Skip to content
compliancebase
GDPRChapter III — Right to Rectification

Article 16

Right to Rectification

GDPR · Regulation (EU) 2016/679 · Last verified August 2026

Objective

Allow inaccurate personal data to be corrected and incomplete data to be completed, taking the processing purpose into account.

Points of focus

  • Provide usable correction channels
  • Propagate validated corrections to relevant recipients and systems
  • Preserve necessary audit context without continuing inaccurate use

Implementation notes

Define authoritative sources for identity fields, publish correction events to downstream systems, and separate immutable audit history from the corrected current state used for decisions. Operationalize provide usable correction channels in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain rectification workflow and completed request samples with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a user edits their profile but stale data remains in crm and support tools Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample rectification workflow and completed request samples with dates and named reviewers. Be ready to walk through how you detect and correct: a user edits their profile but stale data remains in crm and support tools

Evidence auditors typically request:

  • Rectification workflow and completed request samples
  • Correction propagation logs across processors
  • Data-quality rules for authoritative profile fields

Common gaps

  • A user edits their profile but stale data remains in CRM and support tools
  • An immutable event history is used to justify displaying known inaccurate current data

Cross-Framework Mapping

FrameworkRequirementImplementation note
GDPRArticle 16This control
SOC 2CC3.2, CC6.1Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness.
ISO 27001A.5.34, A.8.10ISO privacy and security controls can implement parts of this duty when mapped to processing.
HIPAA164.308(a)(1)HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data.

Primary sources

Frequently Asked Questions

Right to Rectification applies to the systems and commitments in your GDPR scope. Translate the requirement into concrete operating workflows — provide usable correction channels — with evidence stored where auditors and customers can sample it.

Lead with rectification workflow and completed request samples and pair it with correction propagation logs across processors. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because a user edits their profile but stale data remains in crm and support tools Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • GDPRRegulation (EU) 2016/679

Last verified: August 2026 · Primary sources linked above