{"id":10881,"date":"2025-07-09T10:59:38","date_gmt":"2025-07-09T08:59:38","guid":{"rendered":"https:\/\/s8.tgin.eu\/?p=10881"},"modified":"2025-07-09T10:59:39","modified_gmt":"2025-07-09T08:59:39","slug":"data-subject-rights-in-ai-a-practical-guide-for-businesses","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/data-subject-rights-in-ai-a-practical-guide-for-businesses\/","title":{"rendered":"Respecting Data Subject Rights in AI: A Practical Guide for Businesses"},"content":{"rendered":"\n<p>Nowadays, data subject rights must be considered as artificial intelligence (AI) revolutionizes industries. However, with this advancement, <a href=\"https:\/\/commission.europa.eu\/law\/law-topic\/data-protection_en#:~:text=Timeline-,Data%20protection%20in%20the%20EU,there%20is%20a%20need%20for%20clear%20and%20strong%20data%20protection%20rules.,-Data%20protection%20is\">data privacy and data protection<\/a> both become major concerns for both businesses and consumers. With AI tools enabling greater collection and use of personal data, making it more critical than ever for organizations to respect the rights of data subjects. It is important that organizations design and deploy these technologies in compliance with data protection laws, especially the rights of data subjects provided by the GDPR.<\/p>\n\n\n\n<p>Data subject rights (DSRs) are not optional check boxes. They are legally enforceable rights granted to individuals whose personal data is processed. Businesses must respect data subject rights throughout all stages of AI development, deployment, and ongoing system management. The <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:32016R0679&amp;from=EN#page=39\">GDPR<\/a> grants individuals several rights over their personal data. Let us focus on four of these here:<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<ol class=\"wp-block-list\">\n<li><strong>Right to be informed<\/strong>: As with other data protection frameworks, transparency is key under the GDPR. This right takes the form of a duty to inform prior to the processing taking place. Businesses must include information on how they collect, use, store, and share data, the purpose of processing, the legal basis, data retention periods, and who may receive the data. Privacy notices are the typical repositories for this information. They must be concise, accessible, and written in plain language.<\/li>\n\n\n\n<li><strong>Right of access<\/strong>: Data subjects can request access to the exact personal data a business holds about them. Businesses must provide information about processing activities, data categories, and any third parties with whom they share the data.<\/li>\n\n\n\n<li><strong>Right to rectification<\/strong>: Data subjects can request organizations to correct incorrect or incomplete data without delay. Businesses must respond promptly and update the data across systems and third-party processors where necessary.<\/li>\n\n\n\n<li><strong>Right to object, right to be forgotten and right to revoke consent<\/strong>: It allows individuals to exercise control. The European Data Protection Board (EDPB)&nbsp; published a case digest on <a href=\"https:\/\/www.edpb.europa.eu\/system\/files\/2023-02\/one-stop-shop_case_digest_on_the_right_to_object_and_right_to_erasure_en.pdf\">right to object and erasure<\/a>. Data subjects must be able to object to the use of their data and request its erasure when it is no longer necessary, when they withdraw consent, or for purposes like direct marketing.<\/li>\n<\/ol>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-style-rounded\">\n<figure class=\"aligncenter size-large is-resized\"><img decoding=\"async\" width=\"683\" height=\"1024\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/06\/pexels-sora-shimazaki-5669619-683x1024.jpg\" alt=\"\" class=\"wp-image-10770\" style=\"width:322px;height:auto\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/06\/pexels-sora-shimazaki-5669619-683x1024.jpg 683w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/06\/pexels-sora-shimazaki-5669619-200x300.jpg 200w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/06\/pexels-sora-shimazaki-5669619-768x1152.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/06\/pexels-sora-shimazaki-5669619-1024x1536.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/06\/pexels-sora-shimazaki-5669619-1365x2048.jpg 1365w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/06\/pexels-sora-shimazaki-5669619-scaled.jpg 1707w\" sizes=\"(max-width: 683px) 100vw, 683px\" \/><\/figure>\n<\/div><\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Incorporating data minimization in AI Systems<\/h2>\n\n\n\n<p>One of the most effective ways businesses can respect data subject rights is by adhering to the data protection <a href=\"https:\/\/www.edps.europa.eu\/data-protection\/data-protection\/glossary\/d_en#:~:text=The%20principle%20of%20%E2%80%9Cdata%20minimisation,necessary%20to%20fulfil%20that%20purpose.\">principle of data minimization<\/a>. This GDPR principle requires businesses to collect and process only the minimum personal data necessary to achieve their specific purpose. Avoid over-collecting data, use anonymized or synthetic data for training, and regularly review AI outputs to remove unnecessary personal information.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Implement transparent data practices<\/h2>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-style-rounded\">\n<figure class=\"aligncenter size-large is-resized\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/data-4828441_1280-1024x682.jpg\" alt=\"\" class=\"wp-image-8203\" style=\"width:460px;height:auto\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/data-4828441_1280-1024x682.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/data-4828441_1280-300x200.jpg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/data-4828441_1280-768x512.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/data-4828441_1280.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p><a href=\"https:\/\/www.edps.europa.eu\/data-protection\/our-work\/subjects\/transparency_en\">Transparency<\/a> is central to building trust and achieving legal compliance. Always define the purpose of processing, specifically the training of AI models. If businesses rely on <a href=\"https:\/\/commission.europa.eu\/law\/law-topic\/data-protection\/rules-business-and-organisations\/legal-grounds-processing-data\/grounds-processing\/what-does-grounds-legitimate-interest-mean_en\">legitimate interest<\/a>, they must show that they gave data subjects the chance to object; otherwise, they invalidate their legal basis.<\/p>\n\n\n\n<p>Clearly inform existing customers in advance when using their data to train AI models, and provide opt-out options before processing begins. <strong>Transparency is key.&nbsp;<\/strong><\/p>\n\n\n\n<p>When there&#8217;s no direct relationship with the individual (such as when using publicly available data or from data brokers), the GDPR requires information to be provided within one month of its collection <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:32016R0679&amp;from=EN#page=41\">GDPR Articles 14<\/a>.&nbsp;&nbsp;<\/p>\n<\/div>\n<\/div>\n\n\n\n<p>In 2023, the  <a href=\"https:\/\/www.datenschutz-notizen.de\/chatgpt-temporarily-banned-by-the-italian-garante-3041656\/\">Italian DPA<\/a> temporarily banned OpenAI\u2019s ChatGPT, citing a lack of transparency around how it used personal data for training. The DPA later required the company to implement clear privacy notices and provide users with ways to exercise their rights.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Respect the right to access<strong>&nbsp;<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Can data owners request access to training data?&nbsp;<\/h3>\n\n\n\n<p>This becomes complicated with large language models, but under the GDPR, individuals have the right to know if and how their data is being used.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How to exercise that right?&nbsp;<\/h3>\n\n\n\n<p>Under the GDPR, individuals have the <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:32016R0679&amp;from=EN#page=38\">right to know if and how their personal data is used<\/a>, including data processed by AI systems. While this is straightforward for users with an existing relationship (who can submit data subject access requests via account settings or customer support), it&#8217;s more complicated when there&#8217;s no direct connection.<\/p>\n\n\n\n<p>In such cases, organizations must ensure proactive transparency by clearly informing people through privacy policies and AI transparency reports. Failure to uphold this right contributes to loss of trust and accountability in AI use and development.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Develop clear processes for data deletion and rectification&nbsp;<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Can data be corrected or deleted after it has been used to train an AI model?&nbsp;<\/h3>\n\n\n\n<p>While difficult, companies must explore the use of data architectures that allow tracing of personal data contributions. The GDPR (<a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:32016R0679&amp;from=EN#page=5\">Recital 26<\/a>) considers even <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:32016R0679&amp;from=EN#page=5\">pseudonymous data<\/a>, like randomly generated user IDs, as personal data since organizations can technically link it back to a person, directly or indirectly.<\/p>\n\n\n\n<p>To reduce data subject risk while improving compliance, companies could implement the following measures:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Data encryption<\/strong>: Businesses should ensure <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:32016R0679&amp;from=EN#page=51\">proper security implementation<\/a>, especially when handling sensitive personal information.<\/li>\n\n\n\n<li><strong>Anonymization and pseudonymization<\/strong>: Where possible, <a href=\"https:\/\/www.edps.europa.eu\/press-publications\/press-news\/blog\/pseudonymous-data-processing-personal-data-while-mitigating_en#:~:text=Unlike%20anonymised%20data%2C%20pseudonymised%20data,statistical%20or%20historical%20research%20purposes.\">anonymize or pseudonymize data<\/a> before using it in AI models. Anonymization and pseudonymization protect personal data by reducing breach risks and limiting the impact on individuals in case of a data exposure.<\/li>\n\n\n\n<li><strong>Access control<\/strong>: Implement strict access controls and monitoring to ensure only authorized personnel can access personal data. This prevents unauthorized exposure of sensitive information.<\/li>\n<\/ul>\n\n\n\n<p>By embedding these practices into AI development pipelines, organizations can take meaningful steps toward compliance, trust-building, and ethical AI deployment.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Ensure security and privacy by design<\/h2>\n\n\n\n<p>Organizations should build user trust and meet regulations by embedding privacy from the start, not treating it as an afterthought. This is the core of the <a href=\"https:\/\/techgdpr.com\/blog\/tag\/privacy-by-design\/\">privacy by design<\/a> principle under <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:32016R0679&amp;from=EN#page=15\">the GDPR<\/a>.<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p>Key steps include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Promoting user choice and control<\/strong>: Provide clear opt-out options before processing data\u2014whether in email campaigns, mobile app popups, or web trackers.). Empower users with privacy dashboards that let them view, manage, and delete their personal data at any time.<\/li>\n\n\n\n<li><strong>Secure data handling<\/strong>:  Businesses must encrypt personal data used in AI training while <a href=\"https:\/\/www.edpb.europa.eu\/system\/files\/2025-06\/spe-training-on-ai-and-data-protection-technical_en.pdf\">transmitting and at rest<\/a>. Implement strict access control mechanisms to ensure that only authorized personnel can interact with sensitive data.<\/li>\n<\/ul>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-style-rounded\">\n<figure class=\"aligncenter size-large is-resized\"><img decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/11\/pexels-photo-1260309-1024x683.jpeg\" alt=\"\" class=\"wp-image-1738\" style=\"width:426px;height:auto\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/11\/pexels-photo-1260309-1024x683.jpeg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/11\/pexels-photo-1260309-300x200.jpeg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/11\/pexels-photo-1260309-768x512.jpeg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/11\/pexels-photo-1260309-1920x1280.jpeg 1920w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div><\/div>\n<\/div>\n\n\n\n<p>Embedding privacy and security into system architecture from the outset not only ensures compliance, trust-building, and ethical AI deployment.<br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Maintain ongoing communication and feedback loops<\/h2>\n\n\n\n<p>Transparency shouldn\u2019t stop at data collection. When introducing AI processing, <a href=\"https:\/\/techgdpr.com\/blog\/the-differences-between-privacy-policy-and-privacy-notice\/#:~:text=Privacy%20Notices,and%20data%20protection.\">update your privacy notices<\/a> to reflect new processing activities, as required by the GDPR. Use layered notices to highlight AI-specific practices like model training, profiling or automated decision-making. Importantly, inform users before processing, not after. True consent means giving people a real choice. Building feedback loops as user input is essential for improving fairness, spotting issues, and building trust in your AI systems.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p>As AI continues to shape modern business, respecting data subject rights is not just a legal obligation; it&#8217;s a foundation for responsible innovation. By embedding privacy by design, adopting transparent data practices, and enabling user control, organizations can align AI development with GDPR principles and foster long-term trust. Data protection isn\u2019t a compliance checkbox, it\u2019s a strategic imperative for ethical and sustainable AI. <\/p>\n\n\n\n<p>Feel free to reach out to <a href=\"https:\/\/techgdpr.com\/products\/5-hour-initial-online-consultancy-package\/\">us<\/a> for any clarification of AI compliance needs.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Nowadays, data subject rights must be considered as artificial intelligence (AI) revolutionizes industries. However, with this advancement, data privacy and data protection both become major concerns for both businesses and consumers. With AI tools enabling greater collection and use of personal data, making it more critical than ever for organizations to respect the rights of [&hellip;]<\/p>\n","protected":false},"author":31,"featured_media":5682,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[8,11,88,7,93],"tags":[253,344,35,330],"class_list":["post-10881","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai","category-data-subjects","category-gdpr","category-privacy-by-design","category-security","tag-ai","tag-data-subject-rights","tag-gdpr","tag-transparency"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-scaled.jpg",2560,1707,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-300x200.jpg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-768x512.jpg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-1024x683.jpg",640,427,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-1536x1024.jpg",1536,1024,true],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-2048x1365.jpg",2048,1365,true],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-200x200.jpg",200,200,true]},"post_excerpt_stackable":"<p>Nowadays, data subject rights must be considered as artificial intelligence (AI) revolutionizes industries. However, with this advancement, data privacy and data protection both become major concerns for both businesses and consumers. With AI tools enabling greater collection and use of personal data, making it more critical than ever for organizations to respect the rights of data subjects. It is important that organizations design and deploy these technologies in compliance with data protection laws, especially the rights of data subjects provided by the GDPR. Data subject rights (DSRs) are not optional check boxes. They are legally enforceable rights granted to individuals&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/ai\/\" rel=\"category tag\">Artificial Intelligence<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/data-subjects\/\" rel=\"category tag\">Data Subjects<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/privacy-by-design\/\" rel=\"category tag\">Privacy by Design<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/security\/\" rel=\"category tag\">Security<\/a>","author_info":{"name":"Oluwatosin Victoria Ademokun","url":"https:\/\/techgdpr.com\/blog\/author\/victoria\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-scaled.jpg",2560,1707,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-300x200.jpg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-768x512.jpg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-1024x683.jpg",640,427,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-1536x1024.jpg",1536,1024,true],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-2048x1365.jpg",2048,1365,true],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-200x200.jpg",200,200,true]},"post_excerpt_stackable_v2":"<p>Nowadays, data subject rights must be considered as artificial intelligence (AI) revolutionizes industries. However, with this advancement, data privacy and data protection both become major concerns for both businesses and consumers. With AI tools enabling greater collection and use of personal data, making it more critical than ever for organizations to respect the rights of data subjects. It is important that organizations design and deploy these technologies in compliance with data protection laws, especially the rights of data subjects provided by the GDPR. Data subject rights (DSRs) are not optional check boxes. They are legally enforceable rights granted to individuals&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/ai\/\" rel=\"category tag\">Artificial Intelligence<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/data-subjects\/\" rel=\"category tag\">Data Subjects<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/privacy-by-design\/\" rel=\"category tag\">Privacy by Design<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/security\/\" rel=\"category tag\">Security<\/a>","author_info_v2":{"name":"Oluwatosin Victoria Ademokun","url":"https:\/\/techgdpr.com\/blog\/author\/victoria\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Respecting Data Subject Rights in AI: A Practical Guide for Businesses - TechGDPR<\/title>\n<meta name=\"description\" content=\"Ensure GDPR compliance in AI by respecting data subject rights with clear steps on transparency, minimization, and privacy by design\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/data-subject-rights-in-ai-a-practical-guide-for-businesses\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Respecting Data Subject Rights in AI: A Practical Guide for Businesses - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"Ensure GDPR compliance in AI by respecting data subject rights with clear steps on transparency, minimization, and privacy by design\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/data-subject-rights-in-ai-a-practical-guide-for-businesses\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2025-07-09T08:59:38+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-07-09T08:59:39+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-scaled.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1707\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Oluwatosin Victoria Ademokun\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Oluwatosin Victoria Ademokun\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-subject-rights-in-ai-a-practical-guide-for-businesses\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-subject-rights-in-ai-a-practical-guide-for-businesses\\\/\"},\"author\":{\"name\":\"Oluwatosin Victoria Ademokun\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/6f958aa8f66db9fcf038093efbc91946\"},\"headline\":\"Respecting Data Subject Rights in AI: A Practical Guide for Businesses\",\"datePublished\":\"2025-07-09T08:59:38+00:00\",\"dateModified\":\"2025-07-09T08:59:39+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-subject-rights-in-ai-a-practical-guide-for-businesses\\\/\"},\"wordCount\":1203,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-subject-rights-in-ai-a-practical-guide-for-businesses\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2022\\\/05\\\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-scaled.jpg\",\"keywords\":[\"AI\",\"Data subject rights\",\"GDPR\",\"Transparency\"],\"articleSection\":[\"Artificial Intelligence\",\"Data Subjects\",\"GDPR\",\"Privacy by Design\",\"Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-subject-rights-in-ai-a-practical-guide-for-businesses\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-subject-rights-in-ai-a-practical-guide-for-businesses\\\/\",\"name\":\"Respecting Data Subject Rights in AI: A Practical Guide for Businesses - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-subject-rights-in-ai-a-practical-guide-for-businesses\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-subject-rights-in-ai-a-practical-guide-for-businesses\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2022\\\/05\\\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-scaled.jpg\",\"datePublished\":\"2025-07-09T08:59:38+00:00\",\"dateModified\":\"2025-07-09T08:59:39+00:00\",\"description\":\"Ensure GDPR compliance in AI by respecting data subject rights with clear steps on transparency, minimization, and privacy by design\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-subject-rights-in-ai-a-practical-guide-for-businesses\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-subject-rights-in-ai-a-practical-guide-for-businesses\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-subject-rights-in-ai-a-practical-guide-for-businesses\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2022\\\/05\\\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-scaled.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2022\\\/05\\\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-scaled.jpg\",\"width\":2560,\"height\":1707},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-subject-rights-in-ai-a-practical-guide-for-businesses\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Respecting Data Subject Rights in AI: A Practical Guide for Businesses\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/6f958aa8f66db9fcf038093efbc91946\",\"name\":\"Oluwatosin Victoria Ademokun\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/12\\\/IMG_0638-1-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/12\\\/IMG_0638-1-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/12\\\/IMG_0638-1-150x150.jpg\",\"caption\":\"Oluwatosin Victoria Ademokun\"},\"description\":\"Oluwatosin Victoria Ademokun is currently an intern at TechGDPR. Victoria is pursuing a Masters in International Security Management from the Berlin School of Economics and Law. She currently holds a BSc in Criminology and Security Studies from AAUA Nigeria.\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/victoria\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Respecting Data Subject Rights in AI: A Practical Guide for Businesses - TechGDPR","description":"Ensure GDPR compliance in AI by respecting data subject rights with clear steps on transparency, minimization, and privacy by design","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/data-subject-rights-in-ai-a-practical-guide-for-businesses\/","og_locale":"en_US","og_type":"article","og_title":"Respecting Data Subject Rights in AI: A Practical Guide for Businesses - TechGDPR","og_description":"Ensure GDPR compliance in AI by respecting data subject rights with clear steps on transparency, minimization, and privacy by design","og_url":"https:\/\/techgdpr.com\/blog\/data-subject-rights-in-ai-a-practical-guide-for-businesses\/","og_site_name":"TechGDPR","article_published_time":"2025-07-09T08:59:38+00:00","article_modified_time":"2025-07-09T08:59:39+00:00","og_image":[{"width":2560,"height":1707,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-scaled.jpg","type":"image\/jpeg"}],"author":"Oluwatosin Victoria Ademokun","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Oluwatosin Victoria Ademokun","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/data-subject-rights-in-ai-a-practical-guide-for-businesses\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/data-subject-rights-in-ai-a-practical-guide-for-businesses\/"},"author":{"name":"Oluwatosin Victoria Ademokun","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/6f958aa8f66db9fcf038093efbc91946"},"headline":"Respecting Data Subject Rights in AI: A Practical Guide for Businesses","datePublished":"2025-07-09T08:59:38+00:00","dateModified":"2025-07-09T08:59:39+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-subject-rights-in-ai-a-practical-guide-for-businesses\/"},"wordCount":1203,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-subject-rights-in-ai-a-practical-guide-for-businesses\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-scaled.jpg","keywords":["AI","Data subject rights","GDPR","Transparency"],"articleSection":["Artificial Intelligence","Data Subjects","GDPR","Privacy by Design","Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/data-subject-rights-in-ai-a-practical-guide-for-businesses\/","url":"https:\/\/techgdpr.com\/blog\/data-subject-rights-in-ai-a-practical-guide-for-businesses\/","name":"Respecting Data Subject Rights in AI: A Practical Guide for Businesses - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-subject-rights-in-ai-a-practical-guide-for-businesses\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-subject-rights-in-ai-a-practical-guide-for-businesses\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-scaled.jpg","datePublished":"2025-07-09T08:59:38+00:00","dateModified":"2025-07-09T08:59:39+00:00","description":"Ensure GDPR compliance in AI by respecting data subject rights with clear steps on transparency, minimization, and privacy by design","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/data-subject-rights-in-ai-a-practical-guide-for-businesses\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/data-subject-rights-in-ai-a-practical-guide-for-businesses\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/data-subject-rights-in-ai-a-practical-guide-for-businesses\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-scaled.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2022\/05\/tingey-injury-law-firm-yCdPU73kGSc-unsplash-scaled.jpg","width":2560,"height":1707},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/data-subject-rights-in-ai-a-practical-guide-for-businesses\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Respecting Data Subject Rights in AI: A Practical Guide for Businesses"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/6f958aa8f66db9fcf038093efbc91946","name":"Oluwatosin Victoria Ademokun","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/IMG_0638-1-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/IMG_0638-1-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/IMG_0638-1-150x150.jpg","caption":"Oluwatosin Victoria Ademokun"},"description":"Oluwatosin Victoria Ademokun is currently an intern at TechGDPR. Victoria is pursuing a Masters in International Security Management from the Berlin School of Economics and Law. She currently holds a BSc in Criminology and Security Studies from AAUA Nigeria.","url":"https:\/\/techgdpr.com\/blog\/author\/victoria\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/10881","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/31"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=10881"}],"version-history":[{"count":8,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/10881\/revisions"}],"predecessor-version":[{"id":10899,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/10881\/revisions\/10899"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/5682"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=10881"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=10881"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=10881"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}