Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What happens when an organisation cannot or will…
Governance, Ownership & Risk

What happens when an organisation cannot or will not correct disputed personal data?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Governance, Ownership & Risk

If an organisation refuses to correct data, it should explain the reason without undue delay and at the latest within one month, then tell the individual how to complain to the regulator. In disputed cases, it may still need to add an explanatory note and, where applicable, restrict further processing until the accuracy question is resolved.

What the organisation must do after refusing a correction request

When an organisation cannot or will not amend disputed personal data, the practical issue is not only the refusal itself but the follow-on obligations that preserve fairness and accountability. The individual needs a clear explanation, a path to challenge the decision, and protection against the disputed record being treated as settled fact while the accuracy question remains open.

In privacy and data-handling terms, a refusal should be handled as an active governance event, not a dead end. The organisation should document why it believes correction is not justified, notify the person promptly, and make sure the disputed status is visible wherever that record is used operationally.

Where the dispute is genuine and the accuracy cannot be confirmed immediately, the point is to keep the record usable without pretending it is undisputed. That usually means attaching a note or similar marker so downstream users understand the data is contested, and, where appropriate, pausing further processing that would rely on uncertain accuracy.

How disputed personal data should be handled in practice

Accuracy disputes are usually a workflow problem as much as a legal one. The organisation needs a method for separating routine update requests from genuine disputes, because a simple typo correction, a contested allegation, and a data-quality disagreement do not require the same level of review or the same evidential threshold.

If the organisation believes the data is already correct, it should still preserve the dispute record. That protects the individual from silent rejection and gives internal teams a traceable reason for continuing to use the data in a limited way. For identity-related records, this matters because incorrect personal data can flow into access decisions, case handling, or downstream profiling.

Where the organisation lacks enough evidence to settle the issue quickly, the safer position is to limit reliance on the contested field until the matter is resolved. The Identity Data Privacy and Consent Guide is useful here because it ties data subject rights, privacy-by-design handling, and retention discipline together in a way practitioners can apply to disputed records.

Why this matters for accuracy, trust, and downstream use

The main risk is not just retaining a wrong record, but allowing a disputed record to keep driving decisions as if it were settled. That can affect service outcomes, internal approvals, investigations, customer communications, or any process that depends on accurate personal data. A correction refusal without an explanatory note can also make the organisation look arbitrary, even when the underlying decision is defensible.

For organisations processing personal data under GDPR, the handling of a dispute is closely tied to accuracy, transparency, and the right to complain. The EU General Data Protection Regulation (GDPR) is the most direct reference point for the underlying obligations, especially where the organisation needs to justify its refusal and manage the record while the accuracy question remains unresolved.

If the disputed information is used beyond the immediate case, the impact can spread quickly. A contested address, identity attribute, or status flag can propagate into multiple systems, so the real control is not just editing the source record, but preventing unsupported downstream reliance on it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while GDPR defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPRArt. 5 — Principles relating to processing of personal dataAccuracy and fairness govern disputed personal data handling.
Art. 16 — Right to rectificationDirectly addresses refusal or inability to correct personal data.
Art. 18 — Right to restriction of processingSupports pausing use of disputed data while accuracy is resolved.
Recommendation — Apply Art. 5 to keep contested personal data accurate and transparently handled. Use Art. 16 to assess rectification requests and document any refusal. Apply Art. 18 to restrict processing when data accuracy is contested.
NIST SP 800-53 Rev 5IP-4 — Complaint ManagementProvides a governance analogue for handling and tracking disputed requests.
AU-3 — Content of Audit RecordsSupports recording the reason for refusal and the dispute status.
Recommendation — Establish complaint handling so disputed-data cases are tracked to closure. Log the refusal basis and dispute outcome so the decision is reviewable.

Practitioner Guidance

What to verify: Confirm whether the disputed field is actually being used in live decisions, shared feeds, or automated workflows. If it is, treat the dispute as operationally material, because the harm often comes from propagation, not from the original record itself.

Decision rule: If the organisation cannot substantiate the current value, add a clear dispute note and restrict reliance on the contested data until it is resolved. If the organisation can substantiate it, explain the basis of that conclusion in plain language and retain the challenge record for auditability.

What good looks like: The individual receives a timely explanation, internal users can see that the data is contested, and any process that depends on the disputed field is either paused or consciously accepted with documented risk.

Practitioner takeaway: A refusal to correct personal data is only defensible when the organisation still preserves transparency, traceability, and controlled use of the disputed record.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org