Key individual privacy rights under GDPR and similar laws include: the right to access (request a copy of all personal data an organization holds about you), the right to erasure or "right to be forgotten" (request that your data be deleted), the right to data portability (receive your data in a structured format), and the right to object to processing for marketing or profiling purposes.
These rights vary by jurisdiction. The EU's GDPR is among the most comprehensive. The UK has UK GDPR. California has the CCPA. Many other countries have national privacy laws. Knowing which laws apply to your situation determines what rights you can exercise and against which organizations.
Exercising your rights: To opt out of marketing, use the unsubscribe mechanism in emails or contact the organization directly. To request data deletion, submit a written request via the organization's privacy contact (usually a Data Protection Officer or privacy team). For data brokers, check their websites for opt-out forms — many are required by law to provide them.
Organizations are required to respond to access requests within defined timeframes — 30 days under GDPR. If they do not, you can complain to your national data protection authority, which has enforcement powers. The threat of a regulator complaint is often sufficient to prompt compliance.