Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy describes data subject rights including access, correction, deletion, restriction, objection, portability, and opt-out of profiling and targeted advertising, and provides three submission channels (portal, email, phone), while noting that these rights are subject to exceptions and are only applicable where Thomson Reuters acts as a data controller.
This analysis describes what Thomson Reuters's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the operational mechanisms for exercising data subject rights but conditions fulfillment on Thomson Reuters acting as a controller for the relevant data, which may limit rights for individuals whose data is processed through Thomson Reuters as a data processor on behalf of enterprise customers. The 2024 California metrics disclose an 87% rejection rate for data access requests and a 51% rejection rate for deletion requests, which may warrant documentation review for compliance adequacy.
Under this clause, users may submit access, deletion, correction, and opt-out requests through the Data Subject Rights Portal, by email, or by phone, but fulfillment is conditioned on Thomson Reuters acting as a controller for the relevant data and on the applicability of the requested rights under local law. The 2024 published metrics indicate that a significant proportion of requests received were rejected.
Cross-platform context
See how other platforms handle Data Subject Rights and Request Fulfillment and similar clauses.
Compare across platforms →Monitoring
Thomson Reuters has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"To submit a request, you can contact us through our Data Subject Rights Portal, email us at privacy.issues@thomsonreuters.com, or call us at 866-633-7656. Important: These rights are not absolutely guaranteed and there are several exceptions where we may not have an obligation to fulfill your request. We are only required to honor these rights to the extent we act as a controller of that data, and the requested rights have been granted and apply to you under applicable data protection laws.Excerpt from Thomson Reuters's Privacy
1) REGULATORY LANDSCAPE: GDPR Articles 15-22 establish enforceable data subject rights including access, erasure, rectification, restriction, portability, and objection. CCPA/CPRA establishes analogous rights for California residents with specific response timelines. The CCPA regulations published under Section 999.317(g) require annual publication of consumer request metrics, which Thomson Reuters has disclosed for 2024. The California Privacy Protection Agency has enforcement authority over CCPA/CPRA compliance including request fulfillment. 2) GOVERNANCE EXPOSURE: Medium to High. The 2024 published metrics show 299 of 343 data access requests rejected (approximately 87%) and 303 of 590 deletion requests rejected (approximately 51%). While rejection may be legally justified under applicable exceptions, the rates warrant documentation review to confirm that rejection bases are recorded, legally supported, and communicated to requestors with explanation and appeal information as required by CCPA/CPRA and GDPR. 3) JURISDICTION FLAGS: California CPRA requires response to access requests within 45 days (extendable to 90 days with notice) and mandates that rejection reasons be communicated to requestors with appeal information. GDPR requires response within 30 days (extendable to 60 days with notice) and requires substantive justification for refusals. EU supervisory authorities and the California Privacy Protection Agency may audit request fulfillment records. 4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers whose employee or end user data is processed by Thomson Reuters should confirm in their data processing agreements whether Thomson Reuters will fulfill data subject requests directly or whether the enterprise customer retains responsibility. The controller/processor distinction determines who bears the obligation to respond. 5) COMPLIANCE CONSIDERATIONS: Legal teams should review Thomson Reuters' documented rejection bases for the categories of requests reflected in the 2024 metrics and confirm that internal procedures for communicating rejections and providing appeal information are consistent with CCPA/CPRA and GDPR requirements. The appeal pathway described in the statement (email or written appeal, with right to complain to local regulator) should be verified as operationally functional.
This provision establishes the operational mechanisms for exercising data subject rights but conditions fulfillment on Thomson Reuters acting as a controller for the relevant data, which may limit rights for individuals whose data is processed through Thomson Reuters as a data processor on behalf of enterprise customers. The 2024 California metrics disclose an 87% rejection rate for data access requests …
Under this clause, users may submit access, deletion, correction, and opt-out requests through the Data Subject Rights Portal, by email, or by phone, but fulfillment is conditioned on Thomson Reuters acting as a controller for the relevant data and on the applicability of the requested rights under local law. The 2024 published metrics indicate that a significant proportion of requests …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Thomson Reuters.