Data subject rights procedure
How a request from a data subject is received, verified, logged, answered within the deadline and, where refused, explained.
How the register reads it
| Also called | DSAR procedure, individual rights procedure |
|---|---|
| Family | Privacy |
| Document type | Procedure. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Expected owner | The data protection officer or privacy lead. |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | GDPR or ISO 27701 is ticked and no line resolves to it. |
| Template | Subject access request procedure. |
Which standards require it, and what each expects it to contain
5 requiring clauses, 2 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27701:2025
ISO 27701 A.1.3.10 Handling requestsThe organization must define and document policies and procedures for handling and responding to legitimate requests from individuals, which can include requests for a copy of data or to lodge a complaint, handling them within appropriate defined response times, taking account of jurisdictions that set response times by complexity and volume and that require the individual be told of delay, with the appropriate response times stated in the privacy policy, and of jurisdictions that permit a fee in limited cases such as excessive or repetitive requests.
Common gap: Requests handled through general customer service with no privacy specific triage, so clocks start late
Source: ISO/IEC 27701:2025
ISO 27701 A.1.3.7 Access, correction or erasureThe organization must implement policies, procedures or mechanisms enabling individuals to obtain access to, correct and erase their personal data without undue delay, must define and meet a response time, must disseminate corrections and erasures through its systems and to authorized users and pass them to third parties who received the data, must have a route for disputes about accuracy or correction that includes telling the individual what changes were made and why corrections could not be made where that is so, and must keep current with jurisdictional restrictions on when and how these requests may be made.
Common gap: Erasure performed in the primary system while backups, archives, logs and analytics copies retain the data
Source: ISO/IEC 27701:2025
GDPR (Regulation (EU) 2016/679)
GDPR Art. 12 Transparent information, communication and modalities for rightsProvide the Article 13 and 14 information and every Article 15 to 22 and 34 communication in a concise, transparent, intelligible and easily accessible form, in clear and plain language, with particular care where the information is addressed to a child, normally in writing including by electronic means. Facilitate the exercise of data subject rights and do not refuse to act unless the controller demonstrates it cannot identify the data subject. Provide information on action taken without undue delay and in any event within one month of receipt, extendable by two further months where the complexity and number of requests requires it, with the data subject informed of the extension and its reasons within the first month. Where no action is taken, say so within one month with the reasons and inform the data subject of the right to lodge a complaint with a supervisory authority and to seek a judicial remedy. Act free of charge; a reasonable fee or refusal is available only for manifestly unfounded or excessive requests, and the controller bears the burden of demonstrating that character. Additional information may be requested only where there are reasonable doubts about the requester's identity.
Common gap: The one month clock started when the request reached the privacy team rather than when it reached the organisation
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 15 Right of access by the data subjectOn request, confirm whether personal data concerning the data subject is being processed and, where it is, provide access to that data together with the purposes, the categories of personal data, the recipients or categories of recipient including any in third countries or international organisations, the envisaged storage period or the criteria setting it, the existence of the rights to rectification, erasure, restriction and objection, the right to lodge a complaint with a supervisory authority, any available information on the source where the data was not collected from the data subject, and the existence of automated decision-making including profiling with meaningful information about the logic involved and its significance and envisaged consequences. Where data has been transferred to a third country, inform the data subject of the Article 46 safeguards relating to the transfer. Provide a copy of the personal data undergoing processing, in a commonly used electronic form where the request was made electronically, free for the first copy and at a reasonable fee based on administrative costs for further copies. The right to obtain a copy must not adversely affect the rights and freedoms of others.
Common gap: Structured database records returned while email, chat, ticketing and free text notes naming the person are never searched
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 17 Right to erasure (right to be forgotten)Erase personal data without undue delay where the data is no longer necessary for the purposes it was collected or processed for, where consent is withdrawn and no other legal ground applies, where the data subject objects under Article 21(1) and there are no overriding legitimate grounds or objects to direct marketing under Article 21(2), where the data has been unlawfully processed, where erasure is required by Union or Member State law, or where the data was collected in relation to information society services offered to a child. Where the data has been made public, take reasonable steps including technical measures, allowing for available technology and the cost of implementation, to inform other controllers processing it that erasure of any links to, or copies or replications of, the data has been requested. The obligation does not apply to the extent processing is necessary for freedom of expression and information, for compliance with a legal obligation or a public interest task, for public health reasons, for archiving, research or statistics under Article 89(1) where erasure would seriously impair those objectives, or for the establishment, exercise or defence of legal claims.
Common gap: Records flagged as deleted in the application while remaining fully readable in the database, the warehouse and the search index
Source: GDPR (Regulation (EU) 2016/679)
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a register