TinRate Wiki The Expert Encyclopedia
Marketplace
W
TinRateWIKI
Article Browse

How do you properly handle data subject access requests under GDPR?

Beginner · How-to · GDPR Compliance

Answer

Verify the requestor's identity, locate all relevant data, provide it in accessible format within one month, and document the entire process.

Data subject access requests (DSARs) are fundamental GDPR rights that require systematic handling to ensure compliance:

Step 1: Receive and log - Establish clear channels for receiving requests (email, online form, post). Log all requests with timestamps and assign reference numbers.

Step 2: Verify identity - Confirm the requestor's identity to prevent unauthorized data disclosure. Request additional identification if needed, but don't create excessive barriers.

Step 3: Clarify scope - If the request is unclear, ask for clarification. Determine if they want all data or specific information.

Step 4: Search comprehensively - Look across all systems, databases, emails, paper files, and backups. Include data held by processors on your behalf.

Step 5: Assess exemptions - Consider if any exemptions apply, such as protecting other individuals' rights or privileged information.

Step 6: Prepare response - Provide data in accessible format (typically PDF or Word). Include information about processing purposes, retention periods, data sources, and sharing details.

Step 7: Respond timely - You have one month from receipt, extendable by two months for complex requests. Notify the individual of any extensions.

Step 8: Document everything - Keep records of the request, response, and any decisions made.

Axel Desmet from Cresco emphasizes that having robust procedures prevents delays and demonstrates accountability to regulators.

For personalized guidance, consult a GDPR Compliance specialist on TinRate.

Experts who can help

The following GDPR Compliance experts on TinRate Wiki can help with this topic:

Expert Role Company Country Rate
Axel Desmet Tech & Commercial Lawyer Cresco Belgium EUR 150/hr
Bertil van Eden Cyber Security Professional van Eden Secure Belgium EUR 120/hr
Bob van Bouwel Your Lead-Out Legal Lead-Out Legal Belgium EUR 100/hr
Eveline Van den Abeele Legal counsel Rechtaan Belgium EUR 140/hr
Inge Van Noppen Consultant in risk, internal control, compliance, GDPR Konfident Belgium EUR 125/hr
Philippe Kimpe Founder Lucy Belgium EUR 150/hr
Sylvia Beeckman IT Consultant Esbee. IT Consultancy Belgium EUR 50/hr
  1. What is GDPR and what does it cover?
    The General Data Protection Regulation (GDPR) is a comprehensive EU privacy law that governs how personal data of EU residents is collected, processed, and stored.
  2. What is GDPR and why does it matter for businesses?
    GDPR is the EU's comprehensive data protection law that regulates how personal data is collected, processed, and stored, with significant penalties for non-compliance.
  3. What constitutes personal data under GDPR?
    Personal data is any information relating to an identified or identifiable natural person, including direct and indirect identifiers.
  4. What is GDPR and what does it regulate?
    GDPR is the EU's General Data Protection Regulation that governs how personal data must be collected, processed, stored, and protected by organizations.
  5. What is GDPR and what does it regulate?
    GDPR is the EU's General Data Protection Regulation that governs how personal data of EU residents must be collected, processed, and protected by organizations.
  6. What are the typical costs of implementing GDPR compliance?
    GDPR compliance costs range from €10,000-€50,000 for small businesses to €500,000+ for enterprises, depending on complexity and data processing scope.
  7. What is a Data Protection Officer (DPO) and when is one required?
    A DPO is an independent expert who monitors GDPR compliance. Required for public authorities and organizations processing sensitive data at scale.
  8. What tools are available for managing GDPR consent and preferences?
    Popular consent management platforms include OneTrust, Cookiebot, TrustArc, and Osano, offering consent banners, preference centers, and compliance tracking.
  9. How to implement privacy by design in software development?
    Integrate privacy considerations from project inception through data minimization, security controls, user consent mechanisms, and regular privacy reviews.
  10. How should organizations handle GDPR data subject access requests?
    Verify identity, locate all personal data, provide comprehensive information within one month, and maintain detailed records of the process.

See also

Content is available under Creative Commons Attribution-ShareAlike License · TinRate Marketplace
Browse