The policy describes data subject rights including access, correction, deletion, restriction, objection, portability, and opt-out of profiling and targeted advertising, and provides three submission channels (portal, email, phone), while noting that these rights are subject to exceptions and are only applicable where Thomson Reuters acts as a data controller.
This analysis describes what Thomson Reuters's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the operational mechanisms for exercising data subject rights but conditions fulfillment on Thomson Reuters acting as a controller for the relevant data, which may limit rights for individuals whose data is processed through Thomson Reuters as a data processor on behalf of enterprise customers. The 2024 California metrics disclose an 87% rejection rate for data access requests and a 51% rejection rate for deletion requests, which may warrant documentation review for compliance adequacy.
Under this clause, users may submit access, deletion, correction, and opt-out requests through the Data Subject Rights Portal, by email, or by phone, but fulfillment is conditioned on Thomson Reuters acting as a controller for the relevant data and on the applicability of the requested rights under local law. The 2024 published metrics indicate that a significant proportion of requests received were rejected.
Cross-platform context
See how other platforms handle Data Subject Rights and Request Fulfillment and similar clauses.
Compare across platforms →"To submit a request, you can contact us through our Data Subject Rights Portal, email us at privacy.issues@thomsonreuters.com, or call us at 866-633-7656. Important: These rights are not absolutely guaranteed and there are several exceptions where we may not have an obligation to fulfill your request. We are only required to honor these rights to the extent we act as a controller of that data, and the requested rights have been granted and apply to you under applicable data protection laws.Excerpt from Thomson Reuters's Privacy
1) REGULATORY LANDSCAPE: GDPR Articles 15-22 establish enforceable data subject rights including access, erasure, rectification, restriction, portability, and objection.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes the operational mechanisms for exercising data subject rights but conditions fulfillment on Thomson Reuters acting as a controller for the relevant data, which may limit rights for individuals whose data is processed through Thomson Reuters as a data processor on behalf of enterprise customers. The 2024 California metrics disclose an 87% rejection rate for data access requests …
Under this clause, users may submit access, deletion, correction, and opt-out requests through the Data Subject Rights Portal, by email, or by phone, but fulfillment is conditioned on Thomson Reuters acting as a controller for the relevant data and on the applicability of the requested rights under local law. The 2024 published metrics indicate that a significant proportion of requests …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Thomson Reuters.