Policy Register

Data subject rights procedure

How a request from a data subject is received, verified, logged, answered within the deadline and, where refused, explained.

How the register reads it

Also calledDSAR procedure, individual rights procedure
FamilyPrivacy
Document typeProcedure. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Expected ownerThe data protection officer or privacy lead.
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenGDPR or ISO 27701 is ticked and no line resolves to it.
TemplateSubject access request procedure.

Which standards require it, and what each expects it to contain

5 requiring clauses, 2 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27701:2025

ISO 27701 A.1.3.10 Handling requests

The organization must define and document policies and procedures for handling and responding to legitimate requests from individuals, which can include requests for a copy of data or to lodge a complaint, handling them within appropriate defined response times, taking account of jurisdictions that set response times by complexity and volume and that require the individual be told of delay, with the appropriate response times stated in the privacy policy, and of jurisdictions that permit a fee in limited cases such as excessive or repetitive requests.

Evidence an auditor accepts: Documented request handling procedure covering identification, triage, response and escalation; response times published in the privacy policy and measured in operation; delay notification procedure and evidence of use
Common gap: Requests handled through general customer service with no privacy specific triage, so clocks start late
Source: ISO/IEC 27701:2025
ISO 27701 A.1.3.7 Access, correction or erasure

The organization must implement policies, procedures or mechanisms enabling individuals to obtain access to, correct and erase their personal data without undue delay, must define and meet a response time, must disseminate corrections and erasures through its systems and to authorized users and pass them to third parties who received the data, must have a route for disputes about accuracy or correction that includes telling the individual what changes were made and why corrections could not be made where that is so, and must keep current with jurisdictional restrictions on when and how these requests may be made.

Evidence an auditor accepts: Documented procedures for access, correction and erasure with defined response times; request log with dates received and completed, and performance against the response time; evidence corrections and erasures propagated to all systems and to third parties
Common gap: Erasure performed in the primary system while backups, archives, logs and analytics copies retain the data
Source: ISO/IEC 27701:2025

GDPR (Regulation (EU) 2016/679)

GDPR Art. 12 Transparent information, communication and modalities for rights

Provide the Article 13 and 14 information and every Article 15 to 22 and 34 communication in a concise, transparent, intelligible and easily accessible form, in clear and plain language, with particular care where the information is addressed to a child, normally in writing including by electronic means. Facilitate the exercise of data subject rights and do not refuse to act unless the controller demonstrates it cannot identify the data subject. Provide information on action taken without undue delay and in any event within one month of receipt, extendable by two further months where the complexity and number of requests requires it, with the data subject informed of the extension and its reasons within the first month. Where no action is taken, say so within one month with the reasons and inform the data subject of the right to lodge a complaint with a supervisory authority and to seek a judicial remedy. Act free of charge; a reasonable fee or refusal is available only for manifestly unfounded or excessive requests, and the controller bears the burden of demonstrating that character. Additional information may be requested only where there are reasonable doubts about the requester's identity.

Evidence an auditor accepts: The request register showing receipt date, response date, and any extension with its notification and stated reasons; readability evidence for the privacy information, such as a plain language review or a reading age assessment; the identity verification standard applied, with the reasoning that it is proportionate rather than routine
Common gap: The one month clock started when the request reached the privacy team rather than when it reached the organisation
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 15 Right of access by the data subject

On request, confirm whether personal data concerning the data subject is being processed and, where it is, provide access to that data together with the purposes, the categories of personal data, the recipients or categories of recipient including any in third countries or international organisations, the envisaged storage period or the criteria setting it, the existence of the rights to rectification, erasure, restriction and objection, the right to lodge a complaint with a supervisory authority, any available information on the source where the data was not collected from the data subject, and the existence of automated decision-making including profiling with meaningful information about the logic involved and its significance and envisaged consequences. Where data has been transferred to a third country, inform the data subject of the Article 46 safeguards relating to the transfer. Provide a copy of the personal data undergoing processing, in a commonly used electronic form where the request was made electronically, free for the first copy and at a reasonable fee based on administrative costs for further copies. The right to obtain a copy must not adversely affect the rights and freedoms of others.

Evidence an auditor accepts: The search methodology showing every system, archive and unstructured store searched, and how completeness was assured; a worked response covering all the supplementary information items, not only the copy of the data; the redaction position and the applied redaction log where third party data was withheld, with a reason recorded per redaction
Common gap: Structured database records returned while email, chat, ticketing and free text notes naming the person are never searched
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 17 Right to erasure (right to be forgotten)

Erase personal data without undue delay where the data is no longer necessary for the purposes it was collected or processed for, where consent is withdrawn and no other legal ground applies, where the data subject objects under Article 21(1) and there are no overriding legitimate grounds or objects to direct marketing under Article 21(2), where the data has been unlawfully processed, where erasure is required by Union or Member State law, or where the data was collected in relation to information society services offered to a child. Where the data has been made public, take reasonable steps including technical measures, allowing for available technology and the cost of implementation, to inform other controllers processing it that erasure of any links to, or copies or replications of, the data has been requested. The obligation does not apply to the extent processing is necessary for freedom of expression and information, for compliance with a legal obligation or a public interest task, for public health reasons, for archiving, research or statistics under Article 89(1) where erasure would seriously impair those objectives, or for the establishment, exercise or defence of legal claims.

Evidence an auditor accepts: Erasure records showing the ground relied on, the decision, and the date the data actually left each system; a deletion capability map covering production, replicas, warehouses, logs, search indexes, backups and processors, with method and lag for each; where an exemption is applied, the specific Article 17(3) ground and the necessity reasoning for the data actually retained
Common gap: Records flagged as deleted in the application while remaining fully readable in the database, the warehouse and the search index
Source: GDPR (Regulation (EU) 2016/679)

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Data sharing agreement · International data transfer policy