Data Subject Request

- Companies must respond to GDPR data subject requests within one month.
- The identity of the requester must be verified beyond doubt before providing information.
- Information can be provided in writing, electronically, or orally.
- Proliance 360 supports the management and documentation of data subject requests.
- Failure to comply with the obligation to provide information can lead to warnings and fines.
The General Data Protection Regulation (GDPR) requires companies that process personal data to proactively inform individuals. This means that companies must actively notify data subjects as soon as they process their personal data and explain how this processing takes place. This also applies when personal data is provided voluntarily, such as during a job application process.
If individuals want to know exactly what data a company holds about them, they can find out by submitting a data subject request – a right granted to them by the GDPR. According to Article 15 of the GDPR, data subjects have a right of access. Through a data subject request, they can ask companies for a detailed overview of all their personal data being processed at any time. Furthermore, they can request a restriction on the processing of their data. If a company receiving such a request does not process any data belonging to the requester, it must confirm this with a negative response. A company has a maximum of one calendar month from the receipt of the request to do so.
Data subject requests under the GDPR must be taken seriously by companies, as failure to comply with the duty to provide information can lead to warnings and fines. Read on to learn how to manage incoming requests from data subjects.
What needs to be considered when handling data subject requests?
Companies must keep several factors in mind when handling data subject requests to meet GDPR requirements:
- Response deadline: A data subject request must be answered within one month. This one-month period begins the moment the request is received by the company.
- Identity verification: Before providing information, you must verify the identity of the requester beyond any doubt (in accordance with Art. 12 (1) sentence 3 GDPR).
- Method of response: Information (the response to the data subject request) can be provided in writing, electronically, or, if explicitly requested, orally. If you respond electronically, ensure that the data is transmitted in an encrypted format.
- Redaction: If the data in question allows for conclusions to be drawn about other individuals, these sections must be redacted or otherwise made unrecognizable.
- Language: The principle of transparency requires that responses to access requests be provided in clear and plain language.
- Documentation: Under the principle of accountability (Art. 5 (2) GDPR), the information provided must be documented internally.
Our service packages for external data protection officers and the Proliance 360 data protection software
Choose the service package that suits you best – from cost-effective basic coverage to individual premium consulting from our certified data protection experts. The foundation of our offering is always the innovative Proliance 360 data protection platform.
- Basic from €175 / month
- Medium from €275 / month
- Premium from €475 / month
Managing data subject requests with software: Simple management of data subject rights with Proliance 360
Depending on the size of the company, managing data subject requests can quickly become overwhelming. However, a correct and systematic approach to these requests is essential. Our solution-oriented Proliance 360 data protection software helps you manage these requests clearly and easily, while ensuring compliance with data protection regulations and data subject rights. The data subject rights most frequently exercised in the course of a data subject request are:
- The right to access personal data (pursuant to Article 15 GDPR) that is processed, for example, in the context of a customer relationship or employment.
- The right to erasure / the right to be forgotten (pursuant to Article 17 GDPR), for instance, if the data subject no longer wishes to receive a newsletter.
Since it is not always immediately obvious whether a request is actually a data subject request, Proliance 360 provides a guide to help you identify it. You are guided step-by-step through the correct procedure for handling a data subject request—from identifying the individual to providing the specific information—ensuring you don't miss anything.
Our automated data protection solution makes privacy management in your company particularly easy. In addition to email templates and samples, Proliance 360 offers another decisive advantage: the entire process, as well as the fact that a request was answered in compliance with data protection regulations, is documented in our software. Both are relevant in the event of inquiries from supervisory authorities and must be demonstrable and available at all times. With digital management via Proliance 360, you or your data protection officer have all information readily available in one place. This is how our data protection software helps you manage data subject requests in a clear and understandable way.
FAQ: We answer your questions about data subject requests
Who can submit a data subject request?
All groups of people whose personal data is processed by a company are considered "data subjects" and are entitled to submit a data subject request. If you are unsure whether a company is processing your personal data, you can also submit a request to find out. If the company does not process any of your personal data, you will receive a so-called negative response.
Does my company have to inform people whose data we process?
Absolutely, as the GDPR requires companies to actively fulfill their duty to inform as soon as they process personal data. Data subjects whose personal data is being processed must be actively informed of this fact. This also applies when personal data is provided voluntarily (such as during an application process).
Can supervisory authorities demand proof that data subject requests have been answered?
Yes, responding to data subject requests is a legal obligation for companies under the GDPR. Companies must document the handling of such requests. Furthermore, if companies fail to respond to these requests, data subjects can file a complaint with the responsible supervisory authority.
How do you answer data subject requests?
Data subject requests are generally made in writing and should be answered in the same way—if necessary, after verifying the identity of the requester—so that the company has proof that the request was processed. In principle, information could also be provided orally if explicitly requested. A data subject request can be answered orally provided that the identity of the data subject has been verified by other means and the data subject has requested this (Art. 13 (1) sentence 3 GDPR). However, since there is no documentation of the response with an oral disclosure (documentation and accountability requirements pursuant to Art. 5 (2) GDPR), this form of disclosure should generally be avoided.
How quickly must data subject requests be answered?
Data subject requests must be answered within one calendar month (the maximum period). This deadline can only be extended in justified cases. The clock starts on the day the request is received. If a company lets this deadline pass, individuals who have not received a response to their request can contact their respective state data protection commissioner.
What happens if data subject requests are not answered?
If a company does not respond to such a request, it is in violation of applicable law. For the company, this means it may face a warning or a fine. Data subjects whose requests have not been answered can contact the data protection commissioner of their respective state.
Our services at a glance
Your personal data protection officer from Proliance will support you, assisted by our intelligent data protection software Proliance 360guide you on your path to data protection compliance. You will go through the following steps:
- Assess
- Data protection inventory
- Data protection audit
- Analyze
- Risk analysis
- Data protection action plan
- Data protection compliance
- Document
- Website privacy policy
- Data protection documentation
- Technical and organizational measures
- Creation of record of processing activities
- Improve
- Data protection impact assessment
- Employee training
- Management of data subject requests
- Data processing agreement
- Data breach
- Expert support
- External Data Protection Officer
- Data Protection Consulting
- Data Protection Management
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.













