Most people have heard of the right to delete their personal data — the idea that you can ask a company to erase information it holds about you. That right exists in various forms under GDPR in Europe, CCPA in California, and an expanding set of state laws across the United States.
Fewer people know about a related right that’s arguably more immediately useful: the right to correct inaccurate personal data.
If a company has wrong information about you — an incorrect address, the wrong income estimate, an inaccurate inference about your health or location history — you have the legal right in a growing number of jurisdictions to demand they fix it. And as of July 1, 2026, Utah expanded its consumer privacy law to explicitly include this right alongside new data portability provisions.
Understanding what this right covers, how to exercise it, and why it matters for the personal data stored in cloud services and apps is worth a few minutes.
What the Right to Correct Actually Means
The right to correct is distinct from the right to delete. When you request deletion, you’re asking the company to remove personal data from its systems. When you request correction, you’re asking the company to update inaccurate data it holds about you with accurate information.
This matters in different situations than deletion does. You might not want a company to delete its record of you entirely — perhaps you need the account, or the deletion would cause you to lose access to services or documents you use. But you might have discovered that the company’s data about you is wrong in a way that affects how you’re treated.
Under data rights frameworks that include correction rights, companies must:
- Acknowledge the request within a specified timeframe (typically 45 days under US state laws)
- Review the claimed inaccuracy and the evidence you provide
- Correct the inaccuracy or explain why they’ve determined the data is in fact accurate
- Notify third parties they’ve shared the data with, where required
The specific obligations and timeframes vary by law, but the underlying principle is consistent: personal data held about you should be accurate, and you have a right to challenge it when it’s not.
Which Laws Include Correction Rights
The correction right isn’t universal, but it’s in more laws than most people realize:
GDPR (European Union). Article 16 of the GDPR provides a right to rectification — you can demand correction of inaccurate personal data held about you. Companies subject to GDPR (essentially any company processing data about EU residents) must comply.
CCPA / CPRA (California). The California Privacy Rights Act, which updated CCPA and took effect in 2023, added a right to correction. California residents can request that businesses correct inaccurate personal information held about them.
Colorado, Connecticut, Virginia, and others. Most US states with comprehensive consumer privacy laws — now numbering over twenty — include correction rights. Colorado’s CPA, Connecticut’s CTDPA, and Virginia’s VCDPA all include the right.
Utah (effective July 1, 2026). Utah amended its Consumer Privacy Act to explicitly include a right to correction, as part of the same legislation (HB 418) that added data portability requirements for social media. Utah residents can now formally request correction of inaccurate personal data from companies covered by the law.
If you’re in the EU or any US state with a comprehensive privacy law, there’s a reasonable chance you have correction rights. The practical coverage is broader than most people assume.
What Personal Data Is Actually Wrong About You
Before you can use a correction right, it helps to understand what companies have about you and what’s likely to be inaccurate. The categories where errors are most common:
Data broker profiles. Companies like Acxiom, Experian, and hundreds of smaller data brokers compile profiles of individuals from public records, purchase history, loyalty programs, and other sources. These profiles often include estimated income, household composition, interests, health conditions, and political affiliation. Errors are extremely common — the inference algorithms aren’t accurate, and the underlying data sources make mistakes.
Credit files. The FCRA (Fair Credit Reporting Act) already provides a robust dispute process for credit report errors, and errors in credit reports remain common. If you’ve never reviewed your credit reports, the free reports available through AnnualCreditReport.com are worth checking.
Advertising profiles. Google, Meta, and other advertising-supported platforms build inferred profiles of users based on behavior. These inferences include demographic attributes, interests, and predicted behaviors. The inference accuracy is highly variable, and the profiles often contain significant errors.
Health inferences. Some data brokers sell health-related inferences derived from purchase history and other behavioral data. These inferences — often used in insurance and marketing contexts — are frequently wrong and can have serious consequences.
Address and contact data. This seems mundane, but inaccurate addresses in company records cause practical problems: billing errors, account lockouts, difficulty with delivery. Companies often update addresses through third-party address verification services that make mistakes.
Photos and content. For cloud storage and social media services, incorrect metadata — wrong date, wrong location, incorrectly identified faces — can be meaningfully wrong in ways that affect how your memories are organized, surfaced, and accessed.
How to Submit a Correction Request
Exercising a correction right requires knowing how the company accepts these requests. Under most privacy laws, companies must provide accessible mechanisms for submitting data rights requests, including correction requests.
Start with the company’s privacy center or privacy settings. Most large companies have a dedicated privacy page, often accessible at company.com/privacy or through account settings. This is usually where data rights requests are submitted.
Look for the “data rights” or “privacy rights” section. The terms vary: “data rights,” “privacy rights request,” “submit a data subject request,” “exercise your privacy rights.” All of these typically cover correction rights where they’re required by law.
Provide evidence of the inaccuracy. A correction request is more likely to succeed, and to succeed faster, if you can document what’s wrong and what the correct information is. A utility bill at your correct address, a medical record contradicting an inaccurate health inference, or a screenshot of the incorrect data alongside accurate information all help.
Cite the applicable law. Saying “I am exercising my right to correction under the CCPA” or “I am submitting this request under Article 16 of the GDPR” makes clear that you’re asserting a legal right, not making a support request. This typically triggers a different handling process with legally mandated response times.
Keep records. Save the confirmation of your request and any response. If the company fails to respond within the required timeframe or denies the request without adequate justification, you may have grounds for a complaint to the relevant regulatory body (the California Privacy Protection Agency, the state Attorney General, or the EU supervisory authority for your member state).
The Limits of the Right
The correction right is real and useful, but it has limits worth knowing:
It applies to factually inaccurate data, not to data you dislike. If a company infers you’re interested in travel because you’ve bought travel gear, you can’t demand they change that inference because you find it intrusive. If they infer you live at an address where you don’t actually live, that’s the kind of factual inaccuracy the right is designed to address.
Inferences and predictions are contested ground. Whether inferred data about you (a predicted income, an estimated age, a health condition inference) is “personal data” subject to correction rights is still an evolving legal question. Some laws treat inferences differently than factual data. But the trend, especially under GDPR’s broad definition of personal data, is to treat many inferences as personal data subject to rights.
Small businesses and exempt categories. Many state privacy laws include thresholds — companies below a certain size, or those processing fewer than a threshold number of consumer records, may not be covered. HR data (data about employees rather than consumers) is often separately regulated or excluded from consumer privacy laws.
The company can dispute your request. If the company has evidence that the data they hold is actually accurate, they can deny your correction request with an explanation. You’re entitled to know why the request was denied and to appeal in some jurisdictions.
Why This Matters for File and Photo Storage
If you use cloud storage, photo apps, or personal productivity tools, you’ve shared personal data with these services. Some of that data is the content you’ve stored (your files, photos, notes). Some is metadata and derived data (when you access files, what device you use, where you were when you took photos, what the AI thinks is in your images).
Incorrect metadata about your stored content — wrong dates on photos, incorrect locations, inaccurate AI-generated captions or tags — is exactly the kind of thing correction rights are designed to address.
More broadly, the expansion of correction rights (Utah’s July 2026 addition is part of a pattern, not an outlier) reflects a growing legal consensus that personal data should be accurate and that data subjects should have meaningful tools to ensure it is.
Understanding and exercising these rights isn’t just valuable in abstract terms. Inaccurate data about you affects credit decisions, insurance premiums, advertising targeting, and how AI systems interact with you. The effort to request corrections where data is wrong is modest; the potential benefit is real.
Using the California DELETE Platform as a Starting Point
For US residents wanting to identify what data brokers hold about them — including potentially inaccurate information — California’s DELETE (Data Elimination and Limiting Extensive Tracking of Everyone) platform is a useful starting point.
The platform, launched by the California Privacy Protection Agency, allows California residents to send a single opt-out or deletion request to hundreds of registered data brokers simultaneously. Starting August 1, 2026, registered data brokers are required to check the platform at least every 45 days and process deletion requests within 90 days.
If you can see what a data broker holds about you (the access right) and it’s wrong (the correction right), and you’d rather the data not exist at all (the deletion right), you now have legal pathways to address all three. The infrastructure for exercising these rights is more developed than most people realize — it just requires knowing they exist.
The Practical Takeaway
The right to correct is underused primarily because most people don’t know they have it. The legal framework has been building for years — GDPR in 2018, CCPA/CPRA in California, and now over twenty states with their own versions — and Utah’s July 2026 addition is a sign that the trend is solidifying rather than reversing.
If you’ve suspected a company has wrong information about you, or if you’ve noticed an inaccuracy in your profile with a service you use, you likely have a legal right to demand a fix. The mechanism is available; the effort required is modest; and the companies that hold your data are legally obligated to respond.
That’s a more useful privacy tool than most people ever think to reach for.