GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

DAT-011 Data Subject Rights Fulfilment

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Technical and procedural mechanisms exist to fulfil data subject rights requests within legally mandated timeframes. Supported rights include access, rectification, erasure, restriction, portability and objection. Requests are logged, tracked and completed or refused with documented justification. The exercise of each right is facilitated through a route the individual can use without assistance, and where the organisation cannot identify the individual from the data it holds, a refusal on that ground records the demonstration behind it. Where a request is refused, the individual is told the reasons within the response period together with the route to complain to a supervisory authority and to seek a judicial remedy. Responses are free of charge, and a fee or a refusal on the ground that a request is manifestly unfounded or excessive is applied only where the record carries the evidence for that finding. Identifying information is asked for only where there is reasonable doubt about the requester's identity.

Rationale

Rights are enforceable legal entitlements and failing to meet them on time is both a violation and a material enterprise sales risk. The clauses added here are the ones that turn a working fulfilment process into a lawful one: a refusal with no reasons and no complaint route leaves the individual with nowhere to go, a fee charged as a matter of course inverts the free-of-charge rule, and demanding identity documents for every request deters more people than it protects. The form the communications take is DAT-009's.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (16)

DSP-11Personal Data Access, Reversal, Rectification and Deletionfull
DSP-11Personal Data Access, Reversal, Rectification and Deletionfull
GDPR-Art.12.1Transparent Information and Communication Modalitiespartial
GDPR-Art.12.3Response Timeframes, Refusal and Identity Verification for Rights Requestsfull
GDPR-Art.15Right of Accesspartial
GDPR-Art.16Right to Rectificationfull
GDPR-Art.17Right to Erasure (Right to be Forgotten)full
GDPR-Art.18Right to Restriction of Processingfull
GDPR-Art.20Right to Data Portabilityfull
GDPR-Art.21.1Right to Object — Legitimate Interests and Public Tasksfull
GDPR-Art.21.2Right to Object — Direct Marketingfull
GDPR-Art.22Automated Decision-Making and Profilinginformative
PM-26Complaint Managementpartial
MG-4.1-006Post-Deployment AI System Monitoring | MG-4.1-006informative
P5.1Access to Personal Informationfull
P5.2Correction of Personal Informationfull

Evidence (3)

recorddocumentmanual

Data subject rights request log showing all requests received, the right invoked, response timeline, outcome, and any documented refusals.

Example: DSR tracker (Jira / OneTrust / spreadsheet), listing all requests from the last 12 months with: request date, right invoked (access / erasure / portability / rectification / restriction / objection), response sent date, outcome, and any extensions or refusals with reasons

Test: Request the DSR log for the last 12 months. Verify: (1) all requests were responded to within 30 days (or 90 days with documented extension), (2) no request was refused without a documented legal justification, (3) erasure requests were confirmed as completed (including backups where applicable), (4) portability requests were fulfilled in a machine-readable format (e.g. JSON, CSV).

policydocumentmanual

Data subject rights procedure documenting how each right is operationalised, verification steps, internal handoff processes and escalation paths.

Example: Data Subject Rights Fulfilment Procedure (Confluence), approved by DPO, with step-by-step workflows for: access, erasure, portability, rectification, restriction and objection, including identity verification steps, response templates, and SLA timers

Test: Request the DSR procedure. Verify: (1) a documented process exists for each of the six GDPR rights, (2) identity verification steps are defined, (3) internal handoff points (e.g. from support to engineering for erasure) are clearly specified, (4) procedure references the 30-day statutory deadline, (5) approved by DPO within 24 months.

recorddocumentmanual

Refusal and fee records for rights requests, showing the reasons sent to the individual and the evidence behind any finding that a request was manifestly unfounded or excessive.

Example: DSR refusal register 2026, with issued refusal letters

Test: Request the refusal and fee records. Verify: (1) every refused request carries a reason sent to the individual within the response period, (2) each refusal names the supervisory authority complaint route and the judicial remedy, (3) each fee charged or refusal made on the manifestly unfounded or excessive ground carries the evidence the organisation relied on, (4) no request in the period was charged for outside that ground, (5) identifying information was requested only where the record states a reasonable doubt about identity, (6) a refusal on the ground that the individual could not be identified records the demonstration behind it.

Questions (3)

boolean

Is there a documented process for handling data subject rights requests?

Each right should have a documented workflow, identity verification step, and defined internal handoff. A request tracking log must demonstrate requests are actioned within 30 days (or 90 days with documented extension).

multi

Which data subject rights can your organisation fulfil without requiring manual engineering intervention?

Access (subject access request, export of personal data)Rectification (correction of personal data)Erasure (deletion of personal data across all systems)Restriction (suppressing processing without deleting data)Portability (machine-readable export of personal data)Objection (suppressing processing for a stated reason)None of the above

Self-service or tooling-assisted fulfilment for access, portability and erasure is the expected standard for a mature product. Rights that require manual engineering effort introduce delay and error risk.

multi

Which of the following does your rights request process do?

Tells the individual the reasons when a request is refusedNames the supervisory authority complaint route and the judicial remedy in every refusalHandles requests free of chargeApplies a fee or a refusal only where a request is shown to be manifestly unfounded or excessive, with that evidence recordedAsks for identifying information only where there is a reasonable doubt about identityCompletes or refuses each request within the statutory response period, with any extension recordedNone of the above

Options run from the most commonly in place to the least. A refusal with no reasons and no complaint route leaves the individual with nowhere to go. Demanding identity documents for every request deters more people than it protects, and the burden of showing a request is excessive sits with the organisation rather than the requester.