Rights need a workflow

A privacy policy should not only name rights. It should tell people how to exercise them, where to send the request, and what information may be needed to verify identity. The best rights language is connected to a real internal process.

For SaaS teams, that process should identify the request owner, response timeline, verification steps, systems to search, processors to contact, and cases where a request may be limited by another legal obligation or by the rights of others.

Access and portability are different

The right of access under Article 15 lets a person confirm whether their personal data is processed and receive information such as purposes, categories, recipients, retention, rights, source information, and certain automated decision-making details.

Portability under Article 20 is narrower. It applies to data the person provided to a controller, where processing is based on consent or contract and carried out by automated means. A policy should avoid implying that every internal record is portable in the same way.

Erasure has exceptions

The right to erasure is important, but it is not absolute. Article 17 includes grounds for erasure and also exceptions, such as where processing is necessary for legal obligations, certain public interest reasons, freedom of expression and information, or legal claims.

A useful SaaS policy explains this in plain language. Users can request deletion, but some records may need to be retained for billing, security, dispute resolution, tax, accounting, or legal purposes until the relevant reason expires.

Objection and withdrawal are easy to miss

When processing relies on legitimate interests or public task, Article 21 gives people a right to object in certain circumstances. For direct marketing, the objection right is especially strong and should be presented clearly.

Where processing relies on consent, people should be told they can withdraw consent at any time, without affecting processing that happened before withdrawal. The product should make that withdrawal practical, for example through email preferences or cookie settings.

Rights text should match product controls

If users can update profile data in the app, the policy can point them to that self-service path while still offering a contact route. If deletion requires support involvement, the policy should not pretend there is an automated button.

Rights handling improves when legal language, support macros, admin tooling, and backend deletion behavior are aligned. Otherwise, the policy promises one thing while the team has to improvise when a request arrives.