01
The short answer
A company must be able to guarantee data subjects access, rectification, erasure, restriction, objection, and portability of their data, as well as the right to withdraw consent and to lodge a complaint with a supervisory authority. Among the information data subjects must be able to know are the retention period of the data, the origin of the data, and the existence of any automated decision-making.
02
Who does what: controller, processor, and main establishment
The controller decides the purposes and means of processing, while the processor acts on its behalf; for groups with multiple establishments in the Union, the main establishment is identified as the place of central administration, unless decisions on purposes are taken elsewhere. This distinction determines who answers requests and which supervisory authority is involved in cross-border processing.
03
The operational steps of the process
Steps
- Receive the request and log it with the arrival date, to keep an internal record of its handling.
- Identify the internal role responsible (controller or designated processor) based on the specific processing.
- Verify which rights are involved: access, rectification, erasure, restriction, objection, or portability.
- Prepare a response indicating the retention period, the origin of the data, and the existence of any automated decisions, together with the rights that can be exercised.
- Re-examine the processing when the risk level associated with the activities involved changes.
04
A hypothetical case
Hypothesis: a company with establishments in two Member States receives an access request. The privacy team identifies the main establishment, checks whether the processing relies on legitimate interest, and prepares a response that includes the retention period, the origin of the data, and the existence of any automated decisions.
05
Checks on the information provided to data subjects
- The information provided indicates the retention period or the criteria used to determine it.
- The right to withdraw consent is mentioned, if the processing relies on it.
- The right to lodge a complaint with a supervisory authority is indicated.
- If the processing involves high risks, the impact assessment is updated when the risk changes.
- Where relevant, the views of data subjects on the intended processing have been collected.
06
What a company can configure in a management software
An organization can structure, with its software partner, a request register that tracks assigned role, date of receipt, type of right exercised, and response date, so as to maintain a clear view of the status of each request. It is useful to plan a periodic review flow linked to changes in processing risk, with distinct permissions for those who receive, evaluate, and close the request.
07
Frequently asked questions about the process
- What information must the company provide to data subjects about the processing? Retention period, origin of the data, any automated decisions, and available rights.
- When should the impact assessment be updated? When the risk level associated with the processing changes.
- Who identifies the establishment responsible for responding? The place of central administration, unless decisions on processing are taken elsewhere.
08
Next step
Defining roles, timelines, and traceability for each type of request is the first step toward a solid process: map existing processing activities and assign clear responsibilities before the next request arrives.
FAQ
Frequently asked questions
What information must the company provide to data subjects about the processing of their data?
Among other information, the retention period of the data, the origin of the data, the existence of any automated decision-making, and the right to lodge a complaint with a supervisory authority.
Which rights must the company guarantee to data subjects?
Access, rectification, erasure, restriction, objection, data portability, and withdrawal of consent, as well as the right to lodge a complaint with a supervisory authority.
When is it necessary to review a data protection impact assessment?
When there are changes in the risk level represented by the processing activities involved.
✓