Skip to main content
European Commission logo
European Commission
Protecting your data and privacy

Your data matters

Know your rights

  • Know what data is held about you

    You can ask any organisation what personal data they hold about you, why they have it, and how they are using it. They must respond within one month, free of charge. 

  • Have your data corrected

    If an organisation holds inaccurate or incomplete information about you, you have the right to ask them to rectify it. 

  • Ask for your data to be deleted

    You can ask for your data to be erased, when it is no longer needed, or if you decide that you no longer want it to be used. This is called the ‘right to be forgotten’.

  • Say no to certain uses

    You have the right to object to how your data is being used - for example, for direct marketing purposes. If you object, the organisation must stop using it for that purpose. 

  • Take your data with you

    If you switch from one service to another, you can ask for your personal data to be transferred directly to the new provider. You should never feel locked in. 

  • Find out if something goes wrong

    If your personal data is lost, stolen or accessed without authorisation, the organisation responsible for your data must inform you directly. 

How to take action

If you think your personal data is incorrect, being used in a way you don’t agree with, or handled unfairly, you can take action.

📧Contact the organisation

Get in touch with the company or organisation that holds your data and explain what you want to access, correct, delete, or object to. You can usually do this by email or through an online form, and you don’t need to use legal language. They must respond within one month.

🌍Contact your national data protection authority

Not satisfied? If the organisation does not respond, or you are unhappy with their response, you can escalate to your national data protection authority, which helps ensure that data protection rules are properly applied across the EU.

The EU: home to the world’s strongest data protection rules

Since 2018, the General Data Protection Regulation (GPDR), the world’s strongest data protection law, guarantees your rights

  • The GDPR applies to any organisation that handles your personal data, whether public or private, large or small.
  • If a company offers goods or services to people in the EU, the GDPR covers how it handles their data. And these rules do not stop at EU borders. If your data travels beyond Europe, the EU makes sure the same high standards of protection follow it.

In the EU there are also laws to protect your privacy online

  • These laws keep your conversations private, give you control over cookies, and allow you to opt out of unwanted marketing messages.

Take control

While your rights are your strongest protection, there are also everyday steps you can take to keep your personal data safe. 

🔐 Use strong, unique passwords

Use a different password for each of your online accounts, and make them hard to guess. A password manager can help you keep track.

🤔 Think twice before you share

Once personal information is online, it can be difficult to remove. Before sharing details about yourself or others, consider who might see them and how they could be used.

🎣 Stay alert to scams

Fraudulent emails and messages often try to trick you into giving away personal information. If something feels unexpected - an unfamiliar sender, an urgent request, a suspicious link - do not click.

🧐 Read before agreeing

When a website or app asks for your consent to use your data, take a moment to understand what you are agreeing to. Some services may appear free at first glance, but they might monetise your data instead of asking for a subscription fee. 

⚙️ Review your privacy settings

Most apps and social media platforms let you control who can see your information and how it is used. Take a few minutes to check - the default settings are not always in your best interests.

⚠️ Watch out for dark patterns

Some websites use deceptive design tricks to push you into accepting cookies: hiding the reject button, making acceptance one-click while rejection takes several steps, or using misleading wording like ‘By using this site you agree…’. Under EU rules, saying no should be just as easy as saying yes.

👋 Unsubscribe

Every marketing email you receive uses your personal data. Had enough? Open one and look for ‘unsubscribe’, ‘manage preferences’, ‘opt out’: under EU rules this option must always be present.

This page was last updated on 16 July 2026