GDPR · Individuals’ rights
Responses to GDPR data subject requests
An access, erasure or objection request is not resolved by a standard reply. The controller must identify the right exercised, verify identity proportionately, search every relevant system and clearly explain measures, limitations or reasons for refusal.
Classifying the request and verifying identity
The person need not cite the correct article for a request to be valid. A message may simultaneously involve access, objection and erasure, and each component must be identified and tracked.
Where reasonable doubts about identity exist, the controller may request additional information, but verification must be proportionate. Requesting a full identity-document copy for every request may collect excessive data and create new risk.
Search and analysis of the right exercised
The team must search operational applications, email, archives, tickets, backups within applicable limits and relevant suppliers. The response is based on the specific situation and statutory exceptions.
- Access: confirmation of processing, mandatory information and a copy of personal data.
- Rectification: correcting inaccurate data and completing relevant information.
- Erasure: checking the legal basis and statutory retention obligations.
- Restriction: marking data and limiting use in applicable cases.
- Portability: provided data, automated processing and a contractual or consent basis.
- Objection: reassessing legitimate interests or stopping direct marketing.
Deadline, extension and reasoned refusal
The controller responds without undue delay and, in any event, within one month. For complex or numerous requests, the period may be extended by two further months, but the person must be informed within the first month and the reasons for delay explained.
If a request is manifestly unfounded or excessive, the controller may charge a reasonable fee or refuse, but must be able to demonstrate that character. Any refusal must give reasons and explain the possibility of a complaint and judicial remedy.
Evidence of the response and system improvements
The internal register records dates, rights, systems checked, identity, decisions, approvals and evidence of dispatch. Register access must be restricted and retention justified.
Repeated requests may reveal product problems: profiles difficult to export, missing deletion functions or unrecorded sources. Effective compliance turns these cases into technical requirements and preventive controls.
How we work together
- 01Collecting information
We establish the processes, systems, suppliers, data categories, roles and existing documents relevant to managing the GDPR request.
- 02Risk and legality analysis
We check purposes, legal bases, proportionality, time limits, transfers, security and risks to data subjects.
- 03Documents and workflow
We draft the legal documents and align them with internal responsibilities, technical steps, evidence and response deadlines.
- 04Controlled implementation
We deliver the final version, practical instructions and clear priorities; compliance is reviewed periodically when processes or providers change.
Frequently asked questions
Must I also answer a request sent on Facebook?+
The channel does not automatically invalidate it. The company must recognise and route it and verify identity through a secure process.
Can I require the person to use only my form?+
The form may help but should not be used to refuse a valid request sent through another accessible channel.
Must documents containing other people’s data also be sent?+
Access rights must not adversely affect others’ rights and freedoms. Extracts, anonymisation or assessment of competing interests may be necessary.
Need a formal response to a GDPR request?
Send your documents for a legal assessment and a solution tailored to your commercial objective.
Aveți nevoie de asistență juridică urgentă sau de consultanță de specialitate?
Notă juridică și limitarea răspunderii
Informațiile și articolele publicate pe acest site web sunt puse la dispoziție de Avocatul „Basuc Cosmin Ștefan” exclusiv în scop informativ și educativ general. Materialele prezentate reprezintă analize teoretice și opinii de specialitate la data redactării lor, fără a constitui consultanță juridică, asistență legală sau o opinie aplicabilă unui caz concret. Lectura sau utilizarea acestui conținut nu creează o relație profesională avocat-client între cititor și Cabinet. Având în vedere dinamica legislativă și specificul fiecărei situații de fapt, interpretările conținute nu pot substitui analiza individuală a unei cauze. Pentru stabilirea cadrului juridic aplicabil problemei dumneavoastră și obținerea unei consultații profesionale dedicate, vă invităm să contactați Cabinetul prin mijloacele oficiale de comunicare afișate.
Linkuri utile și legislație
