Verify identity, locate all personal data, provide comprehensive information within one month, and maintain detailed records of the process.
Handling data subject access requests (DSARs) requires a systematic approach to ensure GDPR compliance within the one-month deadline.
Verification: First, verify the requestor's identity using proportionate methods. Don't over-collect data, but ensure you're releasing information to the right person.
Scope identification: Locate all personal data about the individual across all systems, databases, backups, and third parties. This includes emails, documents, CCTV footage, and logs.
Response compilation: Provide a copy of personal data in a commonly used electronic format. Include supplementary information: processing purposes, data categories, recipients, retention periods, data sources, and automated decision-making details.
Legal considerations: You can refuse manifestly unfounded or excessive requests, especially repetitive ones. Consider whether other people's privacy rights would be affected by disclosure.
Timeline management: Respond within one month, extendable by two months for complex requests. Inform the individual immediately about any extension and reasons.
Fee structure: Generally free for the first request, but reasonable fees apply for additional copies or manifestly unfounded/excessive requests.
Documentation: Keep detailed records of all requests and responses for accountability.
IT Consultant Sylvia Beeckman at Esbee. IT Consultancy emphasizes implementing automated tools to track and manage DSARs efficiently, ensuring no requests fall through the cracks.
For personalized guidance, consult a GDPR Compliance specialist on TinRate.
The following GDPR Compliance experts on TinRate Wiki can help with this topic:
| Expert | Role | Company | Country | Rate |
|---|---|---|---|---|
| Axel Desmet | Tech & Commercial Lawyer | Cresco | Belgium | EUR 150/hr |
| Bertil van Eden | Cyber Security Professional | van Eden Secure | Belgium | EUR 120/hr |
| Bob van Bouwel | Your Lead-Out Legal | Lead-Out Legal | Belgium | EUR 100/hr |
| Eveline Van den Abeele | Legal counsel | Rechtaan | Belgium | EUR 140/hr |
| Inge Van Noppen | Consultant in risk, internal control, compliance, GDPR | Konfident | Belgium | EUR 125/hr |
| Philippe Kimpe | Founder | Lucy | Belgium | EUR 150/hr |
| Sylvia Beeckman | IT Consultant | Esbee. IT Consultancy | Belgium | EUR 50/hr |