Article 16
Right to Rectification
GDPR · Regulation (EU) 2016/679 · Last verified August 2026
Objective
Allow inaccurate personal data to be corrected and incomplete data to be completed, taking the processing purpose into account.
Points of focus
- Provide usable correction channels
- Propagate validated corrections to relevant recipients and systems
- Preserve necessary audit context without continuing inaccurate use
Implementation notes
Define authoritative sources for identity fields, publish correction events to downstream systems, and separate immutable audit history from the corrected current state used for decisions. Operationalize provide usable correction channels in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain rectification workflow and completed request samples with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a user edits their profile but stale data remains in crm and support tools Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample rectification workflow and completed request samples with dates and named reviewers. Be ready to walk through how you detect and correct: a user edits their profile but stale data remains in crm and support tools
Evidence auditors typically request:
- Rectification workflow and completed request samples
- Correction propagation logs across processors
- Data-quality rules for authoritative profile fields
Common gaps
- A user edits their profile but stale data remains in CRM and support tools
- An immutable event history is used to justify displaying known inaccurate current data
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| GDPR | Article 16 | This control |
| SOC 2 | CC3.2, CC6.1 | Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness. |
| ISO 27001 | A.5.34, A.8.10 | ISO privacy and security controls can implement parts of this duty when mapped to processing. |
| HIPAA | 164.308(a)(1) | HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data. |
Primary sources
- EUR-Lex GDPR Article 16: Regulation (EU) 2016/679, Article 16 — Right to Rectification