← Files VeraARCHIVED FILE
assets/courses/comunicazione-professionale/files/input/source-en.md
9.62 KB · Oct 5, 2026 · 18:29 UTC
# Respect individuals’ rights Source: European Data Protection Board (EDPB), data protection guide for small business. Text extract of the sections on rights, handling requests and access. Official English page text; images and video excluded. Headings and references are preserved; HTML formatting has been converted to text. Captured: 14 September 2026. Check for updates during execution. https://www.edpb.europa.eu/sme/be-compliant/respect-individuals-rights_en © European Data Protection Board. Reuse: https://www.edpb.europa.eu/copyright_en --- Which rights do individuals have under the GDPR? The GDPR provides the following rights to data subjects, i.e. individuals whose data is processed: Right to be informed Right of access Right to rectification Right to erasure (right to be forgotten) Right to restriction of processing Right to data portability Right to object Right not be subject to a decision based solely on automated processing Please note that some of those rights do not apply in all situations, you can see the data subject rights for each legal basis table for more information. The data controller is under an obligation to respond to requests of data subjects who exercise their rights and must facilitate the exercise of these rights. The data processor must assist the data controller in this task. Checklist of what to do concerning data subject rights: Be prepared : Develop systems and procedures to respond to data subject rights requests and train your staff to integrate data subject rights requests into your internal workflows. Facilitate the exercise of rights : Make it easy for data subjects to know what their rights are and how to contact you to exercise them. Know your data flows : Keep your register up to date to rapidly identify the data you process and to locate and retrieve information efficiently. Be transparent : Always inform data subjects in a clear and understandable way about the personal data you process, prior to the processing (for instance in your privacy policy) and during the processing (for instance when complying with a data subject access request). Answer within 1 month : Always answer a data subject request within one month. If you need additional time to answer or if you cannot comply with the request: inform the data subject of this within the one month period. Pass it on : When you receive a request concerning personal data you have transferred to other recipients, do not forget, if need be, to inform the recipients of the result of the request. Document : Keep track of requests from data subjects, and record your answers, also keep track of your reasoning when you do not reply to a request. Read more How to handle data subject rights request Transparency is key in data protection in general and, of course, in the context of data subject’s rights. The data controller must: communicate with data subjects in a clear and understandable language (this is particularly important in cases when an organisation is addressing children); and facilitate the exercise of these rights, in particular via electronic means. For example, you can provide an online form on your website which data subjects can use to easily exercise their data protection rights. Respond in writing The general rule is that an organisation should respond to an individual’s access request in the same way the request was made, or in the way in which the data subject specifically asked for a response. Preferably, you should answer in writing, including where appropriate by electronic means. A reply to a data subject right request could be given orally, but that is not advised as you have to be able to prove that you have answered the request. Respond within one month The GDPR specifies in how much time a data controller must respond to a request, and in what cases it can charge fees. When data subjects exercise one of their rights, the controller must respond within one month . If the request is too complex and more time is needed to answer, then your organisation may extend the time limit by two further months, provided that the data subject is informed within one month after receiving the request. If your organisation can prove that the request is manifestly unfounded or excessive, in particular because of its repetitive character, you may either charge a reasonable fee or refuse to grant the request. If your organisation has reasonable doubts about the identity of the person making the request (for instance the request is made with another email address than the one usually used by your customer, or it is made outside of an authenticated customer account), you may request additional information to confirm the identity of the data subject before answering. If you do not intend to comply with the data subject’s specific request, you must inform the data subject within one month of receiving the request of the reasons why you will not grant the request (e.g. why you are not erasing the requested data). In addition, you must inform the data subjects of the possibility of lodging a complaint with their national data protection authority and seeking a judicial remedy. Do not charge a fee Your organisation cannot claim any payment from a data subject asking to exercise one of their rights. You may, however, charge a fee if the data subject’s request is manifestly unfounded or excessive, in particular because of their repetitive character. The calculation of the fee must take into account the administrative cost of responding to the request for your organisation. As explained above, it is also possible to refuse to act on a request that is manifestly unfounded or excessive. In such a situation, you must be able to demonstrate that this is the case. In practice A data subject lodges access requests every two months with the carpenter that manufactured their table. The carpenter answered the first request completely. As the carpenter does not process personal data as part of its core activity and they did not provide more than one service to the data subject, it is unlikely that changes occurred in the dataset concerning the data subject. The data subject has clarified that the new request concerns the same information as the last request. Consequently this request may be regarded as excessive due to its repetitive character. If the carpenter decides to provide the personal data to the data subject but against a fee, it is advisable to inform them in advance thereof, thus giving them a chance to withdraw the request to avoid being charged. Alternatively the carpenter can inform the data subject of the reasons why they will not reply to this request, as well as on the possibility to lodge a complaint with a data protection authority and seek a judicial remedy. data controller: https://www.edpb.europa.eu/sme/learn-the-basics/data-controller-or-data-processor_en data processor: https://www.edpb.europa.eu/sme/learn-the-basics/data-controller-or-data-processor_en EUR-Lex: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN#d1e2161-1-1 EUR-Lex: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN#d1e3150-1-1 Right of access By exercising their right of access, data subjects can verify the lawfulness of each processing activity that concerns them. When they are exercising their right of access, data subjects should get a confirmation of the controller as to whether or not their personal data is being processed. If this is the case, data subjects have access to their personal data and the following information : the purposes of the processing; the categories of personal data concerned; the recipients (or categories of recipients) of the personal data; the retention period for the personal data, or the criteria used to determine that period; the existence of the right to request from the data controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing; the existence of the right to lodge a complaint with a data protection authority; the source of the data (when the personal data is not directly collected from the data subject); the existence of automated decision-making, including profiling, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject; when personal data is transferred out of the European Union, all the appropriate safeguards put into place (pursuant Art. 46 GDPR relating to data transfers). Moreover, the person has a right to receive (free of charge) a copy of the personal data related to them that your organisation is processing. If the person asks for additional copies, your organisation could decide to charge a reasonable fee which is calculated on the basis of the administrative cost of making copies. Note that in most cases, individuals cannot be required to pay a fee to access their personal information. Where a request is made electronically, your organisation should provide the required information in a commonly used electronic format, unless the individual requests otherwise. Important to note Before you provide a copy of the personal data, you must check that doing so will not affect the rights and freedoms of others (e.g. if information relating to more than one person is processed in the same file, or information relating to trade secrets and intellectual property). Read more EUR-Lex: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN#d1e2513-1-1 EDPB: https://edpb.europa.eu/our-work-tools/documents/public-consultations/2022/guidelines-012022-data-subject-rights-right_en
SHA-256: 75b96074c44743ff328f139d45ad296dd8b392a854809b499ff9b8733aff079d