Skip to content

Data Subject Rights: How to Handle Every GDPR Request

Data subject rights explained: one-month deadlines, access copies, erasure, portability, marketing objections, refusals and a practical request log.

A clinic reception diorama sorts request cards beneath EIGHT RIGHTS, ONE MONTH and labels for access, erasure and marketing objections.
By AI Priority Map Editorial

Quick Answer: GDPR data subject rights cover information, access, rectification, erasure, restriction, portability, objection and automated decisions. Most requests require action without undue delay and within one month. Route every request into one log, verify identity proportionately, apply the specific right and its limits, deliver securely, and record the decision and deadline.

Summary in a mind map

Data Subject Rights: How to Handle Every GDPR Request
│
├─ Recognise and log
│   ├─ Ordinary words can invoke a right
│   ├─ Record receipt and verify identity
│   └─ Control the one-month deadline
│
├─ Access and erasure
│   ├─ Confirmation, data and processing information
│   ├─ First copy without a default fee
│   └─ Erasure ground plus any exception
│
├─ Special routes
│   ├─ Portability needs consent or contract
│   ├─ Processing must be automated
│   └─ Marketing objection stops marketing
│
└─ Close with evidence
    ├─ Refusal gives reasons and remedies
    ├─ Deliver securely
    └─ Keep decisions, searches and completion

Recognise the right behind the person's words

People do not need to cite a GDPR article. “Send me everything you hold”, “correct my address”, “stop these adverts” and “delete my account” can each invoke a different right. Front-line staff need a simple route for forwarding any request concerning personal data.

The European Commission lists rights to information, access, rectification, erasure, restriction, portability, objection, and protections concerning automated decision-making and profiling.3 Some rights overlap. A person asking to leave a service may seek contract termination, erasure and an end to marketing at the same time.

Person's requestLikely rightFirst operational question
“What data do you have?”AccessCan identity be confirmed proportionately?
“This address is wrong”RectificationWhich systems and recipients hold it?
“Delete my records”ErasureWhich ground and exceptions apply?
“Send my data to me”Access or portabilityDoes consent/contract plus automation apply?
“Stop advertising to me”ObjectionWhich channels must stop now?

The request owner should classify each component without forcing the person to restate it in legal language. Where scope is unclear, ask a focused question, but do not use clarification to reset a deadline automatically.

Start the one-month clock correctly

Article 12(3) requires information on action taken without undue delay and in any event within one month of receipt.1 The process should timestamp receipt wherever it arrives: shared inbox, branch desk, social account or account manager. A request sent to the wrong department is still a request received by the organisation.

The period can be extended by two further months where necessary, considering complexity and number of requests.1 Extension is not routine extra time. The controller must tell the person within the first month and explain the reasons. A log should preserve both the decision and notification date.

Identity checks must be proportionate. The organisation can request additional information where it has reasonable doubts about identity, but should not collect excessive identity documents by default. Existing authenticated channels may provide strong evidence. The check should reflect the sensitivity and disclosure risk.

Create interim milestones before the legal deadline. A small firm might assign ownership on receipt, confirm scope promptly, complete searches with time for review, and reserve time for secure delivery. These are internal controls, not new legal time limits.

Handle access as three connected components

The EDPB describes access as three components: confirmation whether personal data is processed, access to that data, and access to information about the processing.2 Sending a data export without the explanatory information can therefore leave the response incomplete.

Article 15 provides a right to a copy of personal data undergoing processing. For further copies, the controller may charge a reasonable fee based on administrative costs.1 The rule does not make the first copy chargeable simply because retrieval is inconvenient.

Searches should follow data flows, not only system names. Customer support, finance, email, shared drives, archived systems and processors may each contain responsive data. The search plan records owners, queries, date ranges and results, including checked locations with no matches.

Review protects the rights and freedoms of others. The organisation may need to separate another person's data or confidential material, but cannot use that concern as a blanket reason to withhold the requester's own personal data. Redaction decisions should be specific and recorded.

Secure delivery follows the sensitivity of the material. Verify the destination, choose an appropriate channel and communicate the format. The explanatory response should identify categories, purposes, recipients, retention and other Article 15 information that applies.

Decide erasure by ground, data and exception

Erasure is not a universal instruction to delete every record immediately. Article 17(1) requires erasure without undue delay where a listed ground applies, including where personal data is no longer necessary for the purposes for which it was collected or otherwise processed.1

The controller should map the request to specific datasets and purposes. Account profile data, invoices, support correspondence and suppression entries can have different grounds and retention needs. A single “customer record” label hides the analysis.

Exceptions can permit continued processing, for example where necessary for a legal obligation or legal claims. The response should identify the applicable exception and affected data rather than state broadly that “the law requires retention”. Data outside the exception should still be erased where a ground applies.

Backups need a controlled approach. If immediate selective deletion would undermine a recovery copy, document the limitation, restrict ordinary access, apply normal expiry and ensure a restore process reapplies the erasure before data returns to service. The article deleting data from backups explains that control in detail.

Apply portability only when its gateway is open

Article 20 limits portability to processing based on consent or contract and carried out by automated means.1 The data must be provided in a structured, commonly used and machine-readable format. Both the legal-basis and automation conditions matter.

Processing based on legal obligation or legitimate interests does not enter portability through Article 20. Purely manual processing also misses the automation condition. That does not make the information invisible: access or another right may still apply.

Portability concerns personal data the person provided, interpreted in line with applicable guidance. It is not a right to receive every derived business analysis or an entire database. The response should distinguish the portable set, format and any separate access material.

Direct transmission to another controller may be requested where technically feasible. Feasibility does not remove security checks. The firm should verify destination and protect the transfer while avoiding unnecessary barriers.

Stop direct marketing on objection

Article 21(3) is categorical: where a person objects to processing for direct marketing, the personal data must no longer be processed for those purposes.1 There is no balancing test against the organisation's marketing interests.

The stop must propagate beyond one visible mailing list. CRM audiences, advertising uploads, text campaigns and instructed processors may all require action. The request log should identify each channel and completion confirmation.

A minimal suppression record may be needed so the organisation remembers not to market again. That record should not be reused for another purpose. Deleting every trace of the objection can cause the person to be re-added during the next import.

The UK-specific article on emailing businesses without consent covers a different jurisdictional marketing question. For this EU rights procedure, Article 21's response to the individual's objection remains the operational rule.

Refusals still require a timely response

If the controller does not take action, Article 12(4) requires notice within one month. The response must give reasons and tell the person about the possibility of complaining to a supervisory authority and seeking a judicial remedy.1

A refusal should identify the right, facts and legal reason. “We cannot help” is insufficient. If only part of a request is refused, fulfil the rest and explain the boundary. Where portability does not apply, for example, an access request may still produce information.

Manifestly unfounded or excessive requests require a careful, evidenced assessment. Repetition alone does not automatically establish either condition. The controller bears responsibility for showing why its response is justified.

In words, the tree branches like this: log every request and verify identity proportionately. Route access to search and copy, erasure to grounds and exceptions, portability to consent-or-contract plus automation, and direct-marketing objections to an immediate stop. Any refusal still produces reasons, complaint information and a response within one month.

Give one owner a complete request log

The log coordinates work without turning into an uncontrolled copy of every document. It should record request identity, received date, rights invoked, verification, scope, systems searched, owners, decisions, extension, communications, delivery and closure. Access should be restricted to staff who need it.

Log fieldPurposeEvidence produced
Received date and channelStarts deadline controlTimestamp
Identity methodPrevents wrongful disclosureProportionate verification note
Rights and scopeRoutes the workClassification record
Systems and processorsControls search coverageSearch confirmations
Decision and exceptionsExplains outcomeApproved reasoning
Delivery and closureShows completionSecure-send record

One accountable owner coordinates, but system owners perform searches and actions. Legal or privacy review may be needed for exceptions and third-party data. IT supports extraction and secure delivery. Marketing owns suppression actions. The controller-or-processor guide helps allocate duties where suppliers hold data.

The owner should report patterns. Repeated requests exposing the same retrieval problem indicate a records or system-design issue. The AI governance overview is relevant where automated tools contribute to searches or decisions, but human accountability remains clear.

Worked example: one email invokes four rights

A former customer writes to a small subscription service: “Send me my data, correct my old address, delete anything you no longer need and stop all advertising.” The service does not ask the person to submit four forms. It logs one received date and classifies access, rectification, erasure and direct-marketing objection as separate workstreams under one case.

The authenticated account and a focused confirmation provide proportionate identity evidence. Marketing suppression begins immediately across email and advertising audiences. The company retains a minimal suppression record so a later import does not restart marketing. That record is not used for another purpose.

The access search covers the account platform, support mailbox, payment references and its instructed support processor. Owners record search terms and results. The response includes confirmation, a copy of personal data and information about processing. Another customer's details in a support thread are separated without withholding the requester's messages.

Rectification is applied to the active account and any system where the address remains relevant. The team also checks recipients where notification is required. It does not rewrite a historical invoice if doing so would make the record inaccurate; instead, the current address and historical context are distinguished.

Erasure is assessed dataset by dataset. An obsolete preference record is deleted because it is no longer necessary. Certain invoice data is retained under a specific legal obligation, while the response names the affected data and reason. A backup entry is placed under the restore control so deleted active data will not silently return.

The case owner completes the response within one month and records secure delivery, actions, retained data and reasons. If the request had required an extension, notice and reasons would have been sent within that first month. The example shows why a rights process needs routing: one message can produce several different legal outcomes without losing a single deadline.

Coordinate processors and data recipients

A controller cannot close a request after checking only its own primary database. Processor contracts and records should show where suppliers hold relevant personal data and how quickly they must support rights handling. The internal deadline needs enough margin for retrieval, review and secure delivery.

Instructions to a processor should identify the person and required action without disclosing unnecessary information. The controller remains responsible for the response and should verify completion rather than assume a ticket status proves deletion or correction. Where several customers share a platform, searches must avoid exposing another controller's data.

Rectification and erasure can require communication to recipients under the GDPR's linked provisions, subject to their conditions. The case record should identify recipients, notices sent and any exception. For direct marketing, instructed agencies and uploaded advertising audiences need the same stop signal as internal systems.

Supplier failure should trigger escalation before the legal deadline expires. The controller records missing evidence, uses contractual contacts and decides what can still be completed. A delayed processor does not erase the person's right or automatically justify silence. Clear service responsibilities make this predictable before a real request arrives.

When this procedure does not decide the outcome

Complex identity disputes, mixed third-party data, litigation and conflicting legal duties can require specialist advice. The procedure ensures that the issue is surfaced and controlled; it cannot make every legal judgement automatic.

National procedural rules and sector laws may add obligations. This EU article should not be treated as a substitute for a Member State assessment where local law affects retention, representation or supervisory procedure.

What to do next

Publish one intake route, train staff to recognise ordinary-language requests and create a deadline-controlled log. Test the process with an access request, an erasure request, a portability request and a marketing objection. Use GDPR Accountability Documentation for the next documentation step.

Frequently asked questions

What are the eight GDPR data subject rights?

People have rights concerning information, access, rectification, erasure, restriction, portability, objection, and automated decision-making and profiling. The exact response depends on the request and processing. A firm should not promise every requested outcome automatically, but it must recognise the right, apply its conditions and answer within the applicable deadline.

How long do I have to answer a GDPR request?

The controller must provide information on action taken without undue delay and within one month of receiving the request. Where necessary because of complexity or number, that period may be extended by two further months. The person must be told of the extension and reasons within the initial month.

Can I charge for a copy of personal data?

The first copy under Article 15 is generally provided without charge. For further copies requested by the person, the controller may charge a reasonable fee based on administrative costs. A fee is not a default response to a difficult first request, and the organisation should distinguish a further copy from clarification of the original request.

When can personal data be kept despite an erasure request?

Erasure applies where an Article 17 ground is met, including when data is no longer necessary for its original purpose, but the right has exceptions. Data may sometimes be retained for legal obligations, freedom of expression, public-interest functions or legal claims. The response should identify the specific data, ground and exception.

When does data portability not apply?

Article 20 applies where processing is based on consent or contract and carried out by automated means. A request falls outside portability when those conditions are absent, such as processing based solely on a legal obligation or purely manual records. Other rights, including access, may still apply to the same information.

What happens when someone objects to direct marketing?

Personal data must no longer be processed for direct-marketing purposes after the objection. The stop should reach every relevant campaign, audience and channel, while retaining only the minimum suppression information needed to honour the objection. The business should not require the person to justify the objection or balance it against marketing interests.

Frequently Asked Questions

What are the eight GDPR data subject rights?
People have rights concerning information, access, rectification, erasure, restriction, portability, objection, and automated decision-making and profiling. The exact response depends on the request and processing. A firm should not promise every requested outcome automatically, but it must recognise the right, apply its conditions and answer within the applicable deadline.
How long do I have to answer a GDPR request?
The controller must provide information on action taken without undue delay and within one month of receiving the request. Where necessary because of complexity or number, that period may be extended by two further months. The person must be told of the extension and reasons within the initial month.
Can I charge for a copy of personal data?
The first copy under Article 15 is generally provided without charge. For further copies requested by the person, the controller may charge a reasonable fee based on administrative costs. A fee is not a default response to a difficult first request, and the organisation should distinguish a further copy from clarification of the original request.
When can personal data be kept despite an erasure request?
Erasure applies where an Article 17 ground is met, including when data is no longer necessary for its original purpose, but the right has exceptions. Data may sometimes be retained for legal obligations, freedom of expression, public-interest functions or legal claims. The response should identify the specific data, ground and exception.
When does data portability not apply?
Article 20 applies where processing is based on consent or contract and carried out by automated means. A request falls outside portability when those conditions are absent, such as processing based solely on a legal obligation or purely manual records. Other rights, including access, may still apply to the same information.
What happens when someone objects to direct marketing?
Personal data must no longer be processed for direct-marketing purposes after the objection. The stop should reach every relevant campaign, audience and channel, while retaining only the minimum suppression information needed to honour the objection. The business should not require the person to justify the objection or balance it against marketing interests.

Sources

  1. 1.Regulation (EU) 2016/679 (General Data Protection Regulation)EUR-Lex · 2016
  2. 2.Guidelines 01/2022 on data subject rights — Right of accessEuropean Data Protection Board · 2023
  3. 3.How is my personal data protected?European Commission · 2026

Want this run on your business?

AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.

Start your audit

You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.