International GDPR Europe Legal Rights Data Privacy

GDPR Explained: What You Can Actually Request From Any Company That Emails You

Scan My ShadowSeptember 2, 20263 min read

TL;DR: GDPR applies to any company processing data of EU residents, regardless of where the company is based. It gives you the right to see, correct, export, and request deletion of your data — here's how each request actually works.

👉 See if your data's already leaked — free 30-second check →

GDPR (the EU's General Data Protection Regulation) is often described as strict, but what that means in practice is a set of concrete rights you can exercise directly with any company that processes your personal data — not just EU-based ones, if they serve EU residents.

The core rights that matter day to day

How to actually make a request

Most companies now have a dedicated privacy request form or email address, often linked in their privacy policy footer. A request doesn't need legal language — stating clearly which right you're exercising and for which account is generally sufficient. Keep a copy of what you sent and when, since the one-month clock starts from that point.

What happens if a company ignores the request

Each EU member state has a data protection authority that handles complaints, and this is the standard next step if a company doesn't respond within the required timeframe or refuses without a valid legal basis.

GDPR is one of several regional frameworks — Canada and Australia have their own versions with different specifics, covered in what PIPEDA lets you request in Canada. If a US breach notification prompted you to look into your rights, see what US law requires companies to tell you. For a look at what's already out there about you regardless of jurisdiction, a Scan My Shadow report checks your phone number and email across 1,500+ sources.

Frequently Asked Questions

Does GDPR apply to me if I don't live in the EU?

It applies based on whether the company is processing data of EU residents, not your citizenship — but if you're not an EU resident, a different regional framework, like your own country's law, would typically apply to your requests instead.

Can a company refuse a deletion request?

Yes, if they have a legitimate legal basis to retain the data, such as an active contract, tax record requirements, or an ongoing legal matter.

How long does a company have to respond to a GDPR request?

Generally one month, though this can be extended by up to two additional months for complex requests, with notice to you.

Is there a cost to make a GDPR request?

No, the first request is generally free — companies can only charge a reasonable fee for excessive or repetitive requests.

What's the difference between GDPR and US breach notification law?

GDPR is a broad, ongoing rights framework covering access, correction, and deletion at any time, while US breach laws specifically govern notification after a security incident — they address different situations.

Curious what's already out there about you? Scan My Shadow checks your phone number and email across 1,500+ sources and sends you a clear report — no guesswork, just facts. Start your scan.

Phone + email scan · 1,500+ data sources worldwide · Full report
₹498one-time
Scan My Digital Footprint
Secure payment via Razorpay
  • Results within about 5 minutes
  • Clear, plain-English report
  • Delivered straight to your inbox
  • No login or passwords required
  • Scan data deleted after report is generated