In short: Access, rectification, erasure, portability, objection: which rights data subjects have under GDPR, the deadline to respond, and how to do it correctly.
GDPR puts the individual at the centre: anyone whose data you process has a set of rights, and you, as the controller, are obliged to respect them. Knowing how to respond correctly to a request is not just a legal obligation — it is also a mark of trust towards your customers and employees.
What the rights are
- Right of access — the individual can find out whether you process their data and can receive a copy of it.
- Right to rectification — correcting inaccurate data or completing incomplete data.
- Right to erasure (“the right to be forgotten”) — under certain conditions, the data must be deleted.
- Right to restriction of processing — temporarily “freezing” the processing.
- Right to data portability — receiving the data in a structured, usable format, and transmitting it to another controller.
- Right to object — objecting to processing based on legitimate interest or to direct marketing.
- Rights regarding automated decisions — not to be subject to decisions based solely on automated processing, including profiling, with significant effects.
The deadline to respond
The rule: without undue delay and within no more than one month of receiving the request. The deadline can be extended by a further two months for complex or numerous requests — but you must inform the individual of the extension and the reason within the first month.
How to respond correctly
- Verify the identity of the requester, so that you do not disclose data to someone else.
- Identify all the relevant data — this is why a well-kept record of processing activities saves you time.
- Respond clearly and free of charge (with exceptions for manifestly unfounded or excessive requests).
- Document the request and the response — they serve as evidence in the event of an inspection.
A clear internal procedure for data subject rights turns a potential source of stress into a routine process. This is one of the elements we build as part of a functional GDPR programme.
Receiving requests from data subjects and unsure how to respond?
We build your procedure and templates, so you respond correctly and on time, every time.