01

What a business can do

A business can build a repeatable process to handle data subject requests starting from the rights set out in the GDPR: access, rectification, erasure, restriction of processing, objection, data portability, and withdrawal of consent, as well as the right to lodge a complaint with a supervisory authority. The controller must provide this information within a reasonable period, and in any event at the latest within one month of obtaining the personal data, or, if the data are intended for communication with the data subject, at the latest at the time of the first communication. Mapping these elements makes it possible to respond promptly and with documentation to every request.

02

The context: who decides and who responds

The process is based on the distinction between controller and processor set out in Article 4 of the GDPR. When a business has establishments in more than one Member State, the main establishment is identified as the place of its central administration in the Union, unless decisions on the purposes and means of processing are taken elsewhere, in which case that establishment is considered the main one. Knowing precisely who decides the purposes and means of processing makes it possible to quickly identify who must respond to a data subject's request.

03

The step-by-step workflow

Steps

  1. Receive the data subject's request and record the date of arrival to calculate the one-month period set out in the GDPR.
  2. Identify which right is being exercised among access, rectification, erasure, restriction, objection, portability, or withdrawal of consent.
  3. Check whether the controller or the processor must handle the response, based on the main establishment.
  4. If the processing concerns a high-risk activity, assess whether a review of the impact assessment is needed.
  5. Respond to the data subject stating the outcome and reminding them of their right to lodge a complaint with a supervisory authority.

04

A hypothetical example

Hypothetical example: a customer writes to an e-commerce business asking for erasure of their personal data and withdrawal of consent to direct marketing. The privacy office records the date of receipt, checks that the marketing processing was based on consent, and prepares a response confirming the erasure, stating the retention period applied to any remaining data, and reminding the customer of their right to lodge a complaint with a supervisory authority, all within the one-month period set out in the GDPR.

05

Checks before sending the response

  • The response states the retention period for the data or the criteria used to determine it.
  • The response indicates the existence of any automated decision-making and the logic used.
  • The request is handled within the one-month period or according to the first-communication timelines.
  • If the risk of the processing changes, a review of the data protection impact assessment is considered.
  • The description of the processing remains consistent with the necessity, proportionality, and risk assessment already carried out.

06

How software can support the process

  • A software system can record the date of receipt of each request and automatically calculate the one-month deadline.
  • It can track which right was invoked and who within the business took charge of the response.
  • It can keep a complete history of requests and responses to demonstrate ongoing compliance.
  • It can flag when a change in processing requires a review of the data protection impact assessment.
  • It can assign distinct roles and permissions to those who decide, respond, and verify requests.

07

Key points to remember

  • The rights to track in every request are access, rectification, erasure, restriction, objection, portability, and withdrawal of consent.
  • The response deadline is at the latest one month from obtaining the data, unless tied to first-communication timelines.
  • An impact assessment includes a description of the processing, an assessment of necessity and proportionality, and measures for the risks.

08

Practical next step

A good starting point is to put it in writing: define who in the business handles data subject requests, within what timelines, and when the data protection impact assessment needs to be reviewed, particularly when the level of risk represented by the processing changes. Documenting this process makes it easier to respond consistently to every request.

FAQ

Frequently asked questions

Which rights must a data subject be able to exercise under the GDPR?

The GDPR provides for the right of access, rectification, erasure, restriction, objection, data portability, and withdrawal of consent, as well as the right to lodge a complaint with a supervisory authority.

How quickly must a business respond to a data subject's request?

The information must be provided within a reasonable period and in any event at the latest within one month of obtaining the data, or at the time of the first communication with the data subject.

When does the data protection impact assessment need to be reviewed?

The controller carries out a review when variations in the risk represented by the processing activities arise.

Sources and verification