GDPR Data Subject Rights Checklist — Articles 15–22 DSR Handling

Last updated: 2026-04-21 — ComplianceStack Editorial Team

13 items
🎯

Generate Your Personalized GDPR Checklist

Tell us about your organization and we'll tailor this 13-item checklist to your situation — highlighting your gaps, marking what you already have, and calculating your readiness score. Free. Instant. Downloadable.

Free · Instant · No account required
Reference Checklist Progress 0 of 13 reviewed

GDPR Articles 15–22 grant individuals eight data subject rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), notification of rectification/erasure/restriction to recipients (Art. 19), data portability (Art. 20), right to object (Art. 21), and rights related to automated decision-making (Art. 22). Controllers must respond to DSR requests without undue delay and within one month (extendable by two months for complex or numerous requests). In 2024, DSR violations were the second most common basis for supervisory authority complaints across the EU. Organisations that fail to respond, respond incompletely, or apply exemptions incorrectly face fines of up to €20 million or 4% of global annual turnover. This 19-item checklist covers every element of a compliant DSR handling procedure.

Generate Your Personalized Checklist

Tell us about your data subject rights (dsr) and we'll filter this checklist to what applies to you — with a readiness score and priority gaps highlighted.

Checked items will be marked ✅ complete in your personalized checklist.

📄 Reference Checklist

Generic — use the generator above for a personalized version
Priority Legend:
● Critical ● High ● Medium ● Ongoing

GDPR Reference Checklist for Data Subject Rights (DSR)

SEO Reference

Use the generator above for your personalized checklist. The complete reference checklist is below.

GDPR Compliance Checklist for Data Subject Rights (DSR)

1

Establish a clear, accessible DSR submission channel and publicise it in your Privacy Notice

Critical 1-2 days

Individuals must be able to exercise their rights without difficulty. Provide at least one accessible submission mechanism (dedicated email address, web form, or in-app request). The submission channel must be described in your Article 13/14 Privacy Notice. Do not require individuals to use a format that creates barriers — a written request by email is sufficient regardless of whether you provide a form.

GDPR Articles 12(1), 13(2)(b), 14(2)(c); EDPB Guidelines on the exercise of data subjects' rights
2

Implement identity verification procedures proportionate to the sensitivity of the data

Critical 1-2 days (process design)

Article 12(6) allows controllers to request additional information to confirm identity when in doubt — but the verification burden must be proportionate. For low-sensitivity requests, email confirmation or account login may be sufficient. For high-sensitivity data (health, financial), more rigorous verification is appropriate. Do not use excessive verification requirements as a tool to deter DSR requests — supervisory authorities treat disproportionate verification as an obstacle to exercise of rights.

GDPR Article 12(6); EDPB Guidelines on the right of access §38-44
3

Acknowledge all DSR requests promptly and provide a substantive response within one month

Critical Ongoing (per request)

Article 12(3) requires a response 'without undue delay and in any event within one month' of receipt. Send an acknowledgment within 3-5 business days confirming receipt. The one-month period begins from the date of receipt, not the date of verification. If you cannot respond within one month due to complexity or volume, notify the individual within the original one-month period and extend by up to two additional months.

GDPR Article 12(3)(4)(6); EDPB Guidelines on the right of access §51-58
4

Respond to Subject Access Requests (SARs) with all required information under Article 15

Critical 4-8 hours per request

An Article 15 SAR response must include: confirmation of whether personal data is processed, copies of all personal data, the purposes of processing, the categories of data, the recipients or categories of recipients, the retention period, the right to rectification/erasure/restriction/objection, the right to lodge a complaint with the supervisory authority, source of data if not collected from the individual, and any automated decision-making logic including profiling.

GDPR Article 15(1)(2)(3); EDPB Guidelines on the right of access
5

Provide SAR responses free of charge and in a portable electronic format

Critical Half day (format design)

The first copy of personal data must be provided free of charge. Article 15(3) requires that if the request is made electronically, the information must be provided in a commonly used electronic format, unless the individual requests otherwise. PDF is acceptable; proprietary formats requiring specific software are not. For subsequent copies requested by the same individual, a reasonable administrative fee may be charged (but must be disclosed upfront).

GDPR Article 12(5); Article 15(3); EDPB Guidelines on the right of access §59-65
6

Implement a process for handling rectification requests under Article 16

Critical Ongoing (per request)

When an individual requests correction of inaccurate personal data, you must correct it without undue delay. If you cannot immediately verify accuracy, you may restrict processing while you investigate. Inform the individual of the outcome of rectification or of any inability to rectify with a clear reason. Propagate corrections to all processors who received the inaccurate data (Article 19 notification obligation).

GDPR Article 16; Article 19 (notification to recipients); EDPB Guidelines on rectification
7

Build an erasure (right to be forgotten) process that covers all systems including backups

Critical 3-5 days (process build)

Article 17 erasure applies when: consent is withdrawn and no other lawful basis exists, data is no longer necessary for the purpose collected, the individual objects and there is no overriding legitimate ground, data was unlawfully processed, or erasure is required by law. Erasure must extend to all systems: CRM, email platforms, analytics, backups, and third-party processors. Document your backup erasure schedule — supervisory authorities accept that backup deletion can be deferred to the next scheduled backup cycle if you suppress the data in live systems immediately.

GDPR Article 17(1)(2)(3); Article 19; EDPB Guidelines on erasure
8

Implement restriction of processing functionality under Article 18

High 2-3 days (technical)

Restriction must be technically implemented so that restricted data is not used for processing while the restriction is in place — it may only be stored. Flag restricted records in all systems. Restricted processing may continue only with the individual's consent, for legal claims, to protect others' rights, or for public interest. Notify the individual before lifting a restriction.

GDPR Article 18(1)(2)(3); Article 19
9

Implement data portability for data processed on the basis of consent or contract

High 3-5 days (technical)

Article 20 portability applies only to data processed by automated means on the basis of consent (Article 6(1)(a)) or contract (Article 6(1)(b)). The data must be provided in a structured, commonly used, machine-readable format (CSV or JSON are standard). Where technically feasible and requested, data must be transmitted directly to another controller. Portability does not include derived data or inferred data — only data 'provided by the data subject.'

GDPR Article 20(1)(2)(3)(4); EDPB Guidelines on the right to data portability
10

Process objections to direct marketing immediately and without balancing test

Critical Ongoing (per request)

Article 21(2) provides an absolute right to object to processing for direct marketing. This right cannot be weighed against your legitimate interests — you must stop processing for marketing purposes immediately upon receipt of an objection. Update suppression lists across all marketing systems. The right to object to other processing under Article 21(1) (based on legitimate interests) requires a balancing assessment.

GDPR Article 21(1)(2)(3); Recital 70
11

Document all DSR decisions including bases for any refusals or exemptions applied

High Ongoing

Article 12(4) requires that where you do not act on a request, you must notify the individual within one month with the reasons and their right to complain to the supervisory authority or seek a judicial remedy. Document every DSR request in a register: date received, type of right, identity verified, outcome, date responded, exemption applied (if any). This register is essential for demonstrating compliance under Article 5(2) accountability.

GDPR Article 12(3)(4)(5); Article 5(2) (accountability)
12

Implement Article 22 safeguards for automated decision-making and profiling

High 3-5 days

Article 22 restricts solely automated decisions that produce legal or similarly significant effects. Such decisions require: explicit consent, contract necessity, or legal authorisation — and the individual must have the right to human review, express their point of view, and contest the decision. If you use automated credit scoring, automated hiring decisions, risk profiling, or ad personalisation that affects significant interests, document the logic, significance, and envisaged consequences under Article 15(1)(h).

GDPR Article 22(1)(2)(3)(4); EDPB Guidelines 01/2022 on automated decision-making
13

Notify all recipients of personal data when rectification, erasure, or restriction has occurred (Article 19)

High Ongoing

When you rectify, erase, or restrict processing of personal data, you must notify each recipient to whom the data was disclosed under Article 19 — unless notification is impossible or involves disproportionate effort, in which case document the reason. 'Recipients' include processors and any third parties who received the data. Maintain a record of disclosures sufficient to identify who must be notified for each data category.

GDPR Article 19; Article 30(1)(d) (recipient records in ROPA)

See How Your Data Subject Rights (DSR) Scores on GDPR

Run a free gap analysis to find out which items you have covered and where the risks are.

Gap Analyzer →   Training Tracker →

Common Mistakes That Trigger Enforcement

Refusing SAR requests because the requester cannot use a specific form or process
GDPR Article 12(2) requires that controllers facilitate the exercise of rights. Requiring a specific form, requiring an account login, or refusing requests made by phone or letter without documented justification is an infringement of Article 12. Supervisory authorities have issued enforcement notices for this practice even without a fine.
Applying the 'manifestly unfounded or excessive' exception based on volume of requests rather than genuinely assessing each request
The Article 12(5) exception for manifestly unfounded or excessive requests is narrow and must be assessed per request. Blanket policies limiting DSR responses to one per year per individual, or charging fees for all requests beyond the first, without individual assessment are contrary to GDPR and have been challenged by supervisory authorities.
Providing only the data held in the CRM and ignoring emails, logs, backups, and third-party processors
A SAR response must cover personal data held in all systems, including email archives, server logs, third-party analytics, and processed data at vendors. The ICO has issued enforcement notices where SAR responses omitted email correspondence containing personal data. A partial SAR response is a violation even if incomplete in good faith.
Not updating processors and third-party recipients when erasure requests are actioned
The Article 19 obligation to notify recipients of erasure, rectification, or restriction is commonly overlooked. Where data has been shared with marketing platforms, analytics vendors, or partner organisations and erasure is requested, those recipients must also be notified. Failure means the erasure is technically incomplete.

Frequently Asked Questions

How long do we have to respond to a data subject access request?

Article 12(3) requires a response within one month of receipt of the request. The clock starts from the day the request is received, regardless of verification status (though reasonable time for verification can be built into the process). Where requests are complex or numerous, the period may be extended by a further two months — but the individual must be informed within the original one-month period, with an explanation of the reasons for the extension. Controllers who extend the deadline without adequate justification risk enforcement action.

Can we charge a fee for responding to subject access requests?

Under Article 12(5), the first copy of personal data in response to a SAR must be provided free of charge. A 'reasonable fee based on administrative costs' may be charged for additional copies requested by the same individual. If a request is 'manifestly unfounded or excessive' (a high threshold), the controller may also charge a reasonable fee or refuse to act — but must be able to demonstrate the basis for this assessment. Blanket charges for all SAR responses are not permitted.

What exemptions exist for responding to data subject rights requests?

GDPR provides several exemptions from DSR obligations, most of which must be applied on a per-request basis. Key exemptions: (1) manifestly unfounded or excessive requests (Article 12(5)), (2) data necessary for legal claims, (3) data that would adversely affect others' rights and freedoms (the 'third party data' exception for SARs), (4) processing for scientific/historical research or statistical purposes (Article 89), and (5) member state law exemptions for national security, defence, public security, or criminal investigations. Member states have implemented additional exemptions — the UK GDPR includes an exemption for management planning information. Each exemption must be assessed individually and documented.

✉ Save This Checklist

Enter your email and we'll send you a clean copy — plus updates when requirements change.

We also offer a free personalized gap analysis for your specific situation.

Related Resources

Assess Risk Now →