DAT-011 Data Subject Rights Fulfilment
Description
Technical and procedural mechanisms exist to fulfil data subject rights requests within legally mandated timeframes. Supported rights include access, rectification, erasure, restriction, portability and objection. Requests are logged, tracked and completed or refused with documented justification. The exercise of each right is facilitated through a route the individual can use without assistance, and where the organisation cannot identify the individual from the data it holds, a refusal on that ground records the demonstration behind it. Where a request is refused, the individual is told the reasons within the response period together with the route to complain to a supervisory authority and to seek a judicial remedy. Responses are free of charge, and a fee or a refusal on the ground that a request is manifestly unfounded or excessive is applied only where the record carries the evidence for that finding. Identifying information is asked for only where there is reasonable doubt about the requester's identity.
Rationale
Rights are enforceable legal entitlements and failing to meet them on time is both a violation and a material enterprise sales risk. The clauses added here are the ones that turn a working fulfilment process into a lawful one: a refusal with no reasons and no complaint route leaves the individual with nowhere to go, a fee charged as a matter of course inverts the free-of-charge rule, and demanding identity documents for every request deters more people than it protects. The form the communications take is DAT-009's.
Applicability (9 profiles)
Framework Mappings (16)
| DSP-11 | Personal Data Access, Reversal, Rectification and Deletion | full |
| DSP-11 | Personal Data Access, Reversal, Rectification and Deletion | full |
| GDPR-Art.12.1 | Transparent Information and Communication Modalities | partial |
| GDPR-Art.12.3 | Response Timeframes, Refusal and Identity Verification for Rights Requests | full |
| GDPR-Art.15 | Right of Access | partial |
| GDPR-Art.16 | Right to Rectification | full |
| GDPR-Art.17 | Right to Erasure (Right to be Forgotten) | full |
| GDPR-Art.18 | Right to Restriction of Processing | full |
| GDPR-Art.20 | Right to Data Portability | full |
| GDPR-Art.21.1 | Right to Object — Legitimate Interests and Public Tasks | full |
| GDPR-Art.21.2 | Right to Object — Direct Marketing | full |
| GDPR-Art.22 | Automated Decision-Making and Profiling | informative |
| PM-26 | Complaint Management | partial |
| MG-4.1-006 | Post-Deployment AI System Monitoring | MG-4.1-006 | informative |
| P5.1 | Access to Personal Information | full |
| P5.2 | Correction of Personal Information | full |
Evidence (3)
Data subject rights request log showing all requests received, the right invoked, response timeline, outcome, and any documented refusals.
Example: DSR tracker (Jira / OneTrust / spreadsheet), listing all requests from the last 12 months with: request date, right invoked (access / erasure / portability / rectification / restriction / objection), response sent date, outcome, and any extensions or refusals with reasons
Test: Request the DSR log for the last 12 months. Verify: (1) all requests were responded to within 30 days (or 90 days with documented extension), (2) no request was refused without a documented legal justification, (3) erasure requests were confirmed as completed (including backups where applicable), (4) portability requests were fulfilled in a machine-readable format (e.g. JSON, CSV).
Data subject rights procedure documenting how each right is operationalised, verification steps, internal handoff processes and escalation paths.
Example: Data Subject Rights Fulfilment Procedure (Confluence), approved by DPO, with step-by-step workflows for: access, erasure, portability, rectification, restriction and objection, including identity verification steps, response templates, and SLA timers
Test: Request the DSR procedure. Verify: (1) a documented process exists for each of the six GDPR rights, (2) identity verification steps are defined, (3) internal handoff points (e.g. from support to engineering for erasure) are clearly specified, (4) procedure references the 30-day statutory deadline, (5) approved by DPO within 24 months.
Refusal and fee records for rights requests, showing the reasons sent to the individual and the evidence behind any finding that a request was manifestly unfounded or excessive.
Example: DSR refusal register 2026, with issued refusal letters
Test: Request the refusal and fee records. Verify: (1) every refused request carries a reason sent to the individual within the response period, (2) each refusal names the supervisory authority complaint route and the judicial remedy, (3) each fee charged or refusal made on the manifestly unfounded or excessive ground carries the evidence the organisation relied on, (4) no request in the period was charged for outside that ground, (5) identifying information was requested only where the record states a reasonable doubt about identity, (6) a refusal on the ground that the individual could not be identified records the demonstration behind it.
Questions (3)
Is there a documented process for handling data subject rights requests?
Each right should have a documented workflow, identity verification step, and defined internal handoff. A request tracking log must demonstrate requests are actioned within 30 days (or 90 days with documented extension).
Which data subject rights can your organisation fulfil without requiring manual engineering intervention?
Self-service or tooling-assisted fulfilment for access, portability and erasure is the expected standard for a mature product. Rights that require manual engineering effort introduce delay and error risk.
Which of the following does your rights request process do?
Options run from the most commonly in place to the least. A refusal with no reasons and no complaint route leaves the individual with nowhere to go. Demanding identity documents for every request deters more people than it protects, and the burden of showing a request is excessive sits with the organisation rather than the requester.