Data subject requests: how to respond

How to respond to requests for access, correction or erasure of personal data: a five-step process and the mistakes to avoid.

Every person has the right to ask what data you hold about them, to correct it, to ask for it to be erased or to object to the processing. An organization without a clear process usually discovers this when the first request arrives and nobody knows who should answer.

A five-step process

  • Recognize the request. It can arrive by email, by letter or through any employee, and it does not need to mention the law to be valid.
  • Record the date it was received and assign an owner.
  • Verify the requester's identity without asking for more data than you need.
  • Find the data across all systems. This is where the record of processing activities helps.
  • Reply in writing, clearly and within the deadline.

The deadline

The GDPR sets one month from receipt of the request, with a possible extension in complex cases. Check the exact deadline that applies to you under Law 124/2024 and write it into your internal procedure.

Mistakes to avoid

  • Ignoring the request because it did not come through the right channel.
  • Sending data without verifying who is asking for it.
  • Including other people's data in the reply.
  • Erasing data the law requires you to keep, for example for tax purposes.

Not every request has to be granted in full, but every request deserves a reasoned answer. Keep a register of requests and replies: it is your evidence that the process works.

Related serviceLaw 124 and GDPR ComplianceData mapping, record of processing activities, policies, DPIAs and readiness for an inspection by the Commissioner.Learn more

Let's talk about your next engagement.

Tell us about your engagement — we typically respond within one business day.

WhatsApp +355 69 522 4573