7.2 Global Privacy Legislation on Data Subject Rights

Key Takeaways

  • GDPR grants eight data subject rights in Articles 12-22, enforced by member-state supervisory authorities with fines up to 4% of global annual turnover or EUR 20 million, whichever is higher
  • HIPAA grants a right of access (30 days, one 30-day extension), the right to amend, and an accounting of disclosures, enforced by HHS OCR; it is a sectoral health law, not a general privacy statute
  • CAN-SPAM governs commercial email in the US and requires honoring opt-out requests within 10 business days, a valid physical postal address, and a non-deceptive subject line
  • The Freedom of Information Act (FOIA) gives a right to request federal agency records within 20 business days and is a government-transparency law distinct from private-sector privacy law
  • Indiana, Kentucky, and Rhode Island comprehensive consumer privacy laws all take effect January 1, 2026, joining the growing US state-privacy landscape alongside California, Virginia, Colorado, Connecticut, Utah, and others
Last updated: August 2026

The Established Global Rights Regimes

The CIPM Body of Knowledge expects candidates to recognize the rights granted, the oversight authority, and notable mechanics of the major statutes that give individuals control over their personal data. The five regimes most frequently tested are GDPR, HIPAA, CAN-SPAM, FOIA, and CCPA/CPRA.

GDPR (EU 2016/679)

The General Data Protection Regulation (GDPR) is the EU's comprehensive privacy law, effective May 25, 2018. It grants eight data subject rights in Articles 12-22:

  1. Transparency and modalities (Art. 12) — information must be concise, transparent, intelligible, and easily accessible
  2. Information to be provided (Arts. 13-14) — notice obligations at collection
  3. Access (Art. 15)
  4. Rectification (Art. 16)
  5. Erasure (Art. 17) — the 'right to be forgotten'
  6. Restriction of processing (Art. 18)
  7. Data portability (Art. 20)
  8. Objection (Art. 21) and automated decision-making, including profiling (Art. 22)

Oversight sits with supervisory authorities (DPAs) in each member state, coordinated through the European Data Protection Board (EDPB). Fines reach the higher of EUR 20 million or 4% of global annual turnover (Art. 83(5)).

HIPAA (US Health Privacy)

The Health Insurance Portability and Accountability Act (HIPAA) of 1996, with the HIPAA Privacy Rule (45 CFR Parts 160 and 164) effective April 14, 2003, is a sectoral law covering covered entities (health plans, healthcare clearinghouses, and most healthcare providers) and their business associates. It is not a general privacy statute.

Key individual rights under HIPAA:

  • Right of access (45 CFR 164.524) — individuals have a right to inspect and obtain a copy of their protected health information (PHI) in a designated record set, within 30 days (one 30-day extension permitted with written notice)
  • Right to amend (45 CFR 164.526) — request correction of inaccurate PHI
  • Accounting of disclosures (45 CFR 164.528) — a record of certain disclosures of PHI made in the prior six years
  • Restriction requests (45 CFR 164.522) — a right to request restrictions on uses and disclosures

Oversight: HHS Office for Civil Rights (OCR). Penalties are tiered by culpability.

CAN-SPAM Act (US Commercial Email)

The Controlling the Assault of Non-Solicited Pornography And Marketing (CAN-SPAM) Act of 2003 (15 U.S.C. 7701 et seq.) governs commercial email sent to or from the US. It is enforced by the Federal Trade Commission (FTC). Key requirements:

  • Honor opt-out/unsubscribe requests within 10 business days
  • Provide a valid physical postal address
  • Use a non-deceptive subject line and clear identification that the message is an advertisement
  • Provide a clear and conspicuous opt-out mechanism in every commercial email

Unlike GDPR's consent model, CAN-SPAM uses an opt-out model — senders may email until the recipient opts out.

FOIA (US Federal Government Transparency)

The Freedom of Information Act (FOIA) (5 U.S.C. 552) gives any person the right to request access to federal agency records. Agencies must respond within 20 business days (excluding holidays and the day of receipt), though backlogs are common. FOIA applies to government agencies, not private companies — a distinction candidates should not conflate. It has nine exemptions (e.g., national security, personal privacy, trade secrets) that allow agencies to withhold records.

CCPA and CPRA (California)

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants California residents the rights to:

  • Know the categories and specific pieces of personal information collected
  • Delete personal information
  • Correct inaccurate personal information
  • Opt-out of sale or sharing for monetary or other valuable consideration
  • Limit the use and disclosure of sensitive personal information
  • Non-discrimination for exercising rights
  • Opt-in (for consumers under 16, with parental consent for under-13)

Oversight: the California Privacy Protection Agency (CPPA), the first US dedicated privacy regulator, plus the Attorney General. The CPRA expanded CCPA, created the CPPA, and added sensitive personal information, correction, and limitation rights.

Global Rights Comparison Table

RegimePrimary RightsOversight AuthorityResponse DeadlinePenalty Profile
GDPRAccess, rectification, erasure, restriction, portability, objection, AMD, withdrawal of consentMember-state DPAs via EDPB1 month (extendable +2)Up to EUR 20M or 4% global turnover
HIPAAAccess, amend, accounting of disclosures, restriction requestsHHS OCR30 days (+30 extension)Tiered per-violation; up to ~$2M+ per year for identical violations
CAN-SPAMOpt-out of commercial emailFTC10 business days to honor opt-outUp to ~$51,744 per email (2024 adj.; indexed)
FOIAAccess to federal agency recordsAgency FOIA officers; OSC20 business daysPrimarily injunctive; fees and attorney's fees
CCPA/CPRAKnow, delete, correct, opt-out of sale/sharing, limit SPI, non-discriminationCPPA and CA AG45 days (+45 extension)Up to $2,500 per violation; $7,500 per intentional or minor-related violation

2026 US State-Law Developments

Three new comprehensive state privacy laws take effect January 1, 2026:

  • Indiana — the Indiana Consumer Data Protection Act (INCDPA, SB 5, as amended), modeled on Virginia's VCDPA framework, with a 45-day response window and a tiered cure period that sunsets over time
  • Kentucky — the Kentucky Consumer Data Protection Act (KCDPA, HB 15), also Virginia-aligned, with attorney general enforcement and a 60-day notice-and-cure provision
  • Rhode Island — the Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), broader in applicability than the Virginia model and enforced by the state Attorney General

By January 1, 2026, the US comprehensive state privacy roster includes California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, Tennessee, New Jersey, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island (with several more effective later in 2026 or 2027). Candidates are not expected to memorize every state's text, but should know the convergent rights pattern (access, deletion, correction, opt-out of sale/targeted advertising, sensitive-data opt-in or limit, non-discrimination) and the divergent enforcement model (state AG vs. dedicated agency like the CPPA).

California 2026: ADMT, Risk Assessments, Cybersecurity Audits, and the Delete Act

The CPPA has finalized or is finalizing several regulatory packages that reshape California privacy operations in 2026:

  • Automated Decisionmaking Technology (ADMT) regulations — give consumers a right to opt out of ADMT used for significant decisions (e.g., employment, housing, financial services) and to access information about ADMT use, with notice and pre-use notification requirements
  • Risk assessments — required for processing that presents significant risk to consumers (e.g., sensitive personal information, sale/sharing, ADMT, training certain AI models); the assessment must be submitted to the CPPA under regulations effective on a compliance calendar tied to processing risk
  • Cybersecurity audits — businesses whose processing creates significant risk to consumers must perform independent annual cybersecurity audits, with phased compliance dates based on business size and risk profile
  • Delete Act platform (SB 362) — requires the CPPA to establish a deletion request mechanism by August 1, 2026, through which consumers can submit a single deletion request that registered data brokers must honor, rather than contacting each broker individually

Worked Scenario

A US-based health app company processes user health data subject to HIPAA (it contracts with covered entities as a business associate) AND personal information of California consumers under CCPA/CPRA. A California user submits a request to delete all their account data.

Correct handling: The company must reconcile two regimes. Under HIPAA, the right of access and amendment exists, but HIPAA does not grant a general right to delete PHI that must be retained for legal, clinical, or business-associate-contract reasons — and a Business Associate may delete only as permitted by its Business Associate Agreement. Under CCPA, the consumer has a right to delete personal information, but the CCPA's business-purpose and legal-obligation exemptions allow retention where another law requires it. The compliant outcome is to delete data not required to be retained under HIPAA or other law (e.g., marketing preferences, non-health metadata not subject to a retention obligation), to honor the deletion to the extent permitted, and to provide the consumer with a clear explanation of what was deleted and what was retained and why (transparency under both regimes). Conflating the two regimes — either refusing everything because 'HIPAA controls' or deleting everything because 'CCPA says delete' — is wrong.

Worked Scenario — Email Marketer and CAN-SPAM

A US retailer sends a promotional email blast. A recipient clicks 'unsubscribe' on Tuesday. The retailer's email platform removes the address from the active send list the following Wednesday — nine calendar days, which is six business days. The email includes the company's physical postal address and a clearly labeled advertisement subject line.

Compliant outcome: The unsubscribe was honored within 10 business days (CAN-SPAM), the postal address and subject-line requirements are met, and the opt-out mechanism was functional. Note that CAN-SPAM's opt-out model differs from GDPR's opt-in/consent model — under GDPR, the retailer would need a lawful basis (consent or legitimate interest) to send the marketing in the first place, while CAN-SPAM allows sending until opt-out.

Statutory Response Deadlines (days) by Regime
Test Your Knowledge

Which statement correctly distinguishes HIPAA from the other regimes for purposes of a CIPM candidate?

A
B
C
D
Test Your Knowledge

Which 2026 development is correctly paired with its operative date and authority?

A
B
C
D