← IP, GDPR & Cybersecurity

GDPR · Individuals’ rights

Responses to GDPR data subject requests

An access, erasure or objection request is not resolved by a standard reply. The controller must identify the right exercised, verify identity proportionately, search every relevant system and clearly explain measures, limitations or reasons for refusal.

one-month deadline comprehensive search reasoned exceptions
Basic deadlineOne month from receipt of the request
ExtensionTwo further months if necessary and notified on time
PrincipleFree, accessible and in clear language
01

Classifying the request and verifying identity

The person need not cite the correct article for a request to be valid. A message may simultaneously involve access, objection and erasure, and each component must be identified and tracked.

Where reasonable doubts about identity exist, the controller may request additional information, but verification must be proportionate. Requesting a full identity-document copy for every request may collect excessive data and create new risk.

02

Search and analysis of the right exercised

The team must search operational applications, email, archives, tickets, backups within applicable limits and relevant suppliers. The response is based on the specific situation and statutory exceptions.

  • Access: confirmation of processing, mandatory information and a copy of personal data.
  • Rectification: correcting inaccurate data and completing relevant information.
  • Erasure: checking the legal basis and statutory retention obligations.
  • Restriction: marking data and limiting use in applicable cases.
  • Portability: provided data, automated processing and a contractual or consent basis.
  • Objection: reassessing legitimate interests or stopping direct marketing.
03

Deadline, extension and reasoned refusal

The controller responds without undue delay and, in any event, within one month. For complex or numerous requests, the period may be extended by two further months, but the person must be informed within the first month and the reasons for delay explained.

If a request is manifestly unfounded or excessive, the controller may charge a reasonable fee or refuse, but must be able to demonstrate that character. Any refusal must give reasons and explain the possibility of a complaint and judicial remedy.

04

Evidence of the response and system improvements

The internal register records dates, rights, systems checked, identity, decisions, approvals and evidence of dispatch. Register access must be restricted and retention justified.

Repeated requests may reveal product problems: profiles difficult to export, missing deletion functions or unrecorded sources. Effective compliance turns these cases into technical requirements and preventive controls.

05

How we work together

  1. 01
    Collecting information

    We establish the processes, systems, suppliers, data categories, roles and existing documents relevant to managing the GDPR request.

  2. 02
    Risk and legality analysis

    We check purposes, legal bases, proportionality, time limits, transfers, security and risks to data subjects.

  3. 03
    Documents and workflow

    We draft the legal documents and align them with internal responsibilities, technical steps, evidence and response deadlines.

  4. 04
    Controlled implementation

    We deliver the final version, practical instructions and clear priorities; compliance is reviewed periodically when processes or providers change.

QUESTIONS

Frequently asked questions

Must I also answer a request sent on Facebook?

The channel does not automatically invalidate it. The company must recognise and route it and verify identity through a secure process.

Can I require the person to use only my form?

The form may help but should not be used to refuse a valid request sent through another accessible channel.

Must documents containing other people’s data also be sent?

Access rights must not adversely affect others’ rights and freedoms. Extracts, anonymisation or assessment of competing interests may be necessary.

Need a formal response to a GDPR request?

Send your documents for a legal assessment and a solution tailored to your commercial objective.