Skip to main content
The state of ai impact assessment
Category: Consumer Privacy Rights

Right to Correct

Also known as: Right to Rectification, Right to Correction
Simply put

The right to correct allows individuals to have inaccurate personal information about them fixed, and in some cases to have incomplete information completed. In the EU and UK this right is known as the right to rectification, while in the United States several state privacy laws use the term right to correct. The organization holding the data is generally responsible for making the correction once a valid request is received.

Formal definition

The right to correct (referred to as the right to rectification under the EU GDPR and UK GDPR) is a data subject or consumer right permitting individuals to require a controller or business to correct inaccurate personal data concerning them, and, in the EU/UK context, to have incomplete data completed. Under Articles 16 and 19 of the GDPR, controllers must rectify inaccurate personal data without undue delay, and Article 19 imposes related obligations to communicate rectification to recipients where feasible. In the United States, comparable rights arise under state privacy laws; for example, Section 1798.106 of the California Privacy Rights Act (CPRA) gives consumers the right to correct inaccurate personal information, and similar correction rights appear in other state statutes (such as the Virginia VCDPA, Colorado CPA, Connecticut CTDPA, and Utah UCPA, among others). Scope, procedural requirements, applicable exceptions, and verification standards vary by jurisdiction and statute; the precise obligations depend on the governing legal regime and are not uniform across the EU, UK, and individual U.S. states. This right concerns the accuracy of personal data generally and is distinct from, though it may interact with, cookie- and tracking-related consent obligations. The specific implementation details and enforcement positions of individual U.S. state laws beyond the CPRA are outside the scope of the cited evidence.

Why it matters

The right to correct addresses a foundational data protection principle: personal data held about an individual should be accurate. Inaccurate information can lead to flawed decisions, misdirected communications, or reputational and financial harm to the individual, which is why both EU/UK and several U.S. frameworks provide a mechanism for individuals to have errors fixed. For organizations, honoring this right is not merely a courtesy but a legal obligation under the applicable regime, and failing to act on valid requests can expose the organization to regulatory scrutiny.

The practical significance varies by jurisdiction. Under the EU GDPR and UK GDPR, Articles 16 and 19 require controllers to rectify inaccurate personal data without undue delay and, where feasible, to communicate that rectification to recipients of the data. In the United States, comparable rights have emerged through state privacy laws: Section 1798.106 of the California Privacy Rights Act (CPRA) gives consumers the right to correct inaccurate personal information, and correction rights also appear in other state statutes such as the Virginia VCDPA, Colorado CPA, Connecticut CTDPA, and Utah UCPA, among others. Because scope, procedural requirements, exceptions, and verification standards differ across these regimes, organizations operating across borders generally cannot rely on a single uniform process.

For teams working with cookie consent and tracking technologies, it is worth noting that the right to correct concerns the accuracy of personal data generally and is distinct from consent obligations governing cookies and similar technologies. It may nonetheless interact with those obligations where personal data collected through tracking is inaccurate. The precise obligations depend on the governing legal regime, and the detailed implementation and enforcement positions of individual U.S. state laws beyond the CPRA are not addressed here.

Who it's relevant to

Privacy officers and data protection professionals
These professionals are typically responsible for designing and operating the request-handling processes that make the right to correct actionable. They must account for differing standards across the EU/UK right to rectification and U.S. state correction rights, including verification, exceptions, and timelines, and ensure records are updated and, where required under Article 19 of the GDPR, that recipients are informed.
Legal counsel and compliance teams
Legal and compliance teams interpret how correction obligations apply under each governing regime, from Articles 16 and 19 of the GDPR to Section 1798.106 of the CPRA and comparable provisions in the Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, and other state laws. Because scope and exceptions are not uniform, their judgment is needed to determine what a valid request requires in a given jurisdiction.
Web developers and data engineers
Developers and engineers implement the technical means to locate, update, and propagate corrections across systems. Where personal data collected through cookies, pixels, or similar technologies is inaccurate, they may need to reflect corrections in the relevant data stores, keeping in mind that the right to correct is distinct from the consent obligations governing those tracking technologies.
Marketing and analytics teams
Teams that rely on customer and prospect data have a direct interest in accuracy, since inaccurate records can misdirect communications and undermine analytics. They should understand that individuals may request corrections and that the applicable obligations differ between the EU/UK and individual U.S. states.

Inside Right to Correct

Right to Correct (Right to Rectification)
A data subject or consumer right that generally allows individuals to request that a controller or business correct inaccurate personal data held about them, and in some regimes complete data that is incomplete. Under the GDPR this is framed as the right to rectification; under several U.S. state privacy laws it is framed as a right to correct.
Scope under the GDPR
In the EU (and, in substantially similar form, the UK GDPR), the right to rectification applies to inaccurate personal data and may include completing incomplete data, taking into account the purposes of the processing. It applies broadly across processing activities, subject to certain conditions and exceptions.
Scope under U.S. state privacy laws
Several U.S. state comprehensive privacy laws include a right to correct inaccurate personal data, including California (CPRA amendments to the CCPA), Virginia (VCDPA), Colorado (CPA), and Connecticut (CTDPA), among others. Coverage, thresholds, and the exact wording vary by state; some earlier or narrower state frameworks (for example Utah's UCPA) have historically not provided the same correction right, so the scope must be checked against the specific statute rather than assumed to be uniform.
Relationship to cookie and tracking data
The right may extend to personal data collected through cookies, pixels, SDKs, local storage, or similar technologies where that data is personal data and is inaccurate. However, its practical relevance depends on whether the tracking data is identifiable and correctable; much cookie-derived data is inferred or pseudonymous, which can affect how correction requests are handled.
Verification and identity confirmation
Businesses and controllers generally need to verify the identity of the requester before acting on a correction request, and the accuracy of the corrected data may itself need to be assessed. The standard and process for verification differ between the GDPR and individual U.S. state laws.
Limitations and exceptions
The right is not absolute. It may be limited by the purposes of processing, competing legal obligations, the feasibility of confirming accuracy, and statutory exemptions that vary by jurisdiction. Whether a given request must be honored depends on facts and the applicable legal regime.

Common questions

Answers to the questions practitioners most commonly ask about Right to Correct.

Does the right to correct apply to cookie consent choices or the tracking data collected through cookies?
These are distinct concepts that are often confused. The right to correct is a data subject or consumer right to have inaccurate personal data rectified, and it applies to personal data a business holds about an individual. It is not primarily a cookie-consent mechanism. A user's consent choices are handled through consent withdrawal, opt-out signals, and preference management rather than a correction request. That said, where cookies or similar technologies (pixels, SDKs, local storage, fingerprinting) generate inferences or profile attributes about a person, those inferred data points may in some jurisdictions fall within the scope of correction rights. Whether inferences must be corrected is an area where interpretations differ, so this should be assessed case by case.
Is the right to correct a GDPR-style right that exists uniformly wherever cookies are regulated?
No. The right to rectification under the GDPR (in the EU) and the equivalent right under UK data protection law are longstanding, but a right to correct is not universal across all privacy regimes and should not be presented as such. In the United States, correction rights depend on the specific state law: California's CPRA introduced a right to correct inaccurate personal information, and several other state laws, such as Virginia's VCDPA, Colorado's CPA, and Connecticut's CTDPA, also include correction rights, while some frameworks such as Utah's UCPA have historically not provided one. The precise scope, exceptions, and procedures vary by jurisdiction, so the applicable law must be identified before assuming the right applies.
How should we handle a correction request that concerns data derived from cookies or tracking technologies?
Begin by identifying what personal data your cookie and tracking systems actually hold about the individual, which may include profile attributes, inferences, or identifiers stored in first-party or vendor systems. Determine whether the data at issue is factual data capable of being verified and corrected, or an inference where correction is more contested. Confirm which jurisdiction's rules apply, since scope and exceptions differ across the EU, UK, and individual US states. Where the data is genuinely inaccurate and within scope, update it in your own records and consider whether you are obliged to notify processors, vendors, or third parties to whom the data was disclosed. This entry does not resolve the open question of whether inferences must be corrected, which may depend on facts and evolving guidance.
What steps are involved in verifying the identity of someone making a correction request?
Correction rights generally require you to authenticate the requester to a reasonable degree before altering data, because incorrectly changing records based on an unverified request can itself create risk. The appropriate verification standard typically depends on the sensitivity of the data and the applicable law, and some frameworks address verification requirements explicitly. Avoid collecting more identifying information than necessary for verification. Where a request comes through an authorized agent, additional checks on the agent's authority may be required in certain US state regimes. The specific verification thresholds are not fixed by this entry and should be set with reference to your governing law and any relevant regulatory guidance.
Do we need to pass corrections on to vendors or third parties that received the data via cookies?
In many regimes, when you correct personal data you may be required to take reasonable steps to inform third parties or processors to whom you previously disclosed that data, so they can update their records as well. In the cookie and adtech context, this can be operationally complex because data may have flowed to numerous vendors, SDK providers, or advertising partners. The extent of this notification obligation, and any exceptions for disproportionate effort, differs by jurisdiction. You should map your data-sharing relationships in advance so that a correction can be propagated where the law requires it, while recognizing that the exact obligation depends on the applicable framework and the facts.
What records should we keep to demonstrate we handled correction requests properly?
Maintaining a log of correction requests, including the date received, the identity verification performed, the action taken or the basis for any refusal, and the response timeframe, supports accountability and helps demonstrate compliance if a data protection authority or state regulator inquires. Applicable laws often set response deadlines and permit refusal or partial action in defined circumstances, so recording the reasoning behind each decision is prudent. Record-keeping tools and consent management platforms can assist with this, but they support compliance rather than guarantee it, and legal judgment remains necessary to determine what a given request requires under the relevant jurisdiction.

Common misconceptions

The right to correct is a single, uniform right that works the same everywhere.
The right varies by jurisdiction. Under the EU and UK GDPR it exists as the right to rectification, while in the United States it is provided under several state laws such as California's CPRA, Virginia's VCDPA, Colorado's CPA, and Connecticut's CTDPA, with differing thresholds and wording. Some state frameworks have not provided an equivalent right, so scope should always be checked against the specific statute.
Correcting personal data is only relevant to account or form data, not to cookies or tracking technologies.
Where cookies, pixels, SDKs, or similar technologies collect personal data that is inaccurate, the right may in principle apply. In practice its relevance depends on whether the data is identifiable and correctable, since much cookie-derived data is inferred or pseudonymous, which can affect how a request is handled.
A business must always change any data a person asks to have corrected.
The right is not absolute. Controllers and businesses generally need to verify identity and may need to assess the accuracy of the requested correction, and the right can be limited by the purposes of processing, legal obligations, and jurisdiction-specific exceptions.

Best practices

Map the correction right against each jurisdiction you operate in, distinguishing the GDPR/UK GDPR right to rectification from U.S. state rights to correct (for example CPRA, VCDPA, CPA, and CTDPA), and confirm whether a given state law provides the right at all before relying on a single global process.
Establish a documented identity verification process appropriate to each applicable regime before acting on correction requests, and record how each request was assessed and resolved to support your record-keeping obligations.
Assess whether personal data collected through cookies, pixels, SDKs, or local storage is identifiable and correctable, and define how correction requests touching such data will be handled given that much of it may be inferred or pseudonymous.
Define and document the limitations and exceptions your organization will apply, since the right is not absolute and may be constrained by the purposes of processing, legal obligations, and jurisdiction-specific carve-outs.
Use consent and preference management tooling to support correction workflows, but treat these tools as aids rather than a guarantee of compliance, and retain legal review for contested or fact-dependent requests.
Monitor evolving data protection authority guidance and state law developments, as the scope and enforcement expectations around correction rights differ by jurisdiction and continue to change.
Application Security Isn’t Optional Anymore.