Data Subject Request

Last updated:
14.10.2024
Managing data subject requests is effortless with our privacy software.
Data Subject Request
Key Takeaways
  • Companies must respond to GDPR data subject requests within one month.
  • The identity of the requester must be verified beyond doubt before providing information.
  • Information can be provided in writing, electronically, or orally.
  • Proliance 360 supports the management and documentation of data subject requests.
  • Failure to comply with the obligation to provide information can lead to warnings and fines.

The General Data Protection Regulation (GDPR) requires companies that process personal data to proactively inform individuals. This means that companies must actively notify data subjects as soon as they process their personal data and explain how this processing takes place. This also applies when personal data is provided voluntarily, such as during a job application process.

If individuals want to know exactly what data a company holds about them, they can find out by submitting a data subject request – a right granted to them by the GDPR. According to Article 15 of the GDPR, data subjects have a right of access. Through a data subject request, they can ask companies for a detailed overview of all their personal data being processed at any time. Furthermore, they can request a restriction on the processing of their data. If a company receiving such a request does not process any data belonging to the requester, it must confirm this with a negative response. A company has a maximum of one calendar month from the receipt of the request to do so.

Data subject requests under the GDPR must be taken seriously by companies, as failure to comply with the duty to provide information can lead to warnings and fines. Read on to learn how to manage incoming requests from data subjects.

What needs to be considered when handling data subject requests?

Companies must keep several factors in mind when handling data subject requests to meet GDPR requirements:

  • Response deadline: A data subject request must be answered within one month. This one-month period begins the moment the request is received by the company.
  • Identity verification: Before providing information, you must verify the identity of the requester beyond any doubt (in accordance with Art. 12 (1) sentence 3 GDPR).
  • Method of response: Information (the response to the data subject request) can be provided in writing, electronically, or, if explicitly requested, orally. If you respond electronically, ensure that the data is transmitted in an encrypted format.
  • Redaction: If the data in question allows for conclusions to be drawn about other individuals, these sections must be redacted or otherwise made unrecognizable.
  • Language: The principle of transparency requires that responses to access requests be provided in clear and plain language.
  • Documentation: Under the principle of accountability (Art. 5 (2) GDPR), the information provided must be documented internally.

Our service packages for external data protection officers and the Proliance 360 data protection software

Choose the service package that suits you best – from cost-effective basic coverage to individual premium consulting from our certified data protection experts. The foundation of our offering is always the innovative Proliance 360 data protection platform.

  • Basic from €175 / month
  • Medium from €275 / month
  • Premium from €475 / month

Managing data subject requests with software: Simple management of data subject rights with Proliance 360

Depending on the size of the company, managing data subject requests can quickly become overwhelming. However, a correct and systematic approach to these requests is essential. Our solution-oriented Proliance 360 data protection software helps you manage these requests clearly and easily, while ensuring compliance with data protection regulations and data subject rights. The data subject rights most frequently exercised in the course of a data subject request are:

  • The right to access personal data (pursuant to Article 15 GDPR) that is processed, for example, in the context of a customer relationship or employment.
  • The right to erasure / the right to be forgotten (pursuant to Article 17 GDPR), for instance, if the data subject no longer wishes to receive a newsletter.

Since it is not always immediately obvious whether a request is actually a data subject request, Proliance 360 provides a guide to help you identify it. You are guided step-by-step through the correct procedure for handling a data subject request—from identifying the individual to providing the specific information—ensuring you don't miss anything.

Our automated data protection solution makes privacy management in your company particularly easy. In addition to email templates and samples, Proliance 360 offers another decisive advantage: the entire process, as well as the fact that a request was answered in compliance with data protection regulations, is documented in our software. Both are relevant in the event of inquiries from supervisory authorities and must be demonstrable and available at all times. With digital management via Proliance 360, you or your data protection officer have all information readily available in one place. This is how our data protection software helps you manage data subject requests in a clear and understandable way.

FAQ: We answer your questions about data subject requests

Who can submit a data subject request?

All groups of people whose personal data is processed by a company are considered "data subjects" and are entitled to submit a data subject request. If you are unsure whether a company is processing your personal data, you can also submit a request to find out. If the company does not process any of your personal data, you will receive a so-called negative response.

Does my company have to inform people whose data we process?

Absolutely, as the GDPR requires companies to actively fulfill their duty to inform as soon as they process personal data. Data subjects whose personal data is being processed must be actively informed of this fact. This also applies when personal data is provided voluntarily (such as during an application process).

Can supervisory authorities demand proof that data subject requests have been answered?

Yes, responding to data subject requests is a legal obligation for companies under the GDPR. Companies must document the handling of such requests. Furthermore, if companies fail to respond to these requests, data subjects can file a complaint with the responsible supervisory authority.

How do you answer data subject requests?

Data subject requests are generally made in writing and should be answered in the same way—if necessary, after verifying the identity of the requester—so that the company has proof that the request was processed. In principle, information could also be provided orally if explicitly requested. A data subject request can be answered orally provided that the identity of the data subject has been verified by other means and the data subject has requested this (Art. 13 (1) sentence 3 GDPR). However, since there is no documentation of the response with an oral disclosure (documentation and accountability requirements pursuant to Art. 5 (2) GDPR), this form of disclosure should generally be avoided.

How quickly must data subject requests be answered?

Data subject requests must be answered within one calendar month (the maximum period). This deadline can only be extended in justified cases. The clock starts on the day the request is received. If a company lets this deadline pass, individuals who have not received a response to their request can contact their respective state data protection commissioner.

What happens if data subject requests are not answered?

If a company does not respond to such a request, it is in violation of applicable law. For the company, this means it may face a warning or a fine. Data subjects whose requests have not been answered can contact the data protection commissioner of their respective state.

Our services at a glance

Your personal data protection officer from Proliance will support you, assisted by our intelligent data protection software Proliance 360guide you on your path to data protection compliance. You will go through the following steps:

  1. Assess
    • Data protection inventory
    • Data protection audit
  2. Analyze
    • Risk analysis
    • Data protection action plan
    • Data protection compliance
  3. Document
    • Website privacy policy
    • Data protection documentation
    • Technical and organizational measures
    • Creation of record of processing activities
  4. Improve
    • Data protection impact assessment
    • Employee training
    • Management of data subject requests
    • Data processing agreement
    • Data breach
    • Expert support
    • External Data Protection Officer
    • Data Protection Consulting
    • Data Protection Management

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in