ADP · ADP Privacy Statement · View original document ↗

Individual Rights — Access, Correction, Erasure, and Objection

Low severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time ADP changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for ADP Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy establishes procedures for individuals to request access to, correction of, or deletion of their personal data, and to object to processing, either through their online account or by contacting privacy@adp.com. For EEA individuals, additional rights including data portability and rights regarding automated decision-making are also stated.

This analysis describes what ADP's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the operational mechanism through which individuals may exercise data rights under GDPR, UK GDPR, CCPA, and the ADP BCR framework. EEA individuals have an additional right of data portability and notification regarding automated decision-making, with a dedicated EMEA Data Protection Officer contact provided.

Recent Activity

This document changed recently

Medium May 1, 2026

ADP deleted the cookie preference management tool that previously allowed users to understand and control which cookies were placed on their devices, including functional, analytics, and advertising cookies. The removal eliminates the transparency mechanism through which users could consent to or opt out of different cookie categories. The practical effect depends on whether ADP has replaced this functionality elsewhere or whether cookies continue to be placed without equivalent granular user control.

View change record →

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this clause, individuals can request access to, correction of, or deletion of their personal data held by ADP by logging into their account or emailing privacy@adp.com. EEA-based individuals may also exercise data portability rights and contact the EMEA Data Protection Officer at DataProtectionOfficer.ADPEMEA@adp.com.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Email privacy@adp.com to request access to, correction of, or deletion of your personal data. Include your name, address, email address, and a detailed description of the data and the action you are requesting.
  • Export Your Data
    EEA-based individuals may email DataProtectionOfficer.ADPEMEA@adp.com to request data portability. Include your name, contact details, and a description of the data you wish to receive in a portable format.

Cross-platform context

See how other platforms handle Individual Rights — Access, Correction, Erasure, and Objection and similar clauses.

Compare across platforms →

Monitoring

ADP has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
ADP respects your right to access, correct, and delete your Personal Data, or object to the processing of your Personal Data. If you have an online account, you may log into your account to access update, or delete the information you have provided to us. Additionally, you may contact privacy@adp.com . to request access to your data, and to exercise any of the individual rights afforded to you by ADP's Privacy Code for Business Data, or by applicable data protection laws and regulations.

Excerpt from ADP's Privacy Statement

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

REGULATORY LANDSCAPE: This provision engages GDPR Articles 15 through 22 (data subject rights including access, rectification, erasure, restriction, portability, and objection), UK GDPR equivalent provisions, and CCPA/CPRA rights to know, delete, and correct. The relevant enforcement authorities are EU national DPAs, the UK ICO, and the California Privacy Protection Agency. The policy states ADP will respond 'as soon as possible and in accordance with applicable data protection laws,' which aligns with GDPR's one-month response standard, though the policy does not state a specific response timeline. GOVERNANCE EXPOSURE: Low. The provision articulates recognized individual rights consistent with GDPR and CCPA requirements, and provides both online and email mechanisms for submitting requests. The absence of a specific response timeline beyond 'as soon as possible' may be noted in audits but is not a material deviation from common industry practice. JURISDICTION FLAGS: California residents are directed to a separate California Consumer Privacy Statement for additional rights details. EEA residents have additional rights (portability, automated decision-making notification) not extended globally. Organizations subject to GDPR should confirm that ADP's data subject rights response procedures satisfy their own processor obligations. CONTRACT AND VENDOR IMPLICATIONS: Organizations using ADP to process employee or customer data should confirm that ADP's data subject rights procedures are compatible with their own GDPR and CCPA obligations, including timelines for passing on data subject requests to ADP as a processor. COMPLIANCE CONSIDERATIONS: Compliance teams should document the process for routing data subject requests received from employees or customers to ADP, and confirm ADP's commitment to respond within GDPR's one-month window. Audit procedures should verify that ADP's BCR-based individual rights framework covers all relevant data categories processed on behalf of the organization.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has authority over unfair or deceptive practices related to data subject rights representations under Section 5
    File a complaint →

Provision details

Document information
Document
ADP Privacy Statement
Entity
ADP
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015032
Document ID
CA-D-00302
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
68e06dd8e46c0e54a6f4f1c94bfa5a30c8e2c714e4db7e4e054bc0413797dfc6
Analysis generated
July 9, 2026 06:59 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: ADP
Document: ADP Privacy Statement
Record ID: CA-P-015032
Captured: 2026-07-09 06:59:06 UTC
SHA-256: 68e06dd8e46c0e54…
URL: https://conductatlas.com/platform/adp/adp-privacy-statement/provision/CA-P-015032/individual-rights-access-correction-erasure-and-objection/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does ADP's Individual Rights — Access, Correction, Erasure, and Objection clause do?

This provision establishes the operational mechanism through which individuals may exercise data rights under GDPR, UK GDPR, CCPA, and the ADP BCR framework. EEA individuals have an additional right of data portability and notification regarding automated decision-making, with a dedicated EMEA Data Protection Officer contact provided.

How does this clause affect you?

Under this clause, individuals can request access to, correction of, or deletion of their personal data held by ADP by logging into their account or emailing privacy@adp.com. EEA-based individuals may also exercise data portability rights and contact the EMEA Data Protection Officer at DataProtectionOfficer.ADPEMEA@adp.com.

Is ConductAtlas affiliated with ADP?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by ADP.