Practical guide

How to draft a personal data rectification request with AI

4 min read · Updated June 2026 · Editorial oversight: Avv. Federico Papa

The rectification request is an essential tool provided by Art. 16 of EU Regulation 2016/679 (GDPR) to ensure the accuracy and updating of personal data processed by third parties. This right allows the data subject to obtain from the controller the correction of inaccurate information or the completion of incomplete data without undue delay. Exercising this right is fundamental to preserving the integrity of an individual's information assets and preventing prejudice resulting from processing based on untruthful data. The legal professional must structure the document with technical precision, ensuring that the request is clear and supported by objective elements to facilitate compliance by the controller.

In brief

A rectification request under Art. 16 GDPR, draftable with AI support, ensures the correction of inaccurate personal data or completion of incomplete information. The document must identify the data subject, controller, and DPO, describing inaccuracies and replacement data. Pursuant to Art. 19 GDPR, controllers must notify third-party recipients of the rectification. Under Art. 12 GDPR, responses are mandatory within one month, extendable by two months for complex cases. Non-compliance allows for complaints to the Data Protection Authority or judicial remedies. Transmission requires PEC or registered mail for legal proof.

The steps

  1. 1.

    Identification of the parties involved

    It is necessary to precisely indicate the personal and contact details of the applicant, specifying their status as data subject. The data controller must also be correctly identified, including its corporate name or the professional's identification details and, if available, the contact details of the Data Protection Officer (DPO). A correct heading ensures that the request is directed to the entity legally responsible for updating the information.

  2. 2.

    Analysis of inaccuracy or incompleteness

    The core of the request lies in the precise identification of the personal data currently processed by the controller that is considered inaccurate, obsolete, or incomplete. The lawyer must specifically describe the nature of the error, distinguishing between a mere formal inaccuracy and an information gap that requires substantial integration. This section must be drafted with maximum clarity to avoid ambiguous interpretations or disputes by the recipient.

  3. 3.

    Formulation of the rectification request

    The request must be formulated unambiguously, specifying the correct data or the supplementary information to replace the erroneous entries. It is appropriate to expressly cite Art. 16 GDPR to qualify the action legally and urge the controller to proceed without undue delay. The accuracy of the replacement data is essential for the effective execution of the requested compliance.

  4. 4.

    Request for notification to third-party recipients

    Pursuant to Art. 19 GDPR, it is necessary to demand that the controller communicate the rectification to each recipient to whom the personal data may have been disclosed. The professional should also request that the controller inform the data subject about these recipients, should the data subject explicitly request it, to ensure full control over data circulation. This clause ensures that the error does not continue to produce harmful effects with third parties.

  5. 5.

    Definition of the response deadline

    The request must remind the controller of the obligation to provide information on the actions taken within one month of receipt, pursuant to Art. 12 GDPR. In cases of particular complexity or a high number of requests, it should be specified that this deadline may be extended by a further two months, subject to timely reasoned notification. Explicitly indicating the statutory deadline serves to put the controller on notice and lay the groundwork for any subsequent administrative or judicial remedies.

  6. 6.

    Transmission and supporting documentation

    Transmission must occur via methods that guarantee legal proof of receipt, such as Certified Electronic Mail (PEC) or registered mail with acknowledgment of receipt. A copy of the applicant's identity document may be attached to the request, where necessary to confirm identity in case of reasonable doubts, along with any evidentiary documentation certifying the accuracy of the proposed replacement data. Complete supporting documentation prevents dilatory objections by the controller.

Legal basis: Art. 12 GDPRArt. 16 GDPRArt. 19 GDPR

The template structure

The standard sections that make up the document. The full template can be opened and completed directly on edit.legal.

  1. Sender

    Identification data of the requesting data subject, including tax code and contact details for communications.

  2. Data Controller

    Details of the controller and any DPO, specifying the registered office or PEC address.

  3. Subject: right to rectification

    Formal exercise of the right to rectification and completion of personal data under Art. 16 GDPR.

  4. Inaccurate or incomplete data

    Analytical description of inaccurate or incomplete personal data currently processed and specification of the corresponding correct data.

  5. Rectification request

    Formal request for rectification or completion and concurrent request for notification of the change to third-party recipients under Art. 19 GDPR.

  6. Place, date, signature

    Signature of the applicant with attached copy of a valid identity document.

Mistakes to avoid

  • Failure to specify the correct data: sending a generic request without providing exact replacement data prevents the controller from executing the request.
  • Omission of the Art. 19 GDPR request: failing to demand notification of the rectification to third-party recipients severely limits the effectiveness of the remedy.
  • Absence of proof of identity: failing to attach an identity document may justify the controller in postponing the request due to reasonable doubts regarding the applicant's identity.
  • Incorrect identification of the controller: addressing the request to an entity lacking decision-making authority over the processing nullifies the legal action.

Frequently asked questions

What are the costs for exercising the right to rectification?

Exercising this right is free of charge under Art. 12 GDPR. However, where requests are manifestly unfounded or excessive, in particular because of their repetitive character, the controller may charge a reasonable fee based on administrative costs.

What happens if the controller does not respond within one month?

If the one-month deadline expires without a response, the data subject may lodge a complaint with the Data Protection Authority or bring an action before the courts.

Is it possible to rectify data that constitutes a subjective opinion or evaluation?

The right to rectification primarily applies to objective data. Where processing involves subjective evaluations or professional opinions, completion may consist of adding a note reflecting the data subject's opposing stance or clarification.

Avv. Federico Papa
Editorial oversight: Avv. Federico Papa·ICAM

What edit.legal automates

  • Automatic insertion of legal references to Articles 12, 16, and 19 GDPR to ensure the legal soundness of the document.
  • Structured variable fields for an analytical description of the inaccurate data and the corresponding correction.
  • Automatic generation of the third-party notification clause in compliance with the transparency obligations set out in the regulation.

Put edit.legal to the test on actual cases

Try edit.legal for free on an active case. No credit card required.

Try edit.legal for free