← Security Awareness Hub Luxembourg / EU · Privacy

Your GDPR Rights — And How to Actually Use Them

You have real, enforceable rights over your personal data in the EU. Most people never use them because no one explains the mechanics. Here's how.

GDPR isn't just a cookie banner. It gives you concrete powers over what companies hold about you — and a free authority that enforces them. This page is the practical version: which right, what to write, who to escalate to.

TL;DR
  • You can ask any company what data they hold on you (access), fix it (rectification), delete it (erasure), and stop certain uses (objection).
  • The request is usually free and they must normally respond within one month.
  • You don't need a lawyer or a special form — a clear email is enough.
  • If they ignore you or refuse wrongly, you complain to your data-protection authority. In Luxembourg that's the CNPD.

The rights you'll actually use

  • Right of access (Art. 15): "Send me a copy of all personal data you hold about me, and tell me why you have it and who you share it with."
  • Right to rectification (Art. 16): correct wrong or outdated data.
  • Right to erasure (Art. 17): the "right to be forgotten" — have data deleted where there's no overriding reason to keep it.
  • Right to object (Art. 21): stop processing for direct marketing (this one is near-absolute) or other specific uses.
  • Right to data portability (Art. 20): get your data in a portable format to move elsewhere.
  • Right to restrict (Art. 18): freeze processing while a dispute is sorted out.

How to actually exercise them

  1. Find the controller's contact — usually a privacy@ address or a DPO contact in their privacy policy.
  2. Write plainly. You don't need legal language. State which right, identify yourself enough for them to find your record, and ask for a response within one month.
  3. Keep a copy with the date sent — your clock starts there.
  4. Expect one month. They can extend by two more for complex requests but must tell you and why.
  5. If they go silent or refuse improperly, escalate to the authority (below).

A copy-paste starting point

Subject: Data subject request under the GDPR

I am exercising my right of access under Article 15 GDPR. Please provide a copy of all personal data you hold about me, the purposes of processing, the recipients, and the retention period. My account / reference is […]. Please respond within one month as required.

[Name, contact]

Swap "Article 15 / access" for the right you need.

🇱🇺 In Luxembourg

  • Your supervisory authority is the CNPD (Commission nationale pour la protection des données, cnpd.lu). It handles complaints when a company won't comply.
  • The CNPD provides guidance for individuals as well as professionals — start there before complaining, to frame your case.
  • A complaint to the CNPD is without prejudice to other remedies — you can still pursue the matter in court.
  • If a company suffered a breach exposing your data, they may be required to notify the CNPD within 72 hours and, in higher-risk cases, to notify you.

Red flags that a company is stalling

  • "Use our form only" as a way to slow you down (a clear request by any channel is valid).
  • Charging a fee for a normal first request (usually not allowed).
  • Demanding excessive ID "to verify you" beyond what's reasonable.
  • Silence past one month with no extension notice.

If your data is actively being misused

→ See I've Been Hit — "Someone is impersonating me / using my data."

If you run a company and you're on the receiving end of these requests, handling them correctly is a DORA/GDPR compliance question, not just a courtesy — johlem.net.