Verify the requestor's identity, locate all relevant data, provide it in accessible format within one month, and document the entire process.
Data subject access requests (DSARs) are fundamental GDPR rights that require systematic handling to ensure compliance:
Step 1: Receive and log - Establish clear channels for receiving requests (email, online form, post). Log all requests with timestamps and assign reference numbers.
Step 2: Verify identity - Confirm the requestor's identity to prevent unauthorized data disclosure. Request additional identification if needed, but don't create excessive barriers.
Step 3: Clarify scope - If the request is unclear, ask for clarification. Determine if they want all data or specific information.
Step 4: Search comprehensively - Look across all systems, databases, emails, paper files, and backups. Include data held by processors on your behalf.
Step 5: Assess exemptions - Consider if any exemptions apply, such as protecting other individuals' rights or privileged information.
Step 6: Prepare response - Provide data in accessible format (typically PDF or Word). Include information about processing purposes, retention periods, data sources, and sharing details.
Step 7: Respond timely - You have one month from receipt, extendable by two months for complex requests. Notify the individual of any extensions.
Step 8: Document everything - Keep records of the request, response, and any decisions made.
Axel Desmet from Cresco emphasizes that having robust procedures prevents delays and demonstrates accountability to regulators.
For personalized guidance, consult a GDPR Compliance specialist on TinRate.
The following GDPR Compliance experts on TinRate Wiki can help with this topic:
| Expert | Role | Company | Country | Rate |
|---|---|---|---|---|
| Axel Desmet | Tech & Commercial Lawyer | Cresco | Belgium | EUR 150/hr |
| Bertil van Eden | Cyber Security Professional | van Eden Secure | Belgium | EUR 120/hr |
| Bob van Bouwel | Your Lead-Out Legal | Lead-Out Legal | Belgium | EUR 100/hr |
| Eveline Van den Abeele | Legal counsel | Rechtaan | Belgium | EUR 140/hr |
| Inge Van Noppen | Consultant in risk, internal control, compliance, GDPR | Konfident | Belgium | EUR 125/hr |
| Philippe Kimpe | Founder | Lucy | Belgium | EUR 150/hr |
| Sylvia Beeckman | IT Consultant | Esbee. IT Consultancy | Belgium | EUR 50/hr |