Notification Obligation Regarding Rectification or Erasure
This is a duty on an organisation that controls personal data to tell each third party it has shared that data with when it later corrects, deletes, or restricts the use of that data. In this way, corrections and deletions can flow through to others who also hold copies. The individual can also ask the organisation to identify who those recipients are.
Under Article 19 of the GDPR (and the corresponding provision of the UK GDPR), the controller shall communicate any rectification or erasure of personal data, or restriction of processing, carried out in accordance with Articles 16, 17(1) and 18, to each recipient to whom the personal data has been disclosed. Based on the evidence provided, this obligation applies unless doing so proves impossible or involves disproportionate effort; the precise wording of that limitation and any exceptions should be verified against the current official text. The Article also provides that the controller shall inform the data subject about those recipients if the data subject requests it. This provision operates as a downstream corollary to the rights of rectification (Article 16), erasure (Article 17), and restriction of processing (Article 18); the exact scope of what counts as 'impossible or disproportionate effort' is fact-specific and may be subject to regulatory guidance and assessment.
Why it matters
Article 19 addresses a practical gap that individual rights would otherwise leave open: when personal data has been shared with others, correcting or deleting it in one place does not automatically fix every copy that exists downstream. Without a duty to notify recipients, an individual could successfully exercise a right to rectification (Article 16), erasure (Article 17(1)), or restriction of processing (Article 18) against one controller, yet inaccurate or unlawfully retained data could continue circulating among the parties to whom it was disclosed. This provision is what makes those rights meaningful across a data-sharing chain rather than only at a single point.
For organisations, the obligation turns rights handling into a process that must extend beyond internal systems. When a controller rectifies, erases, or restricts data, it generally must communicate that change to each recipient to whom the data was disclosed, unless doing so proves impossible or involves disproportionate effort. The precise boundaries of that limitation are fact-specific and should be assessed case by case; the exact wording and any exceptions should be verified against the current official GDPR and UK GDPR text. In practice this means controllers need to know, and be able to reconstruct, who received particular data in order to satisfy the duty.
The Article also gives the individual a further lever: on request, the controller must inform the data subject about the recipients to whom these changes were communicated. This transparency element allows individuals to understand and, where relevant, pursue the propagation of a correction or deletion. Because what counts as 'impossible or disproportionate effort' may be subject to regulatory guidance and interpretation, organisations should document their reasoning where they rely on that limitation.
Who it's relevant to
Inside Notification Obligation Regarding Rectification or Erasure
Common questions
Answers to the questions practitioners most commonly ask about Notification Obligation Regarding Rectification or Erasure.