How can you implement GDPR data subject rights in your business?
Chapter 3 of GDPR sets out certain rights which individuals have over their personal data. They are not principles or guidelines, but legally enforceable rights which your business must fulfil if a user or employee chooses to exercise them.
The table below lays out the eight core rights detailed by GDPR and how your business can help implement them in day-to-day practice.
Right to be informed [Art. 13, 14&19]
• Ensure that your privacy policy is clear, detailed and easily accessible. • In your privacy policy, ensure you explain: • Provide your privacy policy at the point of data collection. • Regularly update your privacy policy to reflect any changes.
Right of access [Art. 15]
• Provide users with an easy mechanism, such as a webform, to request access to their personal data. • Consider implementing DSAR portals for scalable and efficient rights management. • Respond within a month to any DSAR requests. • Keep detailed logs of requests and responses.
Right to rectification [Art. 16]
• Respond to correction requests within a month. • Have procedures for correcting inaccurate personal data and informing sub-processors of any corrections.
Right to erasure (‘right to be forgotten’) [Art. 17]
• Implement processes allowing individuals to request deletion of their data. • Respond within a month to any erasure requests. • Make sure you have systems to identify and remove all data from your platforms and any sub-processor platforms in this instance.
Right to restriction of processing [Art. 18]
• Ensure you have technical mechanisms for temporarily stopping data processing when a data subject requests restriction.
Right to data portability [Art. 20]
• Provide data in a common, machine-readable format upon request, unless technically not feasible.
Right to object [Art. 21]
• Communicate objection rights upfront. • Allow objections to processing based on legitimate interest or public task. • Allow objections to direct marketing. • Implement opt-out systems for making these objections in practice.
Rights in automated decision making (ADM) [Art. 22]
• Notify users if ADM with legal or similarly ‘significant’ effects is taking place. Tell them why, how, and the consequences of the use of ADM. • Require them to consent to ADM before proceeding. • Inform them of the right to human intervention, contestation, and explanation and provide channels to access this.
These are all tasks with which a Privacy Partner can advise on and assist in setting up.
Last updated

