GDPR: access, erasure and rectification

Under the GDPR you have the right to access, correct, erase and port your personal data. Insyna helps you write a correct request to the authority or company and keeps track of the legal deadline for their reply.

Legal basis
GDPR Article 15 (right of access) · GDPR Article 16 (right to rectification) · GDPR Article 17 (right to erasure) · GDPR Article 20 (data portability) · General Data Protection Regulation (EU) 2016/679
Response time
1 month (extendable to 3 months for complex requests)
Contact
Data protection officer or customer service

Your rights under the GDPR

A subject access request (Article 15) gives you a copy of all the personal data an organisation holds about you, plus information on where it came from, how long it is kept and who has had access to it. You also have the right to correct inaccurate data (Article 16), in some cases have data erased — for example when it is no longer needed or you withdraw your consent (Article 17) — and receive your data in a machine-readable format (Article 20).

The organisation normally has one month to respond, a deadline that can be extended to three months for particularly complex requests. The first request is free.

Authorities versus companies

A company must erase your data once there is no longer a legitimate reason to keep processing it — for example an ongoing contract or a requirement under the Bookkeeping Act. Authorities, on the other hand, often have a duty under the Archives Act to preserve official documents, and can refuse erasure on that basis. If you are refused, you have the right to a written justification.

Chydenius drafts your request with the correct article references and sends it to the organisation’s data protection officer or customer service. If you receive a refusal, Insyna helps you ask for a justification or turn to the Swedish Authority for Privacy Protection (IMY).

How to do it, step by step

  1. Describe your request

    Tell Chydenius whether you want a copy of your data (art. 15), rectification (art. 16), erasure (art. 17) or portability (art. 20) — and from which authority or company.

  2. We write the request

    Chydenius drafts a correct request citing the right articles and sends it to the organisation’s data protection officer or support.

  3. Wait for the response

    The organisation normally has one month to respond. Your first request is free of charge.

  4. Follow up if needed

    If no reply arrives or the request is refused, Chydenius helps you send a reminder or escalate to the Swedish Authority for Privacy Protection (IMY).

What you can request

  • Your own personal data that the organisation has recorded
  • Information about where the data was collected from
  • Information about how long the data is kept
  • Information about who has accessed your data
  • Erasure of data no longer needed for its original purpose
  • Erasure when you withdraw consent
  • Erasure in the case of unlawful processing
  • Correction of inaccurate data
  • A copy of your data in a structured format (portability)
  • That the organisation stops processing your data for direct marketing

What you cannot request

  • Erasure of data the authority must keep under the Archives Act
  • Erasure that would obstruct freedom of expression or information
  • Erasure of data needed for legal claims
  • Other people’s personal data
  • Anonymised or aggregated statistics
  • Data covered by statutory confidentiality

Frequently asked questions

What does a subject access request cost?

Your first request for a copy of your data is free. An organisation may only charge a reasonable fee if the request is manifestly unfounded or excessively repetitive.

Can an authority refuse to erase my data?

Yes. Authorities often have a statutory duty under the Archives Act to preserve documents, and can refuse erasure on that basis. Companies usually lack the same duty, but can still refuse if there is another legal basis for processing the data, such as an ongoing contract or the Bookkeeping Act.

How long do they have to respond?

Normally one month from receiving the request. For complex or numerous requests the deadline can be extended to three months, but you must be told about the extension within the first month.

Do I need to explain why I want my data?

No. A subject access request under Article 15 does not require you to give a reason. You are entitled to a copy of your data simply by asking for it.

What can I do if an organisation ignores my request?

If you get no response within the deadline, you can send a follow-up referencing the original request and the GDPR deadline, and ultimately file a complaint with the Swedish Authority for Privacy Protection (IMY), which can investigate and order compliance.

The email we send

This is the actual email Chydenius writes and sends to the authority for you — in correct Swedish, anonymously (never in your name), always asking for a reply by email. You don’t need to write Swedish yourself.

Bästa Handläggare,

Jag begär ett registerutdrag enligt artikel 15 i dataskyddsförordningen (GDPR) över samtliga personuppgifter som ni behandlar om mig. Jag önskar även information om ändamålen med behandlingen, varifrån uppgifterna kommer, hur länge de sparas och vilka som har tagit del av dem.

Enligt artikel 12.3 i GDPR ska svar lämnas utan onödigt dröjsmål och senast inom en månad.

Jag önskar ta del av uppgifterna digitalt (via e-post) i första hand.

I avvaktan på Ert svar,
En Medborgare

Ready to create your case?

Let the AI assistant Chydenius write a professional letter for you. Anonymous and free.

More guides