EU and Swiss Data Rights: Access, Erasure, Objection, and Complaints
The GDPR and Swiss FADP provide distinct routes for access, erasure or deletion, objection, and supervisory complaints or reports. Each route has its own authority, conditions, limits, and territorial scope, so one right should not be treated as a universal removal process.
Not legal advice. This page is research, not compliance guidance.
What does the GDPR right of access provide?
GDPR Article 15 lets a data subject ask the controller whether personal data are being processed and, if so, obtain access to the data, the listed processing information, information about transfer safeguards, and a copy.
The request goes to the controller, which must facilitate the exercise of rights under Articles 15 through 22. The access right covers confirmation of processing, access to the personal data, the information listed in Article 15(1)(a) through (h), information about safeguards for transfers, and a copy under Article 15(3). It does not promise a particular response or outcome.
The request is generally free. A controller may charge a reasonable administrative-cost fee or refuse to act when it demonstrates that a request is manifestly unfounded or excessive, especially because it is repetitive. A controller with reasonable doubts about identity may request information needed to confirm identity, and further copies may carry a reasonable administrative-cost fee.
The copy right may not adversely affect the rights and freedoms of others. GDPR provisions also allow qualifying legislative restrictions and specific exemptions or derogations for expression, research, statistics, and public-interest archiving. Territorial scope depends on the processing context: the GDPR can cover processing connected to an establishment in the European Union and certain processing by a controller or processor outside the European Union involving people in the European Union.
- Authority: Regulation (EU) 2016/679, Article 15; the right is exercised against the controller.
- Scope: confirmation, access to personal data and listed information, transfer-safeguard information, and a copy.
- Conditions: identity may need confirmation, requests are generally free, and further copies may carry a reasonable administrative-cost fee.
- Limits: the rights and freedoms of others and qualifying statutory restrictions or derogations remain relevant.
When does the GDPR right to erasure apply?
GDPR Article 17 provides a right to erasure when one of its stated grounds applies, including when data are no longer necessary, consent is withdrawn without another legal ground, a qualifying objection succeeds, processing was unlawful, erasure is legally required, or the data were collected in connection with specified information-society services.
A data subject exercises the right against the controller. The controller must facilitate the request and may seek additional information when reasonable doubts about identity exist. If the controller made the data public and must erase them, Article 17 requires reasonable steps, taking account of available technology and implementation cost, to inform other controllers processing the data about the request concerning links, copies, or replications.
The right is conditional rather than absolute. Article 17(1) and (2) do not apply to the extent processing is necessary for freedom of expression and information, a legal obligation or qualifying public task, qualifying public-health reasons, protected archiving or research purposes, statistics, or legal claims. Article 23 also permits qualifying legislative restrictions.
Erasure and search-result delisting are not interchangeable. The removal-methods reference owns the separate mechanics and limits of name-based delisting, so this page does not recreate that workflow. The GDPR's territorial scope can extend beyond where processing physically occurs when the processing is connected to an establishment in the European Union or specified activities involving people in the European Union. For the separate public-record topic, see What Makes a Business Filing a Public Record?. For newspaper-publication requirements for newly formed LLCs and corporations, see LLC and Corporation Publication Requirements by State.
- Authority: Regulation (EU) 2016/679, Article 17; the request is directed to the controller.
- Conditions: one of the grounds in Article 17(1) must apply, and identity may need confirmation.
- Public data: a controller required to erase publicly disclosed data must take reasonable steps within the article's technology-and-cost qualification.
- Limits: expression, legal obligations, public tasks, public health, qualifying archiving or research, statistics, and legal claims can preserve processing.
When can a person object to processing under the GDPR?
GDPR Article 21 allows an objection based on a person's particular situation when processing relies on Article 6(1)(e) or (f), an objection at any time to direct-marketing processing, and a qualified objection to scientific, historical-research, or statistical processing.
The objection goes to the controller, which must facilitate the exercise of the right. For processing based on Article 6(1)(e) or (f), the objection must relate to the data subject's particular situation and also reaches related profiling. A direct-marketing objection may be made at any time and includes related profiling. In information-society services, the right may be exercised by automated means using technical specifications.
The result depends on the processing basis. After an Article 21(1) objection, the controller may continue only if it demonstrates compelling legitimate grounds that override the data subject's interests, rights, and freedoms, or grounds connected to legal claims. Processing for direct marketing must stop after the objection. For Article 89(1) research or statistical processing, the objection does not apply when processing is necessary for a public-interest task.
The controller must bring the Article 21(1) and (2) rights clearly and separately to the data subject's attention no later than the first communication. Article 23 permits qualifying legislative restrictions. The same GDPR territorial rules apply: the processing may fall within scope through an establishment in the European Union or specified activities involving people in the European Union even when the controller or processor is elsewhere.
- Particular-situation objection: applies to processing based on Article 6(1)(e) or (f), including related profiling.
- Direct marketing: the objection may be made at any time, and processing for that purpose must stop.
- Research or statistics: Article 21 contains a qualified route subject to the public-interest-task limit.
- Continuation limit: compelling overriding grounds or grounds for legal claims can permit continued processing after an Article 21(1) objection.
How does a GDPR supervisory complaint work?
A data subject who considers that processing of personal data relating to them infringes the GDPR may lodge a substantiated complaint with a competent Data Protection Authority, which handles and investigates complaints as part of its enforcement role.
A complaint may be lodged with the Data Protection Authority in the country of the data subject's habitual residence, place of work, or the place of the alleged infringement. The complaint must satisfy the formal conditions of the Member State where it is lodged and present enough information about the alleged circumstances for the supervisory authority to investigate.
The complaint right does not replace other administrative or judicial remedies. GDPR Article 77 does not necessarily make the complainant a party to the authority's proceedings, although national procedural law may provide that status. The existence of a complaint route therefore does not promise a particular procedure or result.
A person need not be based in Europe for the complaint route to be relevant. If the GDPR applies to the person's situation, the person can complain to a Data Protection Authority in Europe and may also go to court. That is a scope statement, not a conclusion that the GDPR applies to every processing activity outside Europe.
- Authority: supervisory authorities monitor and enforce the GDPR and handle and investigate data-subject complaints.
- Forum: the authority may be in the country of habitual residence, place of work, or the alleged infringement.
- Conditions: the complaint must meet the forum's formal requirements and present enough circumstances for investigation.
- Limits: the complaint right does not displace other remedies or necessarily confer party status in the authority's proceedings.
How do access, deletion, objection, and supervisory reports differ under the Swiss FADP?
Under the Swiss Federal Act on Data Protection, access, deletion, objection, and a report to the Federal Data Protection and Information Commissioner are separate routes with different conditions, enforcement paths, exceptions, and remedies.
Access is the Article 25 right to information. A data subject may ask a controller whether personal data relating to them are being processed and obtain information needed to exercise FADP rights and understand the processing, including the controller, processed data, purpose, retention, source, automated decisions, and recipients. The request goes to the controller and has no prescribed form, although the Federal Data Protection and Information Commissioner recommends a written letter or email and checking any controller-specific guidance. The requester need not justify the request, may act personally or through a legal representative, and must cooperate with reasonable identity verification. Information is generally free, but disproportionate effort may support a fee up to CHF 300. Article 26 permits refusal, restriction, or delay on specified grounds, and Article 27 adds media-specific grounds. The cited Fedlex English translation is informational and has no legal force.
Deletion uses a different route. Articles 32 and 41 address claims involving private processing and federal bodies, and a data subject may request deletion or destruction in qualifying situations. The Federal Data Protection and Information Commissioner recommends a written request to the controller that identifies the right being exercised and follows any controller-specific guidance. For a disputed private-controller response, enforcement can begin with conciliation at the district court and may proceed to civil action; a federal body responds by formal ruling. A report to the Federal Data Protection and Information Commissioner can also be available after nonresponse or a disputed decision. Grounds for deletion include data no longer needed for the original purpose, withdrawn consent, unlawful processing, or collection or use contrary to transparency or good faith. A controller may refuse when another justification applies, including a legal processing requirement or overriding interests.
Objection is not one undifferentiated right. For private processing, Article 30 addresses processing contrary to the data subject's express wishes, while Article 32 can support requests to prohibit specified processing or disclosure. For federal bodies, Article 37 permits an objection to disclosure of specified personal data when a legitimate interest is credibly shown, and Article 41 addresses requests to stop unlawful processing when a legitimate interest exists. The recommended first route is a specific written request to the controller. Private disputes may proceed through conciliation and civil action, while a federal body issues a formal ruling with appeal information. Limits include consent, overriding private or public interests, legal authority, duties to disclose, and circumstances in which a federal body's tasks would otherwise be jeopardised.
A supervisory report goes to the Federal Data Protection and Information Commissioner, which supervises federal bodies and private persons under the FADP. A directly affected data subject or a third party may report a suspected violation. The online data-subject form is for a person directly affected; the third-party form covers a person not directly affected or seeking anonymity, and other forms of submission remain possible. For the data-subject form, the person must first seek explanations or exercise rights with the controller and then receive no response within one month, or challenge an incomplete or incorrect response without resolution. A report requires sufficiently indicative facts; the Commissioner asks that they be recent. The Federal Data Protection and Information Commissioner cannot exercise a person's rights on their behalf, act against cantonal or municipal bodies, award compensation, resolve non-data-protection matters, or impose criminal sanctions. A reporter is not a party and has no right to intervention; a minor violation may not be investigated.
- Access: ask the controller for information about processing; identity checks, specified refusal grounds, and a possible disproportionate-effort fee apply.
- Deletion: ask the controller to delete or destroy data in qualifying situations; private and federal enforcement paths differ.
- Objection: private-processing, federal-disclosure, and federal unlawful-processing provisions carry different conditions and limits.
- Supervisory report: submit sufficiently indicative facts to the Federal Data Protection and Information Commissioner after the route's stated prerequisites; the report does not make the reporter a party or guarantee intervention.
- Territorial scope: the FADP applies to circumstances that have an effect in Switzerland even when initiated abroad, while private-law and criminal territorial rules remain reserved.