« Cookies are used by us, » « Your data is important to us, » the checked box, the form asking for too much information: The General Data Protection Regulation (GDPR) is five years old, and for most people, it boils down to annoying banners. It misses the point: This regulation has given you REAL and CONCRETE RIGHTS over your data — the right to know what is held about you, to obtain a copy of it, to have it erased, and to refuse. Rights that are almost no one exercises due to lack of knowledge. The citizen’s guide to taking back control — your rights, how to exercise them, and when they matter.
Your rights, concretely (and what they allow)
The GDPR arms you — the useful inventory: The right of access — knowing what an entity holds about you and GETTING A COPY (the bank, the social network, the employer, the online store, the data broker: The request reveals the extent — often staggering: Our guides on car, health — the exercise that opens the eyes); the right to rectification (false data corrected — outdated address, incorrect information); the right to be forgotten (« right to be erased » — the deletion of your data, subject to conditions: The account really closed, the content dereferenced from search engines); the right to object (refusing a processing — marketing at the forefront: « I object to the use of my data for advertising purposes » is OPPOSABLE), the right to limitation and the right to portability (retrieving your data in a reusable format to take elsewhere — Our guides: Simplified digital moving); and the rights on automated decisions (refusal of credit or selection by algorithm alone — the right to human intervention and explanation — an increasing issue in the age of AI). The framework — these rights are EXERCISED FREE OF CHARGE (except for abusive requests), the entity has a deadline to respond (one month in principle), and an unjustified refusal opens the way to a complaint: The regulator (the CNIL in France) is the enforcer — its intervention is free and real (fines fall — the power dynamic exists). These rights are not theoretical: They are EXERCISED in a single email — still, one must know that they exist.
The GDPR gives you real power over your data. You can ask companies to show you what they know, correct mistakes, delete your data, or stop using it for ads. You can even take your data elsewhere. These rights are free, and companies must respond quickly. If they ignore you, you can complain to authorities like the CNIL, which can fine them.
Imagine you want to leave a social network. You can email them and ask for a copy of all your data (right of access). If they don’t respond in a month, you can file a complaint with the CNIL. In 2023, the CNIL fined a major tech company €60 million for ignoring such requests.

Exercising them: The practical user guide
From theory to action: The typical request — an email (or form) to the « data protection officer » (DPO) of the entity (often dpo@… or in the privacy policy): « I exercise my right of access/deletion/objection — please communicate/suppress the data concerning me » (Our guides on letters: AI writes the model, to be personalized — and the CNIL provides official templates); the important uses — the right of access to UNDERSTAND (what does my insurance, my employer, this app know? — Our guides), the objection to marketing to cut the tap (newsletters, telemarketing — stronger than unsubscribing on a case-by-case basis), the deletion of the account QUITTED (closing is not always enough — the deletion ASKED goes further: Our guides on dormant accounts — each dead account is a data that sleeps), the portability to MOVE (retrieved and taken data — the end of captivity by inertia); the recourse — silence or refusal are contested: The follow-up, then the COMPLAINT to the CNIL (online, free — the regulator investigates, sanctions, makes jurisprudence: Our guides on disputes — the power dynamic is real, giants have paid), and emerging collective actions; and the reasonable rhythm — one does not ask for everything from everyone (energy is put on what MATTERS: sensitive entities — insurance, employer, data brokers —, accounts to close properly, marketing to cut); the informed citizen exercises targeted, not crusading.
The good reflex. Do the right of access experience on ONE entity that intrigues you — the most used social network, or the data broker you suspect: The request sent, the copy received (the file of what is known about you — deductions, ad categories, history): The effect is pedagogical and lasting (one no longer clicks « I accept » the same way after SEEING what it produces). It is the digital equivalent of reading the label: Once one has looked, one chooses differently — and the exercise, free, transforms the passive citizen into a citizen who knows what he gives.

Cookie banners and consents: Decode the game
The daily topic, decoded: The consent must be FREE and INFORMED — the rules behind the banners: Refusal must be as easy as acceptance (the « Reject all » button at the same level as « Accept all » is an OBLIGATION — the banner that hides refusal in three sub-menus is non-compliant and should be reported: Our guides), pre-checked consent is forbidden (the box already checked is not a consent), and the service must not be conditioned on the acceptance of advertising (the « accept or pay » is a legal debate in progress); the practical reflex — « Reject all » or « Continue without accepting » by default (two seconds — the content displays the same in the vast majority of cases: Our guides on browsers), essential cookies distinguished from trackers (the first make the site work, the second follow you — Our guides), and periodic cleaning (Our guides — the accumulation of consents and trackers is purged); the useful distinction — cookies (navigation trackers — the subject of the banners) versus DATA YOU PROVIDE (forms, accounts — the real big subject: Our guides on minimization — give only what is necessary, question the « mandatory » fields); and clarity — the GDPR has made the banners visible (the progress: We KNOW we are followed) without eliminating the following (the fatigue of consent is real — progress towards global browser settings is ongoing): The annoying banner is the visible symptom of a real right — learn to play it in three seconds rather than suffer it.
The citizen facing tomorrow: AI, data, and vigilance
The fronts that open: The AI and your data — the models trained on massive data (sometimes yours — public content, creations: The debate on training and consent, opposition rights are organizing — Our guides on AI), the automated decisions that multiply (credit, hiring, insurance: The right to explanation and human becomes central: Our guides), and the coveted health and behavior data (Our guides on health, cars: Assurance vigilance); the advancing regulations — the GDPR completed (the AI regulation, the digital services and markets regulation: Europe is building digital law: The citizen now has an arsenal, underutilized), and the enforcement that strengthens (record fines, warnings: The real power dynamic): The citizen’s role — informed (known rights are living rights: This article is a link in the chain), exercising (the right of access that educates, objection that cuts, complaint that makes jurisprudence: Each individual exercise strengthens the collective), supporting (the associations defending digital freedoms do the work of vigilance and litigation: Their audience and support matter: Our guides), and exemplary (protect your own data, but also those of others: Proximity, children, contacts: Sharing someone else’s data without their consent is a breach, Our guides): And the overall posture — neither resignation (« they know everything anyway » — false and demobilizing: Rights work, fines fall, practices change) nor illusion (the GDPR does not make you invisible — it makes you an ACTOR): The digital citizen is not a defenseless product — they have rights, a regulator, and the law on their side: Still, one must use them.


Be wary of fake GDPR requests and others’ data. Two blind spots: The GDPR is also a PRETEXT for fraud — fake emails « confirm your personal data in accordance with the GDPR » (hacking that takes on legality — Our guides: No compliance is done through a received link; real requests come from YOU to the entity, not the other way around), and fake « data deletion services » for pay (what you do for free): The mirror of your rights — Others’ data are ALSO protected: Publishing a photo, address, message of a third party without their consent violates THEIR rights (Our guides on images — responsibility goes both ways: The GDPR protects you, but also obliges you — the directory, shared contact list, group where one passes on contact information). The informed citizen knows their rights and their duties: This is the condition for a digital world where everyone is protected — including you, by the respect others owe you in return.
Frequently asked questions
Does the right to be forgotten really work (even with the giants)?
Yes, with limits: Entities MUST erase upon justified request (unnecessary data — the closed account, marketing), with legitimate exceptions (legal preservation obligations — accounting, certain archives): An unjustified refusal is contestable (CNIL). The dereferencing of search engines (the « right to be forgotten » of search results) also works under conditions — the balance with public information: Requests are examined on a case-by-case basis and result in real outcomes.

Is it worth it for an individual, or is it reserved for activists?
It is worth it targeted: The objection to marketing (the tap cut — concrete gain), the deletion of accounts quit (Our guides on hygiene), the right of access on a sensitive entity (understand and decide). No need to be an activist — just know that an email is enough: An unused right is a dead right, and exercising it on what concerns you is common sense, not activism.
Outside Europe, are my data protected?
The GDPR applies to entities targeting EU residents (even if based elsewhere — its extraterritorial reach is real), and data transfers outside the EU are regulated (protection mechanisms — a permanent legal challenge): On travel or with foreign services, your EU rights follow in part, with gray areas. Our travel guides (minimal accounts, caution with unknown services) complete the legal framework — the law protects, behavior also matters.

What to take away
The GDPR is not just an annoying banner — it is an arsenal of REAL and FREE RIGHTS: Access (know and obtain a copy of what is held about you — the exercise that opens the eyes), rectification, deletion (the account really closed), objection (marketing cut at the source), portability (moving your data), and the right to human in face of automated decisions — all in a single email to the DPO, with the CNIL as recourse that brings down fines. Cookie banners are played in three seconds (« Reject all » mandatory, pre-checked forbidden), the fronts of tomorrow open (AI, automated decisions, health and behavior data), and the citizen has the choice between resignation (false) and action (effective). With the mirror of duties: Your rights protect others too. Do it once — an access request, a right exercised: You will never again be a passive product, but a citizen who knows and acts.


Want to understand and master the technologies that change your daily life? Our training programs enlighten you.
Leave a Reply
You must be logged in to post a comment.