GDPR Data Subject Access Request – how companies handle the rights of data subjects
Share
Short answer: When a person requests access to their personal data, the organization must be able to identify the request, verify the requester's identity in a proportionate manner, collect the relevant data, assess any limitations, and respond within the timeframes stipulated by the GDPR. A good working procedure ensures that every request is handled consistently and can be followed up afterwards.
What is a register extract under the GDPR?
The right of access means that the data subject can obtain confirmation as to whether personal data is being processed and, if so, gain access to the data as well as information regarding, among other things, the purpose, categories of data, recipients, storage period, and rights. Requests therefore need to be handled more broadly than simply exporting a list from an IT system.
For which rights do companies need to have procedures?
- right of access and register extracts
- rectification of inaccurate data
- erasure when the conditions are met
- restriction of processing
- data portability where applicable
- objection, including against direct marketing
- information about automated decision-making when such rules are relevant
Different rights have different conditions. A standardized checklist reduces the risk of a request being handled as if all rights worked in the same way.
Step by step: from request to closed case
- Register the request. Note when it was received, what the person is requesting, and what contact details are used.
- Assess the identity. Request only the additional information actually needed to avoid disclosing data to the wrong person.
- Narrow down the search. Identify systems, data processors, emails, case management systems, and other sources where relevant data may be found.
- Review the results. A register extract must not result in the rights and freedoms of others being disregarded.
- Respond comprehensibly. The information must be provided in a clear and distinct manner, and the documentation should show how the assessment was made.
- Close and follow up. Save the basis for the decision, the date, and the actions taken in accordance with the organization's documentation procedures.
How much time does the company have?
The GDPR assumes that the data subject should receive information about actions taken without undue delay and normally within one month. In more complex situations, the deadline may be extended under certain conditions, but the data subject must then be informed of the extension and the reasons for it. An internal case register should therefore include the final response date and the person responsible.
Common mistakes
- lacking a common entry point for requests
- performing an overly extensive identity check and thereby collecting more personal data than necessary
- forgetting data held by data processors
- disclosing information about other people without sufficient review
- not documenting why a request is fully or partially denied
- missing the deadline because the case lacks a responsible owner
Practical documentation
For organizations that handle recurring requests, it is effective to combine a case log with response templates, identity verification, decision support, and control points for each right. This makes the process both faster and easier to present during an internal audit.
See the Template Shop’s GDPR package for register extracts and data subject rights.
Related GDPR documentation
A functioning rights workflow is often linked to the company's Record of Processing Activities (RoPA), legal bases, and procedures for incidents. The better mapped the processing activities are, the faster it is normally to find the correct data when a request is made.
FAQ
Must a register extract always be provided in the exact format the person requests?
The format must be accessible and understandable, but practical and legal conditions may affect how the material is provided. The important thing is that the data subject can actually access the information required by the GDPR.
Is the company allowed to charge a fee?
The principle is that information and actions according to the rights regulations are free of charge. The GDPR contains limited exceptions for manifestly unfounded or excessive requests.
Does everything need to be documented?
It is wise to document how the request was handled, which systems were checked, what assessments were made, and when the response was provided. Documentation supports accountability under the GDPR.
The article is general information and does not replace legal advice in individual cases.