The UK General Data Protection Regulation gives you specific rights over the personal data that organisations hold about you. Here is what those rights are and how to exercise them with CM Beyer.
Your seven rights
- Right of access — obtain a copy of the data we hold about you. Submit a DSAR.
- Right to rectification — have inaccurate or incomplete data corrected
- Right to erasure — request deletion of your data (the “right to be forgotten”)
- Right to restriction — limit how we process your data while a dispute is resolved
- Right to object — object to processing based on legitimate interests, including direct marketing. If you object to direct marketing, we must stop immediately.
- Right to data portability — receive your data in a structured, machine-readable format (e.g. CSV)
- Right to withdraw consent — where we process data based on your consent, you can withdraw it at any time
How to exercise your rights
Contact privacy@cmbeyer.co.uk specifying which right you want to exercise. We will respond within one calendar month. There is no charge for most requests.
Are these rights absolute?
Not always. Some rights have exceptions — for example, we cannot delete data that we are legally required to keep (tax records must be retained for 7 years under HMRC rules). If a limitation applies, we will explain clearly which exemption we are relying on and why.
Full details are in our Privacy Policy.