
Personal data may have been disclosed to:
-
processors;
-
service providers;
-
business partners;
-
affiliates;
-
government bodies;
-
credit reference agencies;
-
other recipients.
Article 19 therefore requires the controller, subject to the conditions in that provision, to communicate rectification to recipients to whom the personal data has been disclosed.
This is particularly important in modern interconnected data environments.
Imagine that a company incorrectly records an individual's address and shares it with three external service providers.
Correcting only the company's internal database leaves the inaccurate information in circulation.
Article 19 seeks to prevent this result by creating a notification chain.
The data subject may also request information about the recipients to whom the rectification has been communicated.
28. Refusal of a Rectification Request
Controllers are not required automatically to accept every request.
A request may be refused where, for example:
-
the information is already accurate;
-
the alleged inaccuracy cannot reasonably be established;
-
the requested change would itself create an inaccurate record;
-
the request is manifestly unfounded or excessive within Article 12(5).
However, refusal does not mean that the controller can simply ignore the request.
Under Article 12(4), the controller must communicate the reasons for refusing to act and inform the data subject of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.
The refusal should therefore be:
-
reasoned;
-
transparent;
-
communicated within the applicable timeframe;
-
capable of independent scrutiny.
This procedural protection is essential because otherwise the substantive right under Article 16 could become practically ineffective.
29. Evidentiary Requirements and Proportionality
The Deldits judgment is particularly significant in this respect.
A data subject may be required to provide relevant and sufficient evidence establishing that the information is inaccurate.
But the evidentiary requirement must remain proportionate.
A controller should not demand extensive documentation where the inaccuracy is obvious.
Example
if a controller records “Shubhank” as “Shubhanak”, it would ordinarily be disproportionate to demand extensive documentary evidence merely to correct a simple spelling error where the controller can readily verify the correct information.
By contrast, where a person claims that a complex financial liability does not belong to them, the controller may reasonably require supporting documentation.
The appropriate standard therefore depends upon:
-
the nature of the data;
-
the seriousness of the alleged inaccuracy;
-
the circumstances;
-
the evidence already available to the controller;
-
the consequences of the processing.
This approach reflects the GDPR's broader principle of proportionality.
30. Article 16 in AI and Automated Decision-Making
The importance of Article 16 has increased substantially with the development of artificial intelligence and automated decision-making.
AI systems can process vast quantities of personal data and generate:
-
profiles;
-
classifications;
-
risk scores;
-
predictions;
-
recommendations;
-
behavioural assessments.
Errors in the underlying data can therefore be reproduced at enormous scale.
Example
if an AI-powered recruitment system incorrectly records that an applicant lacks a particular qualification, that error could affect:
-
the candidate's ranking;
-
whether the application is shortlisted;
-
the recommendation produced by the system;
-
the ultimate employment decision.
Similarly, an inaccurate financial record may influence an automated credit assessment.
Article 16 therefore has particular importance where personal data is repeatedly reused by automated systems.
Controllers should have mechanisms capable of identifying and correcting inaccurate source data and ensuring, where appropriate, that corrected information is reflected throughout relevant processing operations.
31. Inferences and AI-Generated Personal Data
A particularly difficult question concerns information that is inferred rather than directly supplied by the data subject.
Example
an AI system may infer that an individual:
-
has a particular income range;
-
is likely to default on a loan;
-
is interested in a particular product;
-
poses a particular fraud risk.
Whether and how such inferred information can be rectified depends upon the nature and purpose of the information.
The crucial point is that the controller should not automatically assume that an algorithmically generated inference is beyond challenge merely because it is probabilistic.
Where the inference is presented as a factual characteristic of the individual, questions of accuracy may arise.
This becomes particularly important when the inference has significant consequences for the data subject.
32. Practical Compliance Framework for Controllers
A controller seeking to comply effectively with Article 16 should establish a structured rectification process.
Step 1: Receive the request
The organisation should have accessible channels through which individuals can submit requests.
Step 2: Verify identity where necessary
Reasonable identity verification may be appropriate to prevent unauthorised changes to personal data.
Step 3: Identify the disputed information
The controller should determine precisely which data is alleged to be inaccurate or incomplete.
Step 4: Assess the purpose of processing
Accuracy must be evaluated in light of the purpose for which the data is processed.
Step 5: Evaluate supporting evidence
The controller may request relevant evidence where reasonably necessary.
Step 6: Consider restriction
Where appropriate, the controller should consider the data subject's Article 18 rights during verification.
Step 7: Correct or complete the data
The correction should be implemented without undue delay.
Step 8: Update connected systems
The organisation should ensure that the corrected information is reflected in relevant databases.
Step 9: Notify recipients
Where Article 19 applies, recipients should be informed of the rectification.
Step 10: Communicate the outcome
The data subject should be informed of the action taken or, where the request is refused, the reasons for refusal and available remedies.
33. Data Governance and Article 16
Article 16 also has implications for broader data governance.
Organisations should not treat rectification as an isolated privacy-team function.
Accuracy should be embedded throughout the data lifecycle:
Collection → Validation → Storage → Use → Sharing → Review → Correction → Deletion
At the collection stage, organisations should seek reliable information.
During storage, they should maintain appropriate update mechanisms.
During processing, they should avoid relying upon outdated or inaccurate records.
When information is shared, they should maintain sufficient records to identify recipients.
When inaccuracies are discovered, they should have mechanisms for propagating corrections.
This lifecycle approach reflects the underlying principle of Article 5(1)(d).
34. The Importance of Accountability
Article 16 should also be considered in light of the GDPR's accountability principle.
A controller should be capable of demonstrating that it has mechanisms for:
-
receiving rectification requests;
-
investigating them;
-
making decisions;
-
recording the reasons for those decisions;
-
implementing corrections;
-
notifying recipients where required.
A controller that repeatedly rejects legitimate rectification requests without adequate investigation may face broader questions regarding its compliance with the accuracy principle.
Similarly, an organisation that accepts corrections but fails to propagate them through its systems may undermine the effectiveness of Articles 16 and 19.