GDPR data subject requests: a workflow that actually works
5 min read · Certifyi research team · Updated July 2026
A data subject request must be answered within one month, extendable by two months for complex cases if you notify the person in time. The workflow that works has four stages: intake and identity verification, discovery across systems, review and redaction, then response and logging.
The rights you must service
- Access: a copy of their personal data and supporting information
- Rectification: correction of inaccurate data
- Erasure: deletion where a valid ground applies
- Restriction: pause processing while a dispute is resolved
- Portability: structured, machine-readable export
- Objection: to processing based on legitimate interests or direct marketing
A four-stage workflow
- Intake: a single monitored channel, with the clock started and logged on arrival
- Verify identity proportionately, without demanding excessive documentation
- Discovery: query every system in your data map, including backups and third-party processors
- Review: redact other people's personal data and genuinely privileged material
- Respond in a usable format and log what was provided, when and by whom
Where the month disappears
Common time sinks
- No single intake channel, so the request sits in someone's inbox for two weeks
- No data map, so discovery becomes an open-ended engineering hunt
- Processors who are slow to respond because the DPA sets no SLA
- Redaction done manually with no template or precedent
Reducing cost per request
The two structural fixes are a current data map and processor DPAs that commit vendors to assist within a defined window. Beyond that, build a repeatable export routine for the most common request type rather than treating each as bespoke.
Key takeaways
- One month to respond, extendable by two for complex requests.
- A single intake channel starts the clock reliably.
- Discovery is only as fast as your data map.
- Log every request and response as evidence.
Frequently asked questions
Can we charge for a request?
Generally no. A reasonable fee is permitted only for manifestly unfounded or excessive requests, or for additional copies.
Do we have to search backups?
Backups are in scope in principle. Regulators accept proportionate approaches where restoration is disproportionately difficult, but you must be able to explain your reasoning.
What if the request comes through support?
It still counts and the clock still starts. Train front-line staff to route requests immediately rather than answering them ad hoc.
Can we refuse an erasure request?
Sometimes. If you have a legal obligation to retain the data or another lawful ground overrides, you may refuse, but you must explain why.
Related reading
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead, at published pricing from $8,000/year.
Book a 20-min deal readiness call