
support.data-subject-request·version 1.0.0·draft2 to verify
The requester gets a reasoned answer within one month, the data is found and the decided action (correct, delete, restrict, copy) is actually done and recorded.
Any person — customer, ex-employee, job applicant, website visitor — asks what data the company holds on them, or asks to correct, delete, restrict, export it, or objects to processing. Not for a suspected personal-data breach — use tech.security-audit. Not for maintaining the register of processing activities itself — use company.gdpr-register. A request may arrive addressed to anyone in the company; once recognized, this playbook takes over.
Any step can wait until a date and reopens by itself; every closed step leaves evidence (a note, a link, a number).
Record: requester, date received, channel, which right is invoked (access, rectification, erasure, restriction, portability, objection), verbatim text. Compute the deadline: one month from receipt; if the month has no equivalent day, the last day of that month.
Done when the request log entry exists with the received date and the deadline date. ⛔ "Received" is when it reached any company mailbox, not when support opened it.
Search mail (bc mail search), documents, CRM, invoicing, spreadsheets, website forms, backups, and list systems held by processors (payroll, hosting, mail provider).
Done when a written inventory names each system, what it holds, and who controls it — including "checked, nothing found" per system.
If the requester is not already known to the channel they wrote from, ask for confirmation through a channel already on file.
Done when identity is confirmed, or the doubt is written down and the answer notes it.
For access: a copy or structured export of the personal data, plus purposes, categories, recipients, retention period and the source if not collected from the person. Draft the response letter; if the company intends to refuse or to extend by up to two months, draft the reasons and the complaint information.
Done when the draft letter and the data export exist and are dated.
Approval · S5 · owner — the run stops until a named person records the decision
Review the pack: grant in full, grant in part, refuse (name the specific ground), or extend with the reason sent within the first month. Check erasure against retention duties — invoice and payroll data the company must keep by law is restricted, not deleted.
Done when the owner has named the decision in writing.
Approval · S6 · owner — the run stops until a named person records the decision
Send the approved letter with the export (a password-protected archive or a secure link, never a plain attachment of a full export to an unverified address).
Done when the sent message is in the mail record with its date, within the deadline.
Rectify, erase, restrict or export as approved — in every system from S2, including the mail provider's deletion, and note where data survives in immutable backups and when those age out.
Done when each system from S2 shows the change or a written note why it cannot (legal retention, backup lifecycle).
Write the outcome in the GDPR register's request log: what was asked, decided, sent, changed, and the dates. Set a task to confirm erasure/restriction propagated (a check two weeks out).
Done when the log entry is complete and the follow-up task exists.
| Symptom | Response |
|---|---|
| The deadline is already past when the request is noticed | Answer immediately anyway; record the miss in the log and in the next company.gdpr-register review — a late answer is a violation, silence is a worse one. |
| Requester identity cannot be confirmed | Do not send data; state in writing what is needed to confirm identity, pause the clock honestly in the log, re-check when answered. |
| The data sits in a processor's system | Instruct the processor in writing, get their confirmation with a date, record it; the answer deadline still belongs to the company. |
| Erasure conflicts with a legal retention duty | Restrict instead (mark, stop processing, keep only for the legal purpose) and say so in the answer. |
| The requester complains to the supervisory authority | Do not argue by e-mail; hand the complete S8 log to the owner the same day — the record is the defence. |
The request verbatim with received date · the S2 inventory · identity check (or the reason none was needed) · the approved decision (who, when) · the sent letter and export checksum · per-system confirmation of the S7 change · the final log entry. Keep for the retention period the GDPR register defines.
After every 5 requests ask: how many days from receipt to answer, and which step consumed the wait? Did S2 find a system holding the data that nobody knew about? Was any decision reversed after the answer went out? A new version changes the step that caused the wait or the miss, and says so in its change note.
Obligātās sīkdatnes tur sarunu kopā. Analītika ir izslēgta, līdz tu atļauj — tā neliek nevienu sīkdatni un neglabā ierīces identifikatoru.Necessary storage keeps your conversation together. Analytics is off until you allow it — it sets no cookie and stores no device identifier. Ko mēs glabājamWhat we store