For the complete documentation index, see llms.txt. This page is also available as Markdown.

How can you implement GDPR data subject rights in your business?

Chapter 3 of GDPR sets out certain rights which individuals have over their personal data. They are not principles or guidelines, but legally enforceable rights which your business must fulfil if a user or employee chooses to exercise them.

The table below lays out the eight core rights detailed by GDPR and how your business can help implement them in day-to-day practice.

Right
How your business can implement it

Right to be informed [Art. 13, 14&19]

• Ensure that your privacy policy is clear, detailed and easily accessible. • In your privacy policy, ensure you explain: • Provide your privacy policy at the point of data collection. • Regularly update your privacy policy to reflect any changes.

Right of access [Art. 15]

• Provide users with an easy mechanism, such as a webform, to request access to their personal data. • Consider implementing DSAR portals for scalable and efficient rights management. • Respond within a month to any DSAR requests. • Keep detailed logs of requests and responses.

Right to rectification [Art. 16]

• Respond to correction requests within a month. • Have procedures for correcting inaccurate personal data and informing sub-processors of any corrections.

Right to erasure (‘right to be forgotten’) [Art. 17]

• Implement processes allowing individuals to request deletion of their data. • Respond within a month to any erasure requests. • Make sure you have systems to identify and remove all data from your platforms and any sub-processor platforms in this instance.

Right to restriction of processing [Art. 18]

• Ensure you have technical mechanisms for temporarily stopping data processing when a data subject requests restriction.

Right to data portability [Art. 20]

• Provide data in a common, machine-readable format upon request, unless technically not feasible.

Right to object [Art. 21]

• Communicate objection rights upfront. • Allow objections to processing based on legitimate interest or public task. • Allow objections to direct marketing. • Implement opt-out systems for making these objections in practice.

Rights in automated decision making (ADM) [Art. 22]

• Notify users if ADM with legal or similarly ‘significant’ effects is taking place. Tell them why, how, and the consequences of the use of ADM. • Require them to consent to ADM before proceeding. • Inform them of the right to human intervention, contestation, and explanation and provide channels to access this.

These are all tasks with which a Privacy Partner can advise on and assist in setting up.

Last updated