Subscribe to our newsletter!

Submit

Thank you for signing up for our newsletter!

We’re excited to have you with us and will keep you updated with the latest news, insights, and updates straight to your inbox.
Oops! Something went wrong while submitting the form.
Back to Blog
June 20, 2020
|
Read time {time} min

Data Subject Rights Under the GDPR [Explained]

Written by
Permission
Stay in the loop

Get the latest insights, product updates, and news from Permission — shaping the future of user-owned data and AI innovation.

Subscribe

With the passage of GDPR, it has become an unstoppable force that is reshaping the ways that companies do business and how they interact with their customers. Yet in spite of its landmark importance, there is still confusion as to what exactly the consequences are for ordinary people.

So, let’s examine what your individual data rights are under GDPR.

You can summarize them with these words:

  1. The right of consent
  2. The right to access the data
  3. The right to change data
  4. The right to complain
  5. The right to erasure
  6. The right to portability

I’ll pick them off one by one, but remember that it is not a fine-detail description of the legal niceties — if you want that, follow the links. This article just explains each.

Individual Data Rights Under GDPR

1. The Right of Consent

Under GDPR, organizations cannot store an EU citizen’s data unless they give their unambiguous consent. There are some exclusions (see the Right to Erasure, later in this article). The precise words used in the regulations are: “freely given, specific, informed and unambiguous”.

Consent is not given if the organization requesting the data does not ask for it, or displays pre-ticked boxes that indicate consent. Those who haven’t explicitly opted in opt-in, have opted out. No matter what data they provided, the organization has no right to store it.

To make matters more awkward, consent must be given for each process applied to the data. So perhaps XZY Company stored my data so it could process my orders. That’s fine, but it cannot aggregate that data with other people’s data and start analyzing it unless I also agree to that. So it behooves companies to get all the permissions all at once.

GDPR also restricts the automated processing of personal data to analyze or predict an individual’s behavior. Specifically, the regulations restrict this activity if it will have a significant impact on an individual, such as in a hiring or credit decision. Many companies will have to adjust their business models around such restrictions.

And if you are hoping there’s a loophole for data already stored, there isn’t. If you never got permission, you now have to get it, both for storing the data and processing it.

Read More: Art. 7 GDPR

2. The Right to Access the Data

This is more complex and far-reaching than the word “access” implies.

First of all, the EU citizen has the right to ask whether an organization is holding and processing his or her data, whether they have had any interaction with them or not. Having discovered that this is the case, they have the same rights as if they had volunteered the information. They then have the following rights, as well as all the other rights described in this article:

  1. Ability to access the data.
  2. To know what data is held, and where it came from.
  3. To know the purposes of the processing done on it.
  4. To whom the data has been disclosed, including recipients in other countries or international organizations. If that is done, all the data rights have to be enforceable at the destination (see Art. 46 GDPR).
  5. The time period the data will be stored, or if impossible to state precisely, the criteria used to determine that period.

Beyond that, individuals have the right to know of the existence of automated decision-making on their data, including profiling, and “meaningful information about the logic involved”, as well as the significance and the consequences of such processing for the data subject.

Or, to put it simply, if you are analyzing their data, you have to tell them exactly how and what the consequences will be for them.

Read More: Art. 15 GDPR

3. The Right to Change Data

The right to change data enables the individual to request that data, if incorrect, be corrected.

Additionally, companies will have to notify them of everyone to whom their data has been disclosed so they can get that copy of the data updated. Failure to comply with their request requires a company to explain the reason for not doing so, and it has an obligation to inform the user of their right to complain.

This could, of course, become complicated. The problem is dirty data. Nowadays, there is a considerable amount of dirty data, for a variety of reasons, including data entry errors by the data owner.

The problem is that incorrect data may have negative consequences for the data owner, for example, if it is part of a credit report.

Read More: Art. 16 GDPR

4. The Right to Complain

So, to whom will they complain? Individuals have the right to complain to a supervisory authority; there is at least one such authority in every EU country.

The situation will thus be a little difficult if your company hasn’t yet registered with an authority. The authority will provide guidance on what needs to happen. Their word will probably be final.

Read More: Art. 16 GDPR

5. The Right to Portability

Individuals have the right to request all personal data about them from an organization company holding their data. This must be transferred to them in a “machine-readable” format — so a CSV file will do.

For the EU citizen, this could be very useful if they wish to build a database of personal information. Just get all of it from every company or government department you gave it to. Nice!

Read More: Art. 20 GDPR

6. The Right to Erasure

The “right to erasure” has also been referred to as the “right to be forgotten”. This means that EU citizens can request the complete deletion of their data. The data must be deleted without “undue delay”.

So, my advice to EU citizens: If you want the data deleted, first go and collect it and put it into a personal database, then request deletion. However, there are exceptions you need to know about. You will not be able to get data deleted in the following situations:

  1. Legal compliance. For example, banks in most jurisdictions are obliged to keep data for seven years, so your personal data will not be erased. Also, if you have a criminal record, don’t expect to get that expunged.
  2. A “public interest”. For example in the area of public health, data archiving in respect of scientific, historical research or public interest or data supporting legal claims.
  3. Paper data and microfiche data. GDPR only applies to digital information. Neither does it apply to technically impossible situations, such as when your data is held in a back-up file, but in that circumstance, no processing of your data is allowed. If it is restored, it must be deleted.

If a company makes your data public, and you wish “to be forgotten”, it is obligated to take reasonable steps to get other processors to erase the data. For example, when a website publishes an untrue story about an individual and later is required to erase it, it must request other websites that have republished the story to erase their copy of the story.

Of course, this only applies when it doesn’t conflict with freedom of expression laws. In short, you can’t suppress legitimate press.

Read More: Art. 17 GDPR

But What About the US?

US companies that are affected by GDPR are advised to consult with their insurance brokers to determine the impact of the regulations on their insurance programs. They need to discuss the coverage of GDPR violations and the logistics of insurance policies to pay into GDPR-regulated countries.

Yet for all of these data rights, they only apply to citizens of EU countries. So where does this leave the state of data privacy for US citizens?

On April 10th, Mark-have-I-said-I’m-sorry-enough-yet-Zuckerburg was facing a Senate Committee, pretending to sound responsible and issuing the occasional “mea culpa”. The senators, as one would expect, didn’t understand the technology side and spent most of their time trying to say something memorable.

Kudos went to Lindsey Graham (R-SC) for mentioning the word “monopoly”. This word strikes fear into the hearts of big company executives, and can make a social network CEO melt like that Nazi villain in Raiders Of The Lost Ark. But it didn’t.

Regulations Imminent!

Nevertheless: Personal data abused, elections interfered with, citizens outraged — no doubt we’ll soon see a convoy of regulations coming down the pike.

Politicians are filling the air with sound-bites that suggest imminent action and express noble goals (along party lines of course). One might get the impression that sometime soon, no single piece of personal data will ever be bruised or abused again. Dream on.

For one thing, the Facebook business model depends entirely on exploiting personal data, and no politician wants to be responsible for downing America’s sixth-largest company. So expect a poorly formulated “Privacy Bill of Rights” or “Bill of Privacy Rights” to emerge.

Subsequently, lobbyists will circle like vultures over roadkill until the traffic dies away, so they can dip their beaks into the impending legislation to “enhance” it. They will prevent any of the companies they represent (Facebook, Google, Twitter, et al) from losing a dime of revenue, and with a fair wind, they may actually turn it into a revenue opportunity.

That’s how it might have happened if the EU hadn’t ruined the game. Unfortunately for our beloved data pirates, the EU has set the bar for privacy legislation and it’s not a low one. American politicians may feel the urge to compete — but sadly they’re unfit.

Can America Beat the EU?

There’s a scant possibility that the US legislative system will get even halfway to where Europe is. They don’t have the players. The US legislative team has been performing abysmally of late — they haven’t won a trophy since the LA Dodgers last won the World Series.

But perhaps it doesn’t matter. Promising new teams are emerging from the newly formed crypto economy, and they may do the job on America’s behalf. They may even go further.

Crypto businesses that preside over personal data tend to give a damn about privacy. As new businesses that are de-facto-international, they’d be stupid to flout GDPR, so they don’t.

Some, like Permission, are going further than GDPR. Rather than explain the technology employed (it’s complicated), let me frame it in the terms I’ve used above to describe the EU’s personal data rights program.

We would like to enhance those handsome regulations in the following way:

  1. The right to personal cryptographic control. You have the right to personal cryptographic control (by private key) of ALL your personal data and the right to provide permission for its usage at the item level.
  2. The right to anonymity. You have the right to have your data anonymized when requested by others so that it does not include any personal data that identifies who you are (this may seem impossible to implement, but it isn’t because of the next right).
  3. The right to zero-knowledge proof. You have the right to employ zero-knowledge proofs to provide credentials to preserve your anonymity.

Sound like a movement you could get behind? Join us at Permission.

Recent articles

Big Tobacco Had Its Reckoning. Now It’s Big Tech’s Turn.

Aug 12th, 2026
|
{time} read time

The floodgates are open.

Thousands of lawsuits are moving forward. States are writing new rules for kids online. And lawmakers are beginning to tell AI companies what they can and cannot do when children use their products.

And you don't have to look far to see it happening...

The courts: 3,000+ lawsuits get the green light

On August 10, the Ninth Circuit allowed more than 3,000 lawsuits against Meta, Google/YouTube, TikTok and Snap to move forward.

The cases allege that the companies deliberately designed features of their platforms to be addictive, particularly for young users.

The tech companies had argued that Section 230 of the Communications Decency Act protected them from the claims. The court rejected their attempt to use Section 230 to stop the litigation at this stage, finding that it provides a defense rather than immunity from being sued.

At their core, these cases are allegations about the platforms themselves: how they were designed, how they kept people engaged, and what responsibility the companies bear for the consequences.

The companies will still have the opportunity to defend themselves against those allegations.

But with more than 3,000 cases now getting the chance to be heard, this is getting harder to argue away.

New Jersey: families get a way to enforce the rules

One day later, New Jersey Governor Mikie Sherrill signed the New Jersey Kids Code Act into law.

The law establishes new design and privacy requirements for covered online services likely to be accessed by minors. Among other provisions, it requires high privacy settings by default, restricts certain push notifications, prohibits dark patterns for minors, limits how children's personal data can be used and retained, and places restrictions on targeted advertising.

But one provision in particular changes the accountability equation: a private right of action.

An individual under 18 who is injured by a violation can bring a claim under the law, with statutory damages of $5,000 per violation. Parents may also bring an action on a minor's behalf.

Which is legal language for something pretty simple: families don't have to wait around for a regulator to act. They can take companies to court themselves.

Colorado: AI safety starts becoming a legal requirement

Then there's Colorado.

Earlier this year, Governor Jared Polis signed Colorado HB 26-1263, establishing specific requirements for operators of conversational AI services.

And this one is worth paying attention to because the law doesn't simply tell AI companies to "keep kids safe." It starts defining what that actually means.

Operators must estimate users' ages. When dealing with minors, the law requires recurring disclosures that they are interacting with AI rather than a person and establishes protections around sexually explicit interactions.

It also addresses one of the most unsettling questions surrounding companion-style AI: emotional dependence.

The law requires safeguards designed to prevent conversational AI from producing statements that simulate emotional dependence. It also requires protocols for responding to suicidal ideation and self-harm, privacy and account-management tools for minors and parents or guardians, and reporting requirements intended to help regulators evaluate whether those safeguards are actually working.

The law takes effect January 1, 2027.

For companies building conversational AI, that's a meaningful shift. Child safety is moving beyond a set of voluntary guardrails companies write for themselves. In Colorado, some of those guardrails are becoming law.

It's no coincidence that this is all happening at once.

Big Tobacco didn't wake up one morning and discover the world had changed its mind. The reckoning came piece by piece, until lawsuits became regulation and an industry that had spent decades setting its own standards was finally forced to take responsibility for the harm its products caused.

We're watching that shift happen again.

For years, the responsibility for keeping kids safe online has fallen on parents.

Set the parental controls. Check the privacy settings. Watch the screen time. Know which apps they're using. Figure out who they're talking to. Keep up with every new platform, algorithm and now AI chatbot entering their lives.

All while the technology on the other side of the screen gets more sophisticated by the month.

Now courts and lawmakers are starting to ask the companies building that technology a much more uncomfortable question:

If children are using your products, what are you doing to keep them safe?

For families, that's the shift that matters most.

This isn't another round of false promises to "do better."

This is legislation. These are lawsuits. This is accountability beginning to have teeth.

Parents will always have the role of protecting their children online. We happen to believe they should have far more visibility and control over the technology entering their families' lives, not less.

But parents cannot be the entire safety system.

The law is making clear that the companies designing the products, writing the algorithms and building the AI our kids interact with have a responsibility, too.

And when they fail to meet it, they'll finally be held accountable.

ChatGPTs Births A Parenting Tool That Needs Some Image Repair

Aug 4th, 2026
|
{time} read time

Sam Altman keeps pitching AI as a co-parent. The reason parents aren't buying isn't nostalgia, it's the lawsuits.

Last Friday, Sam Altman had an idea he was excited about. Hook your family calendar up to ChatGPT, tell it what your kids are into, and every morning on the drive to school it'll produce a little podcast: one kid's soccer game that afternoon, another kid's birthday coming up, maybe some news. He called it a "cool use case."

What should’ve felt really innovative, landed like the opening scene of a bleak dystopian movie. Two kids in the back, one parent up front, and a smooth synthetic voice narrating, to everyone present, the lives of everyone present. "Later today, Maya has soccer." Maya, who has soccer, looks out the window. Nobody says anything, because the podcast is saying it for them.

The internet population caught what we caught. The reply that stuck came from Alex Hirsch, creator of Disney’s Animated series, Gravity Falls. It was seven poignant words: "What if you just talked to your children?" That was the entire rebuttal, and it traveled a great deal further than the thing it was rebutting. Altman's post drew somewhere around 9,600 likes. Hirsch's reply cleared 120,000. On the CEO's own platform, the crowd took a vote, and the crowd chose the small talk.

Now, we want to be fair here, because the easy thing is to dunk and move on. But we’re parents here at Permission and anyone who has done the 7:40 a.m. drive on four hours of sleep, refereeing a backseat dispute about who touched whom first, knows the exact fantasy of a button that handles the morning. That instinct isn't a character flaw. It's a Tuesday.

But this wasn't a one-off. Altman has been quietly auditioning AI for the co-parent role for a while now. On The Tonight Show in December 2025 he said he couldn't imagine having to "raise a newborn without ChatGPT" then added that people had managed the trick for a few hundred thousand years without it. Also, last year, in a podcast hosted by Andrew Mayne, Altman admitted that people might form “problematic parasocial relationships” to a chatbot. (You know, the one-sided kind that we usually reserve for celebrities we've never met.) He sees the hazards clearly. He's pitching the product anyway.

When visibility turns into vulnerability.

The reason parents flinched at the idea of carpooling with a chatbot for school drop off isn't that they're allergic to convenience. It's that the company making the offer is, right now, being sued by multiple families who say its chatbot played a role in their loved ones' spiraling delusions and, in the worst cases, their deaths. OpenAI says it is continually improving how its models handle sensitive conversations, and that work genuinely matters. But you can see the problem. "Let me into your calendar, your commute, and your kids personal details" is a big ask from anyone. It is a much bigger ask from a company currently explaining itself in court.

Trust isn't a feature you ship in the next update. It's something people hand you slowly, and take back all at once.

Here's where we should admit an interest. We build Permission on a belief that sounds boring until you sit with it: your data belongs to you. With Permission your kids’ browsing history doesn’t get shipped out to the open internet. Not to a model, not to a growth chart, not to whoever posts the next cool use case. And the closer AI creeps toward our kids (and it is creeping, because kids are already asking it everything) the more one question starts to outrank all the others:

Where is the line between parenting and outsourcing parenting?

Because "parenting tool" is doing a lot of quiet work in that phrase. A tool is a hammer. It lives in a drawer, it does one honest thing, and it does not ask to read your child's messages or move into the family calendar. When a company calls its chatbot a "parenting tool," it's worth asking, gently, which word they mean. The tool part, or the parenting part.

We happen to think AI can be genuinely, unglamorously useful to families. Not by doing the talking for you, but by handing you the context you'd otherwise miss instead of a thousand panicked notifications, and then getting out of the way so you can make the call. That's a real distinction, and it deserves its own piece.

So take this as Part One: the news, the flinch, and the reason the flinch is earned. In Part Two, we'll make the harder and more hopeful argument that you can let AI help you parent without completely handing over your family secrets. There is a version of this where the grown-ups stay in charge. We think it's the only version worth building.

For now, the seven best words anyone has offered on the whole affair still belong to Hirsch. So we'll give him the last one, too.

What if you just talked to your children?

Insights

The Verdicts Are In

Jun 25th, 2026
|
{time} read time

For years, concerns about the harm social media platforms cause children were categorized as “alleged.” In the spring of 2026, juries started using different words: negligent, deceptive, unconscionable. Courts are now saying what parents have long suspected: the design was the harm. Here is what the courtroom evidence now shows and why parents should be paying close attention.

Before a Child Can Tell Fact From Fiction

Before children are developmentally equipped to distinguish fact from fiction, digital systems have already begun influencing how they think, what captures their attention, and how they begin forming their sense of identity.

Social media platforms no longer function as just communication tools today. They increasingly shape how children develop self-worth, regulate emotion, build social relationships, and understand the world around them.

For years, concerns surrounding children’s relationship with technology were often dismissed as parental anxiety or treated as speculation. That argument is becoming harder to sustain.

Across courtrooms, regulatory investigations, internal company disclosures, and mounting scientific research, a clear pattern is emerging: some of the world’s largest technology companies have built systems that maximize engagement by exploiting psychological vulnerabilities in young users, while parents remain largely unaware of what they have actually consented to.

The issue is no longer whether these systems pose risks to children.

The more urgent question is whether the systems themselves will fundamentally change, or whether society will continue documenting the damage in real time while continuing to participate in the very system that creates it. 

The Environment Around Childhood Has Changed

The environment children grow up in has changed.

Why are children so easily targeted by these platforms? In adolescence, the regions that govern judgment and emotional steadiness are still maturing, while those that respond to approval, comparison, and reward are already highly active. These platforms are designed to pull on exactly those urges - through likes, notifications, feeds that never end, and "recommended for you" videos that keep coming.

The American Psychological Association has warned that this combination leaves minors more prone to compulsive use, and more exposed to the emotional toll of measuring themselves by how others react to them online.

As reported in Parenting in the Age of AI: Why Tech Is Making Parenting Harder — and What Parents Can Do, parenting got harder because the environment has shifted.

For the first time, families are raising children inside digital environments designed to maximize engagement  and continuously compete for attention. Traditional parenting tools now operate against these systems that are created to keep children online for as long as possible.

What many parents experience as daily frustration is often not a parenting challenge. It is the result of an environment intentionally optimized to override the limits parents try to set.

What the Lawsuits Prove

For years, the harm caused by digital platforms was “alleged.” 

That is changing rapidly.

Between 2024 and 2026, a series of major lawsuits against companies including Meta, TikTok, Google, Character.AI and OpenAI have moved beyond accusation and into courtrooms where evidence is now being publicly examined.

These lawsuits all share something important: they don't blame a single video or post for harming a child. They blame how the apps themselves are built — the endless scroll, the recommendations that decide what your child sees next, the AI designed to keep them watching.

For years, companies argued they couldn't be held responsible for what users posted on their platforms. These cases now point to the design itself, the features built to capture and hold a child's attention. Courts are now increasingly letting those claims move forward. 

The courts, claims, design features and outcomes are laid out in Appendix A.

The Pattern

Across nearly every major lawsuit involving child safety and digital platforms, an alarming pattern continues to repeat itself.

  • Internal research identifies harm early.
  • Executives are made aware of developmental, psychological, and behavioral risks to minors.
  • Product teams continue implementing design choices that increase engagement despite those findings.
  • Public messaging continues emphasizing safety while internal evidence often tells a different story.

Only after years of public pressure do regulators or courts intervene.

When growth and user wellbeing compete, technology companies have repeatedly demonstrated which one wins. While accountability has almost always arrived only after harm has already occurred.

The Consent Parents Never Gave

At the center of nearly every child safety dispute in technology sits a deeper issue that receives far less attention: consent.

Modern internet platforms operate under the assumption that consent has been obtained simply because a user clicked “I agree.”

But clicking “I agree” was never meaningful consent.

Meaningful consent requires understanding consequences.

Yet most parents are never clearly told:

  • How algorithms shape what children see.
  • How behavioral data is continuously collected and analyzed.
  • How engagement systems are designed around psychological reward loops.
  • How platforms measure emotional responses, attention patterns, and behavioral tendencies to optimize retention.
  • How artificial intelligence systems increasingly personalize influence in ways families cannot see.

Parents were never fully informed about the environments their children were entering.

Will Anything Change?

What gets accepted today becomes the default tomorrow. 

The risks, the design choices and the outcomes are now well documented.

Much of what happens next will be shaped by a series of major bellwether cases already underway. The 2026 verdicts in K.G.M. v. Meta and State of New Mexico v. Meta were early signals.

Federal litigation is now accelerating through MDL 3047, where more than 2,600 cases against major tech companies have been consolidated, with the first federal bellwether trial beginning in June 2026.

The outcomes of these cases will help define the future relationship between families and technology.

At Permission, we closely monitor this litigation because it keeps returning to the same core truth: parents deserve to know what their children are actually consenting to — and children deserve to grow up in environments designed to support their development, not exploit their vulnerabilities.

Parents deserve to understand these environments while they are still evolving, not years later, after the consequences are already visible. And children deserve to grow up in environments designed to support their development, not exploit their vulnerabilities.

Learn more about why AI needs permission (and what it means for your family) at AI needs Permission. Permission is actively tracking this litigation and the broader shift it represents for families, AI, and the future of consent online.

Share Permission. Help Another Family.

May 26th, 2026
|
{time} read time

There's something that happens when Permission starts working for your family. You notice things earlier. Conversations get easier. The guesswork goes away.

And almost immediately, you think of another family who needs this.

Now there's a simple way to share it — and get rewarded when you do.

How It Works

Refer Permission to other parents. When three families subscribe through your unique referral link, you receive a $30 gift card — automatically, with no limit on how many times you can earn.**

It's straightforward:

  1. Get your unique referral link from your Permission account
  2. Share it with parents you think would benefit
  3. Once three families subscribe to a paid plan, your $30 gift card is on its way

That's it. No complicated tiers. No tracking spreadsheets. Just sharing something you believe in and being rewarded for it.

A Few Things to Know

  • Rewards are triggered by completed paid subscriptions — free trials don't count.
  • You'll receive a notification once your reward has been credited.
  • Gift cards are fulfilled via our rewards partner, Tremendous. Redemption availability may vary.
  • When sharing your referral link, please disclose that you may receive a reward if the person you refer subscribes. Example: "I use Permission and earn rewards when friends sign up through my link."
  • Program terms apply. See our Terms of Use for full details.

Why We Built This

Permission works best when it spreads the way trust does — through people who know each other.

Parents talk. They share what's working and what isn't. They ask each other for recommendations on everything from pediatricians to schools to apps. We'd rather reward that natural word-of-mouth than spend that money on ads.

When you refer a family to Permission, you're not just earning a gift card. You're helping another parent feel less alone in navigating their child's digital life.

Ready to Share?

Get your referral link → https://app.permission.ai/motivate

** Gift cards fulfilled via Tremendous. Referral rewards require completed paid subscriptions. Program terms apply. See Terms for full details.