Every person has the right to ask what data you hold about them, to correct it, to ask for it to be erased or to object to the processing. An organization without a clear process usually discovers this when the first request arrives and nobody knows who should answer.
A five-step process
- Recognize the request. It can arrive by email, by letter or through any employee, and it does not need to mention the law to be valid.
- Record the date it was received and assign an owner.
- Verify the requester's identity without asking for more data than you need.
- Find the data across all systems. This is where the record of processing activities helps.
- Reply in writing, clearly and within the deadline.
The deadline
The GDPR sets one month from receipt of the request, with a possible extension in complex cases. Check the exact deadline that applies to you under Law 124/2024 and write it into your internal procedure.
Mistakes to avoid
- Ignoring the request because it did not come through the right channel.
- Sending data without verifying who is asking for it.
- Including other people's data in the reply.
- Erasing data the law requires you to keep, for example for tax purposes.
Not every request has to be granted in full, but every request deserves a reasoned answer. Keep a register of requests and replies: it is your evidence that the process works.
