Setting Up a Process for Data Subject Rights (Access, Erasure, Objection)

Customers, website visitors, applicants, or former business partners can request information about their stored data or demand its deletion at any time. So that such a request does not turn into ad hoc stress, companies need a resilient, repeatable process.
In brief: Articles 12-22 GDPR give data subjects rights to access, rectification, erasure, restriction, data portability, and objection. Companies must generally respond to requests free of charge and within one month. Anyone who fails to meet this obligation, or meets it late, risks complaints to the supervisory authority and fines of up to €20 million or 4% of global annual turnover.
What rights do data subjects have under the GDPR?
Data subjects have six central rights against every company that processes their personal data, based on Articles 12-22 GDPR. These include the right to access information about which data is processed, the right to rectification of inaccurate information, the right to erasure, the right to restriction of processing, the right to data portability, and the right to object to certain processing activities. These rights apply regardless of whether the person is a customer, website visitor, applicant, or another data subject, and regardless of whether a business relationship currently exists. For your company, this means: every incoming request relating to one of these rights must be recognized, assigned to the right department, and answered on time, regardless of the channel through which it arrives.
How do you set up the process for data subject requests?
A resilient process for data subject rights consists of five building blocks, ranging from the initial request to documented completion. It is important that the process is not carried only in one person's head, but is defined in a way that also works during vacation, illness, or staff turnover.
- Define a central point of intake and responsibility for data subject requests.
- Define identity verification for the requester (without collecting unnecessary additional data).
- Define a standard process with deadline tracking for each right (access, erasure, objection, and so on).
- Ensure responses within one month; extend only with justification, by up to two months.
- Document requests and their completion in an audit-proof manner.
The access request under Article 15 is in practice the most common request; a prepared template for response letters and internal routing saves valuable time in a real case and prevents the deadline from passing unnoticed. Whether your company is already sufficiently set up for such requests, or where the process still has gaps, can be checked in a structured way as part of a Company Audit.
What deadline applies for responding?
Responding to data subject requests is generally subject to a one-month deadline. This one-month period starts from when the request is received by your company, not from when the responsible department becomes internally aware of it; if a request initially lands in the general customer mailbox and is only later forwarded to the right department, the deadline still starts running regardless. Only in justified cases, such as particularly complex or numerous requests, may the deadline be extended by a further two months. Requests must generally be processed free of charge, so deadline tracking should be firmly anchored in the process.
What are the consequences of violating data subject rights?
Anyone who fails to fulfill data subject rights, or fulfills them late, first risks a complaint from the data subject to the competent supervisory authority. Such a complaint can turn into a formal investigation procedure, which can ultimately result in fines of up to €20 million or 4% of global annual turnover. Besides the financial risk, poorly organized handling of data subject requests also affects the trust of customers and business partners whenever a request goes nowhere or takes unnecessarily long. A cleanly documented process with clear responsibility and deadline tracking significantly reduces this risk, because every request can then be demonstrably processed on time if in doubt.
Frequently asked questions
Who can submit a request for access, erasure, or objection?
In principle, any data subject whose personal data your company processes: customers, website visitors, applicants, or former business partners. The rights under Articles 12-22 GDPR apply to them regardless of any existing business relationship, so former customers or rejected applicants can also submit a request.
Does processing a data subject request cost anything?
No, requests must generally be processed free of charge. The internal effort for review, research, and response lies with the company and is best kept in check through a standardized, repeatable process.
When does the one-month deadline start?
The deadline begins when the request is received by your company, not only once the responsible department becomes aware of it internally. That is why a central point of intake for data subject requests is important, so that no time is lost through internal forwarding.
Do I have to verify the identity of the requester?
Yes, identity verification is part of a resilient process, though without collecting unnecessary additional data for it. The level of verification should match the sensitivity of the requested data, so that data subjects are not burdened unnecessarily and requests are not carelessly answered to unauthorized parties.
What happens if a request is not answered on time?
The data subject can file a complaint with the competent supervisory authority. This can lead to an investigation procedure and, further down the line, to fines of up to €20 million or 4% of global annual turnover, which is why audit-proof documentation of all requests and responses is important.
Source: Articles 12-22 GDPR. This article is general information and does not replace legal advice for individual cases. As of: July 2026.
Share this article
Stay up to date
Get the latest articles, insights and industry updates straight to your inbox.
Decide for yourself what Google shows you
Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.
Add provimedia.de to my preferred sourcesRelated articles
More articles you might find interesting.
Recapitulative Statement (ZM), OSS, and Intrastat in EU Trade
ZM due by the 25th of the following month, OSS filed quarterly, Intrastat from the threshold: EU reporting obligations explained compactly.
Ensuring Product Safety Under the GPSR
The GPSR and Germany's ProdSG require every seller of non-food products to carry out a risk analysis, appoint an EU responsible person, and provide warning notices, even for tiny quantities.
Product Liability: When Manufacturers Are Liable Without Fault
Manufacturers are liable without fault for defective products: product liability insurance protects against claims that could threaten a company's existence.
Ihre Unternehmerpflichten im Griff
Company Audit erstellt Ihnen in wenigen Minuten eine individuelle Pflichtenliste – mit Fristen-Kalender, Erinnerungen und KI-Assistent. Für Selbständige und KMU.