Right to Correct
The right to correct allows individuals to have inaccurate personal information about them fixed, and in some cases to have incomplete information completed. In the EU and UK this right is known as the right to rectification, while in the United States several state privacy laws use the term right to correct. The organization holding the data is generally responsible for making the correction once a valid request is received.
The right to correct (referred to as the right to rectification under the EU GDPR and UK GDPR) is a data subject or consumer right permitting individuals to require a controller or business to correct inaccurate personal data concerning them, and, in the EU/UK context, to have incomplete data completed. Under Articles 16 and 19 of the GDPR, controllers must rectify inaccurate personal data without undue delay, and Article 19 imposes related obligations to communicate rectification to recipients where feasible. In the United States, comparable rights arise under state privacy laws; for example, Section 1798.106 of the California Privacy Rights Act (CPRA) gives consumers the right to correct inaccurate personal information, and similar correction rights appear in other state statutes (such as the Virginia VCDPA, Colorado CPA, Connecticut CTDPA, and Utah UCPA, among others). Scope, procedural requirements, applicable exceptions, and verification standards vary by jurisdiction and statute; the precise obligations depend on the governing legal regime and are not uniform across the EU, UK, and individual U.S. states. This right concerns the accuracy of personal data generally and is distinct from, though it may interact with, cookie- and tracking-related consent obligations. The specific implementation details and enforcement positions of individual U.S. state laws beyond the CPRA are outside the scope of the cited evidence.
Why it matters
The right to correct addresses a foundational data protection principle: personal data held about an individual should be accurate. Inaccurate information can lead to flawed decisions, misdirected communications, or reputational and financial harm to the individual, which is why both EU/UK and several U.S. frameworks provide a mechanism for individuals to have errors fixed. For organizations, honoring this right is not merely a courtesy but a legal obligation under the applicable regime, and failing to act on valid requests can expose the organization to regulatory scrutiny.
The practical significance varies by jurisdiction. Under the EU GDPR and UK GDPR, Articles 16 and 19 require controllers to rectify inaccurate personal data without undue delay and, where feasible, to communicate that rectification to recipients of the data. In the United States, comparable rights have emerged through state privacy laws: Section 1798.106 of the California Privacy Rights Act (CPRA) gives consumers the right to correct inaccurate personal information, and correction rights also appear in other state statutes such as the Virginia VCDPA, Colorado CPA, Connecticut CTDPA, and Utah UCPA, among others. Because scope, procedural requirements, exceptions, and verification standards differ across these regimes, organizations operating across borders generally cannot rely on a single uniform process.
For teams working with cookie consent and tracking technologies, it is worth noting that the right to correct concerns the accuracy of personal data generally and is distinct from consent obligations governing cookies and similar technologies. It may nonetheless interact with those obligations where personal data collected through tracking is inaccurate. The precise obligations depend on the governing legal regime, and the detailed implementation and enforcement positions of individual U.S. state laws beyond the CPRA are not addressed here.
Who it's relevant to
Inside Right to Correct
Common questions
Answers to the questions practitioners most commonly ask about Right to Correct.

