Data subject rights and DSARs
GDPR requires organizations to facilitate the exercise of specific rights granted to individuals regarding their personal data, most notably through Data Subject Access Requests (DSARs). Organizations must provide a mechanism for individuals to access, correct, delete, or move their data within strict legal timeframes.
What it means
Chapter 3 establishes that individuals have ownership over their personal data. This includes the right to be informed about how data is used, the right to access their data (DSAR), the right to rectify inaccuracies, and the right to erasure (the "right to be forgotten"). It also covers more technical rights like data portability and the right to object to or restrict certain types of processing.
In practice, this means an organization cannot ignore a request for personal data simply because it is difficult to retrieve. The requirement applies regardless of whether the request comes via a formal legal letter, an email, or a social media message. Organizations must be able to identify all locations where a specific individual's data resides and extract or delete it accurately.
How to meet it
- Establish a written internal procedure for handling DSARs, including clear steps for intake, verification, and fulfillment.
- Create a dedicated communication channel (e.g., a specific email address or web form) where individuals can easily submit requests.
- Implement an identity verification process to ensure personal data is not accidentally disclosed to an unauthorized third party.
- Maintain an up-to-date data map or inventory so you know exactly which databases, cloud services, and files contain personal data.
- Set up a tracking system (such as a ticket queue) to monitor request deadlines, ensuring responses are sent within the statutory one-month window.
- Train customer-facing staff to recognize a "right" being exercised, even if the requester does not explicitly mention "GDPR" or "DSAR."
Evidence an auditor asks for
- A copy of the organization's Data Subject Rights Policy and internal SOPs.
- A DSAR Log recording the date requests were received, the nature of the request, the verification method used, and the date of completion.
- Redacted samples of completed responses sent to data subjects.
- Evidence of staff training records specifically covering the recognition and escalation of subject rights requests.
Common pitfalls
- Missing the one-month response deadline due to a lack of centralized tracking or internal delays in gathering data from different departments.
- Over-redaction or under-redaction, where organizations either fail to provide required information or accidentally leak other people's personal data within a DSAR response.
- Failing to search all data silos, such as ignoring email archives, Slack/Teams logs, or backup tapes during the collection process.
- Creating overly burdensome identity verification requirements that act as a barrier to the individual exercising their rights.