Data Subject Rights

Data subject rights are the claims the GDPR gives natural persons against the controller: access, rectification, erasure, restriction of processing, data portability and objection, among others. They can be exercised in any form, are as a rule to be met free of charge, and have to be answered within the period the Regulation sets.

DSGVOLast reviewed:

A data subject request almost never arrives the way the process assumes it will. It comes in as a sentence at the end of a support ticket, as a line in a complaint email, as a question from a departing employee, or over the phone from someone who has never heard of the GDPR.

It is still a request, the clock still starts, and the person who received it usually does not know that.

That is what makes these rights different from the rest of the GDPR. Most of the Regulation obliges you to document things internally, where a gap is discovered by an auditor if it is discovered at all. Data subject rights are where data protection faces outward (towards customers, applicants, employees and users), and a lapse is noticed immediately, by the one person with both the motive and the standing to complain about it.

The rights the Regulation grants

RightWhat it covers
AccessConfirmation of whether data are being processed, a copy of the data, and information on purposes, recipients, storage period and origin
RectificationCorrection of inaccurate data and completion of incomplete data
ErasureRemoval of the data once no ground for continued processing remains
Restriction of processingThe data stay stored but, narrow exceptions aside, may not be used further
Data portabilityRelease of the data the person provided, in a common, machine-readable format
ObjectionObjection to processing based on legitimate interests; for direct marketing, with no balancing test
Protection from purely automated decisionsProtection from decisions with legal or similarly significant effects taken without human involvement

Alongside these sit the right to withdraw consent at any time (a different thing from objecting, and frequently confused with it) and the right to lodge a complaint with a supervisory authority.

The rights themselves come from the Regulation and therefore look the same in every Member State. What is not uniform is how far national law narrows a particular right in a particular field; where you operate across several countries, treat that as something to check rather than something to assume.

Deadline, form and refusal

A request is bound to no form at all. It can be made by email, by phone, at a counter or inside a letter about something else; it does not have to invoke the Regulation; and it cannot be made conditional on the use of your form. You may offer a form. You may not require one.

The Regulation sets a short standard period for responding and allows an extension only on narrow conditions and with an interim notice; the applicable deadlines follow directly from the Regulation. A refusal has to be communicated inside that same period, reasoned, and accompanied by a reference to the routes of complaint and judicial remedy. Silence is the one response that is an infringement in every case, including the cases where you were entitled to say no.

Verifying identity without collecting new data

Where there are reasonable doubts about identity, you may and indeed should ask. Demanding a copy of a passport as a matter of course is the wrong move, because it collects additional data in order to protect existing data. The proportionate route is a check against attributes you already hold: the registered account, a callback on a number already on file, a reply from the address the relationship has always used.

The operational core is being able to find the data

An access request can be answered only if you know where a person's data sit, which is an architectural question rather than a legal one. The foundations are the record of processing activities and the system inventory, together with a current picture of which processors are in use.

The gaps open in the same places every time: exports into spreadsheets, individual employees' mailboxes, ticketing and recruitment systems, log data, test environments running on production data, and backups. None of these is exotic, and none of them appears in the diagram of the primary system.

Where processors hold the data, the contract has to make them help. Article 28 requires precisely that assistance. Without a named contact point and an agreed turnaround at the provider, though, your clock runs while you wait for someone to answer a generic support address.

The limits of the rights

No right is unlimited. Erasure meets its limit in statutory retention duties, access in the rights of others and in trade secrets, portability applies only to certain processing. A limit is not, however, a reason to say nothing: identify the restriction, give the reason, document it, and meet the uncontested part of the request. Partial answers are ordinary. Non-answers are not.

Where it goes wrong

  • Requests land in a department's mailbox and are never recognised as requests.
  • The clock runs with no one watching it, because no one owns it.
  • The response covers the primary system and quietly leaves the copies out.
  • An erasure is implemented as a block, without that being reasoned or recorded.
  • There is no dedicated route for objecting to direct marketing, so objections are handled as unsubscribes and lost.

How Rizzqo prepares the answer

The clock on a subject access request starts when the request arrives, not when it becomes clear where the data sits. Whether the deadline holds is therefore usually decided beforehand. In Rizzqo a primary asset, an item of information or a business process, carries the categories of personal data it holds and passes that property to the supporting assets beneath it, including across several steps.

The groundwork for a request is thereby already done: for a given data category, the systems, services and providers where it occurs are findable, each with a named owner. Answering remains a matter of judgement; what falls away is the search for the parties involved under time pressure.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyEU-hostedMulti-framework