{"id":15307,"date":"2024-10-02T20:17:20","date_gmt":"2024-10-02T18:17:20","guid":{"rendered":"https:\/\/www.cookiebot.com\/en\/?p=15307"},"modified":"2026-03-12T09:16:11","modified_gmt":"2026-03-12T08:16:11","slug":"gdpr-data-subject-rights","status":"publish","type":"post","link":"https:\/\/www.cookiebot.com\/en\/gdpr-data-subject-rights\/","title":{"rendered":"What you need to know about the GDPR\u2019s data subject rights"},"content":{"rendered":"\n<p>Personal data is an integral part of nearly every online service and transaction. Websites, apps, and other connected platforms collect this data for companies to learn about user behaviors and provide better user experiences and services. However, with this comes the need to protect individuals\u2019 privacy and personal data. This is where the General Data Protection Regulation (GDPR) comes in, offering individuals a set of eight data protection rights aimed at ensuring their data is handled securely and transparently.<\/p>\n\n\n\n<p>These data subject rights under the GDPR give people control over their personal data. Whether you\u2019re a website owner or other small business, it\u2019s important to understand what data subject rights are and how they function.<\/p>\n\n\n\n<p>In this blog, we\u2019ll break down the key rights under the GDPR, explain who is protected, and discuss how companies can comply with GDPR individual rights requests.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-are-data-subject-rights-under-the-gdpr\">What are data subject rights under the GDPR?<\/h2>\n\n\n\n<p>The General Data Protection Regulation (GDPR) is a legal framework designed to protect individuals and their personal data. Central to this regulation is the empowerment of individuals \u2014 referred to as \"data subjects\" \u2014 by giving them specific rights over their personal data.<\/p>\n\n\n\n<p>These common data subject rights are intended to provide transparency about data access and use, enable individuals to access and control their information, and hold companies accountable for how they handle personal data. The rights outlined in the GDPR have been influential on the drafting of other data privacy laws since the regulation came into force.<\/p>\n\n\n\n<p>These rights give individuals the ability to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>access their personal data<\/li>\n\n\n\n<li>have inaccurate data corrected<\/li>\n\n\n\n<li>request the deletion of their data in certain situations<\/li>\n\n\n\n<li>restrict or object to data processing&nbsp;<\/li>\n\n\n\n<li>transfer their data to another service provider<\/li>\n<\/ul>\n\n\n<div class=\"cta-block cta-block--size-s cta-block--only-buttons cb-ctx--blue\">\n        <div class=\"cta-block__glass\">\n        <div class=\"cta-block__inner\">\n            <div class=\"cta-block__left-column\">\n                                                    <h2 class=\"cta-block__title no-default-margin like-h4\">\n                        Do you understand all the details of the GDPR?                    <\/h2>\n                                                    <div class=\"cta-block__description like-text-md\">\n                        <p>To better understand the GDPR, its key details, and how it affects your company, we\u2019ve compiled a guide that covers everything you need to know.<\/p>\n                    <\/div>\n                                                                                                                                                        <\/div>\n                            <div class=\"cta-block__right-column\">\n                                                                <div class=\"cta-block__buttons\">\n                                                    <div class=\"cta-block__buttons__button-wp\">\n                                <a id=\"54c8681e-bc5d-4cf1-92f4-73314370bf7e\" class=\"cb-button cb-button-size-l cb-button-contained  no-default-link-decoration cb-button-icon-right cta-block__buttons__button\" href=\"https:\/\/www.cookiebot.com\/en\/gdpr\/\" target=\"\">\n<span>Learn more about the GDPR<\/span><\/a>\n                                                            <\/div>\n                                                                        <\/div>\n                                                        <\/div>\n                    <\/div>\n    <\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Who do data subject rights apply to?<\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"770\" height=\"600\" src=\"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2024\/10\/cb_blog_body_770x600_gdpr_data_subj_a.jpg\" alt=\"Who do data subject rights apply to?\" class=\"wp-image-15310\" srcset=\"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2024\/10\/cb_blog_body_770x600_gdpr_data_subj_a.jpg 770w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2024\/10\/cb_blog_body_770x600_gdpr_data_subj_a-300x234.jpg 300w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2024\/10\/cb_blog_body_770x600_gdpr_data_subj_a-768x598.jpg 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/figure>\n\n\n\n<p>GDPR data subject rights apply to any individual residing in the EU\/EEA whose personal data is being processed by a data controller or processor. However, the regulation's scope is extraterritorial, meaning that it extends beyond the borders of the EU and applies to non-EU-based organizations that process the personal data of individuals within the EU.<\/p>\n\n\n\n<p>Individuals that are protected by GDPR data subject rights include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>EU residents<\/strong>: Any individual living in an EU member state whose data is being processed by an organization.<\/li>\n\n\n\n<li><strong>Non-EU citizens within the EU<\/strong>: Even if someone is not an EU citizen, if they are residing in the EU and their data is processed, they are protected by the GDPR.<\/li>\n\n\n\n<li><strong>Individuals outside the EU whose data is processed by EU-based organizations<\/strong>: If an EU organization processes the personal data of non-EU individuals, GDPR still applies.<\/li>\n\n\n\n<li><strong>Non-EU organizations processing EU citizens' data<\/strong>: For example, if a US-based company offers services to EU citizens, it must comply with the GDPR when processing its data.<\/li>\n<\/ul>\n\n\n\n<p>Ultimately, GDPR data subject rights apply to a wide range of individuals and compliance responsibilities lie with many different types of organizations.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What does \u201csubject data\u201d refer to?<\/h2>\n\n\n\n<p>Under the GDPR, \"subject data\" refers to any information that can directly or indirectly identify an individual. This data could be anything that can be used to distinguish a person, either on its own or in combination with other data.<\/p>\n\n\n\n<p>Types of data that fall under the category of \"subject data\" include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Personal Identifiable Information (PII)<\/strong>: <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/personally-identifiable-information-vs-personal-data\/\" target=\"_blank\" rel=\"noreferrer noopener\">Personally identifiable information<\/a> includes data like names, identification numbers, email addresses, phone numbers, and other personal identifiers.<\/li>\n\n\n\n<li><strong>Location data<\/strong>: Information that can track a person\u2019s geographical location, such as GPS data, IP addresses, and mobile phone data.<\/li>\n\n\n\n<li><strong>Online identifiers<\/strong>: <a href=\"https:\/\/www.cookiebot.com\/en\/tracking-cookies\/\">Tracking cookies<\/a>, device IDs, and similar tracking mechanisms used to monitor online behavior.<\/li>\n\n\n\n<li><strong>Biometric data<\/strong>: Fingerprints, facial recognition data, or other biological measurements that can identify a person.<\/li>\n\n\n\n<li><strong>Health data<\/strong>: Information about an individual's physical or mental health, healthcare, or diagnoses.<\/li>\n\n\n\n<li><strong>Financial data<\/strong>: Bank account numbers, credit card information, or any other financial identifiers.<\/li>\n<\/ul>\n\n\n\n<p>The key factor is that subject data relates to a living individual who can be identified, either directly or indirectly, using these details. Any organization that processes this type of data must adhere to the GDPR.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What are the data subject rights under the GDPR?<\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"770\" height=\"650\" src=\"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2024\/10\/cb_blog_body_770x650_gdpr_data_subj_b.jpg\" alt=\"What are the data subject rights under the GDPR?\n\" class=\"wp-image-15311\" srcset=\"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2024\/10\/cb_blog_body_770x650_gdpr_data_subj_b.jpg 770w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2024\/10\/cb_blog_body_770x650_gdpr_data_subj_b-300x253.jpg 300w, https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2024\/10\/cb_blog_body_770x650_gdpr_data_subj_b-768x648.jpg 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/figure>\n\n\n\n<p>The GDPR grants individuals eight core data subject rights. These rights are designed to provide transparency, control, and security over personal data processing.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. The right to be informed<\/h3>\n\n\n\n<p>Per <a href=\"https:\/\/gdpr.eu\/article-13-personal-data-collected\/\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 13 GDPR<\/a>, individuals have the right to be informed about how their personal data is collected, used, and shared. This means companies must provide clear, concise, and transparent information about their data processing activities.<\/p>\n\n\n\n<p>This information is typically provided through <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/privacy-notice\/\" target=\"_blank\" rel=\"noreferrer noopener\">privacy notices<\/a> or <a href=\"https:\/\/www.cookiebot.com\/en\/how-to-write-a-privacy-policy\/\">privacy policies<\/a>, which must include details such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>What personal data is being collected<\/li>\n\n\n\n<li>The purposes for which the data is processed<\/li>\n\n\n\n<li><a href=\"https:\/\/usercentrics.com\/knowledge-hub\/the-eu-general-data-protection-regulation\/#legal-bases-and-legitimate-interest-in-the-general-data-protection-regulation-18\" target=\"_blank\" rel=\"noreferrer noopener\">The legal basis for processing<\/a><\/li>\n\n\n\n<li>Who the data will be shared with<\/li>\n\n\n\n<li>How long the data will be retained<\/li>\n\n\n\n<li>Individuals\u2019 rights and how to exercise them<\/li>\n<\/ul>\n\n\n\n<p>Organizations must ensure that this information is easy to understand and accessible at the time of data collection.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. The right of access<\/h3>\n\n\n\n<p>Under <a href=\"https:\/\/gdpr.eu\/article-15-right-of-access\/\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 15 GDPR<\/a>, individuals have the right to access their personal data held by an organization. This right, also known as a Subject Access Request (SAR) or Data Subject Access Request (DSAR), enables individuals to request a copy of their data and information on how it is being processed.<\/p>\n\n\n\n<p>When a person submits a request, a company must provide:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Confirmation that their data is being processed<\/li>\n\n\n\n<li>A copy of the personal data<\/li>\n\n\n\n<li>Additional information, such as the purpose of processing, categories of personal data collected and processed, and details of any data sharing<\/li>\n<\/ul>\n\n\n\n<p>Companies must respond to access requests within one month, although extensions may apply, but this depends on the scenario at hand and comes with communication requirements to the data subject.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. The right to rectification<\/h3>\n\n\n\n<p>If an individual discovers that their personal data is inaccurate or incomplete, they have the right under <a href=\"https:\/\/gdpr.eu\/article-16-right-to-rectification\/\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 16 GDPR<\/a> to request its correction. A company is then required to rectify the information promptly, ensuring that any inaccurate or incomplete data is corrected or completed.<\/p>\n\n\n\n<p>This right is crucial for maintaining data accuracy and ensuring that organizations only process up to date information.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4. The right to erasure (or the right to be forgotten)<\/h3>\n\n\n\n<p>The right to erasure, also known as the \"right to be forgotten\" under <a href=\"https:\/\/gdpr.eu\/article-17-right-to-be-forgotten\/\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 17 GDPR<\/a>, enables individuals to request the deletion of their personal data in certain circumstances. These circumstances include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The data is no longer necessary for the purpose for which it was collected<\/li>\n\n\n\n<li>The individual withdraws their consent, and there is no other valid legal basis for processing<\/li>\n\n\n\n<li>The individual objects to the processing, and there are no overriding legitimate legal bases<\/li>\n\n\n\n<li>The data has been unlawfully processed<\/li>\n\n\n\n<li>The data must be erased to comply with a legal obligation<\/li>\n<\/ul>\n\n\n\n<p>It\u2019s important to note that the right to erasure is not absolute. In some cases, companies may have legal grounds or regulatory requirements to retain the data, such as for compliance with legal obligations or the defense of legal claims.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5. The right to restrict processing<\/h3>\n\n\n\n<p>The right to restrict processing under <a href=\"https:\/\/gdpr.eu\/article-18-right-to-restriction-of-processing\/\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 18 GDPR<\/a> enables individuals to limit the way their personal data is processed. This means that an organization may store the data but cannot use it for any further processing unless certain conditions are met.<\/p>\n\n\n\n<p>Individuals can request a restriction of processing if:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>They contest the accuracy of the data (until the organization verifies its accuracy)<\/li>\n\n\n\n<li>The processing is unlawful, but the individual does not want the data to be erased<\/li>\n\n\n\n<li>The organization no longer needs the data, but the individual requires it to establish, exercise, or defend a legal claim<\/li>\n\n\n\n<li>The individual has objected to processing (pending the organization\u2019s verification of whether legitimate grounds override the individual\u2019s rights)<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">6. The right to data portability<\/h3>\n\n\n\n<p>Data portability enables individuals to request the transfer of their personal data from one organization to another under <a href=\"https:\/\/gdpr.eu\/article-20-right-to-data-portability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 20 GDPR<\/a>. This right is designed to enhance user control over personal data and facilitate the free movement of information between service providers.<\/p>\n\n\n\n<p>The right to data portability applies when:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The data is processed based on consent or a contract<\/li>\n\n\n\n<li>The processing is carried out by automated means<\/li>\n<\/ul>\n\n\n\n<p>Upon receiving a request to port data, organizations must provide the data in a structured, commonly used, and machine-readable format.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">&nbsp;7. The right to object<\/h3>\n\n\n\n<p>People have the right to object to the processing of their personal data in certain circumstances under <a href=\"https:\/\/gdpr.eu\/article-21-right-to-object\/\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 21 GDPR<\/a>. This right applies when processing is based on legitimate interest, direct marketing, or research purposes.<\/p>\n\n\n\n<p>If an individual objects to direct marketing, the organization must stop processing the data for that purpose immediately. For other objections, the organization may continue processing if it can demonstrate compelling and legitimate grounds that override the individual's rights.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">8. Rights related to automated decision-making and profiling<\/h3>\n\n\n\n<p>Under <a href=\"https:\/\/gdpr.eu\/article-22-automated-individual-decision-making\/\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 22 GDPR<\/a>, the law provides individuals with the right not to be subject to decisions based solely on automated processing, including profiling, if these decisions have legal or significant effects.<\/p>\n\n\n\n<p>Organizations must ensure that individuals have the opportunity to request human intervention, express their point of view, and challenge automated decisions.<\/p>\n\n\n\n<p>This right is particularly relevant in industries like finance, where automated systems may make decisions about creditworthiness, and in the recruitment process, where algorithms may be used to evaluate candidates.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to respond to data subject rights requests?<\/h2>\n\n\n\n<p>Knowing how to handle a data subject rights request properly is a critical aspect of GDPR compliance. When a company receives a GDPR individual rights request, there are several best practices to follow:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Verification of the individual<\/strong>: Before responding to any request, verify the identity of the individual to ensure that the request is legitimate.<\/li>\n\n\n\n<li><strong>Timely response<\/strong>: GDPR requires that organizations respond to data subjects rights requests within one month. Under certain cases, this period may be extended by an additional two months, but the individual involved must be informed of the delay.<\/li>\n\n\n\n<li><strong>Providing clear information<\/strong>: When fulfilling requests, it\u2019s essential to provide the requested information in a concise, transparent, and easy to understand format.<\/li>\n<\/ul>\n\n\n\n<p>Companies should implement procedures for handling EU data subject rights requests to avoid delays or incomplete responses, and mitigate data breach risks, as these could result in noncompliance penalties.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Who enforces GDPR data subject rights?<\/h2>\n\n\n\n<p>Enforcement of GDPR data subject rights is carried out by Data Protection Authorities (DPAs) in each EU member state. These authorities are responsible for monitoring compliance, handling complaints, and taking action against organizations that violate GDPR rules.<\/p>\n\n\n\n<p>In addition to overseeing data protection, DPAs also have the authority to impose sanctions and fines on organizations that fail to comply with GDPR requirements, including those related to data subject rights. They can also conduct audits, issue warnings, and order organizations to cease data processing activities if necessary.<\/p>\n\n\n\n<p>Individuals who believe their data subject rights have been violated can lodge a complaint with their national DPA, which will investigate the matter and take appropriate action.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What happens if you violate GDPR subject rights?<\/h2>\n\n\n\n<p>Failure to comply with GDPR data subject rights can result in significant consequences for organizations. The GDPR imposes two tiers of administrative fines, depending on the severity of the violation:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Tier 1 fines<\/strong>: Up to EUR 10 million, or 2 percent of the organization\u2019s global annual revenue (whichever is higher) for less severe breaches, such as failing to maintain accurate records or notify the DPA of a breach.<\/li>\n\n\n\n<li><strong>Tier 2 fines<\/strong>: Up to EUR 20 million, or 4% percent of the organization\u2019s global annual revenue (whichever is higher) for more serious breaches, such as violating data subject rights or failing to obtain valid consent.<\/li>\n<\/ul>\n\n\n\n<p>In addition to financial penalties, companies may suffer reputational damage and a loss of consumer trust and opportunities with partners or investors if they fail to uphold data protection rights.<\/p>\n\n\n<div class=\"cta-block cta-block--size-s cta-block--only-buttons cb-ctx--blue\">\n        <div class=\"cta-block__glass\">\n        <div class=\"cta-block__inner\">\n            <div class=\"cta-block__left-column\">\n                                                    <h2 class=\"cta-block__title no-default-margin like-h4\">\n                        Are you GDPR-compliant?                    <\/h2>\n                                                    <div class=\"cta-block__description like-text-md\">\n                        <p>Avoid costly penalties by downloading our free GDPR compliance checklist. It will help you navigate all aspects of the GDPR so you can meet compliance requirements.<\/p>\n                    <\/div>\n                                                                                                                                                        <\/div>\n                            <div class=\"cta-block__right-column\">\n                                                                <div class=\"cta-block__buttons\">\n                                                    <div class=\"cta-block__buttons__button-wp\">\n                                <a id=\"45cf7f9f-b40c-43d3-8639-576b36627ec5\" class=\"cb-button cb-button-size-l cb-button-contained  no-default-link-decoration cb-button-icon-right cta-block__buttons__button\" href=\"https:\/\/www.cookiebot.com\/en\/gdpr-compliance-requirements-checklist\/\" target=\"\">\n<span>Get your free GDPR checklist<\/span><\/a>\n                                                            <\/div>\n                                                                        <\/div>\n                                                        <\/div>\n                    <\/div>\n    <\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">How Cookiebot CMP can help you comply with GDPR data subject rights<\/h2>\n\n\n\n<p>GDPR data subject rights are fundamental to ensure that companies are transparent, accountable, and give users control over their personal data. Organizations that process personal data must understand and respect these rights.<\/p>\n\n\n\n<p>However, that can be easier said than done. Cookiebot CMP simplifies this by helping you manage user consent and provide transparency in your data processing. Cookiebot CMP helps companies:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Collect valid consent<\/strong>: Cookiebot CMP enables websites to obtain valid user consent for data processing per GDPR requirements.<\/li>\n\n\n\n<li><strong>Provide clear information<\/strong>: By generating customizable <a href=\"https:\/\/www.cookiebot.com\/en\/cookie-banner\/\">cookie banners<\/a> and privacy policies, UsercentricsCookiebot helps ensure that users are informed about how their data is being processed.<\/li>\n\n\n\n<li><strong>Facilitate data subject rights<\/strong>: With Cookiebot CMP, organizations can easily implement mechanisms for users to exercise their data subject rights, such as withdrawing consent or requesting access to their personal data.<\/li>\n<\/ul>\n\n\n\n<p>By using Cookiebot CMP, companies can streamline their GDPR compliance efforts and reduce the risk of noncompliance, ultimately protecting both their users and their business.<\/p>\n\n\n<div class=\"cta-block cta-block--size-s cta-block--only-buttons cb-ctx--blue\">\n        <div class=\"cta-block__glass\">\n        <div class=\"cta-block__inner\">\n            <div class=\"cta-block__left-column\">\n                                                                    <div class=\"cta-block__description like-text-md\">\n                        <p>Experience this for yourself, try Cookiebot CMP for 14 days free of charge! No credit card required.<\/p>\n                    <\/div>\n                                                                                                                                                        <\/div>\n                            <div class=\"cta-block__right-column\">\n                                                                <div class=\"cta-block__buttons\">\n                                                    <div class=\"cta-block__buttons__button-wp\">\n                                <a id=\"d1bbf66c-e806-4119-aedf-0ebf738e09dc\" class=\"cb-button cb-button-size-l cb-button-contained  no-default-link-decoration cb-button-icon-right cta-block__buttons__button\" href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\">\n<span>Start your free trial<\/span><\/a>\n                                                            <\/div>\n                                                                        <\/div>\n                                                        <\/div>\n                    <\/div>\n    <\/div>\n<\/div>\n\n\n\n\n","protected":false},"excerpt":{"rendered":"<p>Personal data is an integral part of nearly every online service and transaction. Websites, apps, and other connected platforms collect this data for companies to learn about user behaviors and provide better user experiences and services. However, with this comes the need to protect individuals\u2019 privacy and personal data. This is where the General Data [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":15309,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":true,"editor_notices":[],"footnotes":""},"categories":[1],"tags":[],"class_list":["post-15307","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"thumbnail_status":false,"thumbnail_url":"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2024\/10\/cb_some_gdpr_data_subj_093024.jpg","_links":{"self":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/15307","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/comments?post=15307"}],"version-history":[{"count":0,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/15307\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media\/15309"}],"wp:attachment":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media?parent=15307"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/categories?post=15307"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/tags?post=15307"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}