GDPR Data Subject Rights Checklist — Articles 15–22 DSR Handling

Last updated: 2026-04-22 — ComplianceStack Editorial Team

17 items
🎯

Generate Your Personalized GDPR Checklist

Tell us about your organization and we'll tailor this 17-item checklist to your situation — highlighting your gaps, marking what you already have, and calculating your readiness score. Free. Instant. Downloadable.

Free · Instant · No account required
Reference Checklist Progress 0 of 17 reviewed

Data subject rights under GDPR Articles 15–22 are among the most operationally demanding compliance obligations. Organisations must respond to access requests within one calendar month (extendable to three for complexity), process erasure requests without undue delay, provide portable data in a machine-readable format, and restrict processing when challenged — all while verifying identity without demanding excessive documentation. Supervisory authorities have issued hundreds of enforcement actions for DSR failures: ignoring requests, requiring disproportionate ID verification, refusing valid erasure requests, and missing response deadlines. This 17-item checklist covers the complete DSR handling lifecycle — intake, verification, processing, response, and documentation — in priority order.

Generate Your Personalized Checklist

Tell us about your data subject rights and we'll filter this checklist to what applies to you — with a readiness score and priority gaps highlighted.

Checked items will be marked ✅ complete in your personalized checklist.

📄 Reference Checklist

Generic — use the generator above for a personalized version
Priority Legend:
● Critical ● High ● Medium ● Ongoing

GDPR Reference Checklist for Data Subject Rights

SEO Reference

Use the generator above for your personalized checklist. The complete reference checklist is below.

GDPR Compliance Checklist for Data Subject Rights

1

Establish a documented DSR intake process covering all submission channels

Critical 2–3 days

Data subjects may submit DSRs through any reasonable channel: email, web form, postal mail, telephone, or in-person. Organisations cannot require use of a specific form — Article 12(2) requires facilitation of rights without obstruction. Designate a central inbox or ticketing system to capture all DSRs regardless of channel. Assign a specific team member or DPO responsibility for initial triage. Log every request with a unique reference number and receipt timestamp on the day it arrives.

GDPR Article 12(2); Recital 59; ICO Guidance on Subject Access Requests
2

Respond to all DSRs within one calendar month of receipt

Critical Process design: 2 days

Article 12(3) sets a mandatory one-month response deadline from the day the request is received — not from when identity is verified. For complex or numerous requests, a one-time extension of two additional months is permitted, but you must notify the data subject within the original one-month window with the reason for delay. The clock does not pause during identity verification unless the identity is genuinely unclear. Missing the deadline without notification is a standalone GDPR violation.

GDPR Article 12(3)(4); Recital 59; EDPB Guidelines 01/2022 on DSR
3

Implement identity verification proportionate to risk — avoid excessive demands

Critical 1 day (standards document)

Article 12(6) permits requesting additional information to confirm identity when there is reasonable doubt, but this must be proportionate and must not demand unnecessary documentation. For low-risk contexts (e.g., a data subject providing their email address to retrieve their own data), confirming via reply to their registered email is generally sufficient. Do not routinely require government-issued ID for straightforward requests — supervisory authorities have sanctioned this practice as an obstruction. Document your identity verification standards in your DSR procedure.

GDPR Article 12(6); EDPB Guidelines 01/2022 §3.2; ICO guidance on ID verification
4

Process Subject Access Requests (Article 15) across all systems comprehensively

Critical Process design: 3–5 days

Article 15 entitles data subjects to a copy of their personal data and processing information. The response must cover all personal data held — including email archives, CCTV footage, physical records, and unstructured files, not just structured databases. It must also include: processing purposes, data categories, recipients, retention periods, and data source if not collected directly. Conduct a full data mapping exercise so SAR searches cover every system. Partial responses are a compliance risk even if unintentional.

GDPR Article 15(1)(2)(3); Recital 63; EDPB Guidelines 01/2022
5

Establish an erasure procedure that cascades to all connected systems (Article 17)

Critical 3–5 days

Article 17 requires erasure without undue delay when: data is no longer necessary, consent is withdrawn with no other lawful basis, the data subject objects with no overriding grounds, data was processed unlawfully, or law requires erasure. Erasure must cascade to processors and third parties who received the data (Article 17(2)). Map all downstream recipients. Log erasure actions. Apply exemptions correctly — do not refuse valid requests by citing exemptions that do not apply on the specific facts.

GDPR Article 17; Article 17(2)(3); Recital 65
6

Build data portability export in structured, machine-readable formats (Article 20)

Critical 3–5 days (technical build)

Article 20 applies to data processed by automated means on the basis of consent or contract. The controller must provide data in a commonly used, machine-readable format (CSV, JSON, XML — not PDF). The data subject may also request direct transfer to another controller where technically feasible. Portability applies to data actively provided by the data subject — not derived or inferred data. Build export functionality from your primary systems and test that exported files are complete, accurate, and genuinely machine-readable.

GDPR Article 20; Recital 68; EDPB Guidelines 05/2017 on data portability
7

Implement processing restriction under Article 18 and enforce it across all systems

Critical 2–3 days

Article 18 requires restriction of processing (data may be stored but not otherwise used) when: accuracy is contested, processing is unlawful but the data subject opposes erasure, the controller no longer needs the data but the data subject needs it for legal claims, or an Article 21 objection is pending. During restriction, data may only be processed with the data subject's consent, for legal claims, protection of another person's rights, or public interest. Implement a technical flag or quarantine mechanism to enforce restriction in all processing systems.

GDPR Article 18; Recital 67; EDPB Guidelines 01/2022
8

Process Article 21 objections within one month and stop processing where required

Critical 1–2 days (process design)

Article 21(1) gives data subjects the right to object to processing based on legitimate interests or public tasks on grounds relating to their particular situation. The controller must cease processing unless it can demonstrate compelling legitimate grounds that override the individual's interests. Article 21(2) provides an unconditional right to object to direct marketing — no balancing test applies, and processing must stop immediately. Document your assessment when overriding an Article 21(1) objection. Respond within one month.

GDPR Article 21(1)(2)(3); Recital 69; EDPB Guidelines 01/2022
9

Comply with Article 22 rights on automated decision-making and profiling

Critical 3–5 days

Article 22 prohibits solely automated decisions (including profiling) that produce legal or similarly significant effects unless: the decision is necessary for a contract, authorised by law, or based on explicit consent. Where such processing occurs, data subjects must be able to obtain human review, express their point of view, and contest the decision. Document which automated processes fall under Article 22. Implement a human review workflow. Disclose automated processing clearly in your Privacy Notice.

GDPR Article 22; Recital 71; EDPB Guidelines 03/2017 on automated decision-making
10

Provide DSR responses free of charge in all but exceptional circumstances

High Policy: half day

Article 12(5) requires DSR responses to be provided free of charge. A reasonable fee may only be charged for manifestly unfounded or excessive requests — and even then, the controller may alternatively refuse the request. "Excessive" relates to the data subject's conduct (e.g., repetitive identical requests), not to processing burden. Document and retain evidence before applying the fee or manifestly unfounded exception. Many supervisory authorities require strong evidence and are sceptical of this defence.

GDPR Article 12(5); EDPB Guidelines 01/2022 §2.4
11

Respond in plain, intelligible language appropriate to the data subject

High 1 day (template creation)

Article 12(1) requires information to be provided in a concise, transparent, intelligible, and easily accessible form, using clear and plain language — particularly where the response is addressed to a child. Avoid legal jargon in SAR response letters. Use headings and summaries where the data provided is extensive. For children, use age-appropriate language. Where the data subject's first language is known, providing at least a summary in that language is best practice.

GDPR Article 12(1); Recital 58; Article 8 (children)
12

Cascade erasure and restriction requests to all processors and downstream recipients

High 2–3 days

Article 17(2) requires controllers to inform third parties who have received the erased data, so they can also erase links to, copies of, or replications of that data where technically feasible. This includes cloud processors, analytics providers, advertising platforms, data resellers, and backup systems. Maintain a current data flow map listing all downstream recipients for each data category. Include erasure cascade obligations in your Data Processing Agreements.

GDPR Article 17(2); Article 19; Article 28 (DPA obligations)
13

Maintain a DSR register logging every request, outcome, and timeline

High 1–2 days

Create and maintain a register of all DSRs received: date received, type of request, data subject identity (pseudonymised where possible), date of response, outcome (fulfilled, refused, extended), basis for any refusal, and exemptions applied. This register is essential evidence for supervisory authority investigations and demonstrates accountability under Article 5(2). Review periodically to identify patterns, such as recurring erasure requests that may indicate a systemic data retention issue.

GDPR Article 5(2) (accountability); Article 24; Article 30
14

Train all staff who may receive DSRs to identify and escalate immediately

High 1 day per training cycle

DSRs do not need to be labelled as such or cite GDPR to be valid. A customer email saying "please delete all my data" is an erasure request. A social media message asking "what information do you have about me" is a SAR. Train customer service, sales, legal, HR, and IT staff to recognise DSR language and escalate immediately. A delay caused by an unrecognised request still counts from the date of receipt. Document training attendance annually.

GDPR Article 12(2); Recital 59; Article 29 (staff processing under controller authority)
15

Apply exemptions correctly — document each refusal with factual justification

High Legal review: 1–2 days

GDPR Article 17(3) and national implementations provide narrow exemptions to the right of erasure (legal claims, freedom of expression, scientific research, public health). These must be applicable on the specific facts. Do not use legal claims exemptions as a blanket refusal for any litigious-sounding request. Document the specific exemption, its legal basis, and the factual justification for each refusal. Supervisory authorities have penalised blanket reliance on exemptions without factual analysis.

GDPR Article 17(3); Article 23 (national restrictions); Recital 65
16

Process rectification requests (Article 16) and notify downstream recipients

Medium Process design: 1 day

Article 16 entitles data subjects to rectification of inaccurate data without undue delay. Upon receiving a rectification request, verify the accuracy claim, correct data in all systems, and notify all recipients of the original data under Article 19 (except where disproportionate or impossible). Confirm rectification to the data subject. Where accuracy is genuinely disputed, implement a restriction flag while the dispute is assessed.

GDPR Article 16; Article 19; Recital 65
17

Implement a separate DSR procedure for employee and job applicant data

Medium 2–3 days

GDPR applies to HR data in full — employees, job applicants, contractors, and former staff all have the same rights as customers. SARs from employees may be extensive (email correspondence, performance records, CCTV, payroll data). Develop a separate HR DSR procedure that coordinates with legal counsel, given the potential for employment disputes. Pay particular attention to third-party data included in employee records — it may need to be redacted before disclosure.

GDPR Article 15 (SAR); Article 88 (employment context); WP29 Opinion 2/2017 on employee monitoring

See How Your Data Subject Right Scores on GDPR

Run a free gap analysis to find out which items you have covered and where the risks are.

Gap Analyzer →   Training Tracker →

Common Mistakes That Trigger Enforcement

Pausing the response clock while waiting for identity verification documents
Article 12(3) sets the response deadline from the date of receipt of the request — not from when identity is confirmed. Treating the waiting period for ID documents as a pause is not permitted. Only where identity is genuinely unclear can the controller request clarification, and only that clarification wait counts. Missing the one-month deadline triggers a standalone GDPR violation exposing the controller to fines and enforcement action.
Providing incomplete SAR responses by only searching the primary CRM or database
Article 15 entitles data subjects to a copy of ALL personal data held — not just structured database records. Supervisory authorities have penalised controllers for failing to search email archives, backup systems, CCTV footage, unstructured files, and legacy systems. The test is thoroughness: would a reasonable search have found this data? A court or supervisory authority will assess the search methodology, not just the result.
Refusing erasure requests by citing the legal claims exemption without factual basis
The Article 17(3)(e) legal claims exemption applies where data is necessary for the establishment, exercise, or defence of a specific legal claim — not as a general precaution against potential future litigation. Using it as a blanket refusal has been explicitly criticised by supervisory authorities. Each application of an exemption must be documented with the specific claim and its relevance to the data requested for erasure.
Requiring government-issued photo ID for routine access requests
Article 12(6) permits identity verification only where there is reasonable doubt about identity, and verification must be proportionate. Routinely requiring government-issued ID for email-based access requests — particularly from existing customers — has been sanctioned by the ICO and Irish DPC as an obstruction to data subject rights, constituting a violation of Article 12(2).

Frequently Asked Questions

How do we handle a SAR that would reveal third-party personal data?

Article 15 entitles a data subject to their own data, but this right must be balanced against the rights of third parties under Article 15(4). Where disclosing the requested data would reveal personal data about another identifiable individual, the controller should consider whether it is reasonable to disclose without that third party's consent. In practice, this often means redacting the third party's identifying information while still providing the substantive data about the requester. The test is not whether the third party objects but whether disclosure is proportionate and fair. UK courts have developed a proportionality test: disclose what can reasonably be disclosed without unfairly prejudicing third parties.

Can we charge a fee for data subject access requests?

No, in virtually all cases. Article 12(5) mandates that DSR responses be provided free of charge. The only exceptions are manifestly unfounded requests and requests excessive in nature — both are high thresholds. "Burdensome" or "time-consuming" is not the same as "excessive." Where a fee is charged or a request is refused on these grounds, the controller bears the burden of demonstrating the basis. Supervisory authorities are sceptical of these defences and have overturned fee charges in numerous cases. When in doubt, respond for free.

What are the penalties for failing to respond to data subject requests?

Failure to comply with data subject rights under Articles 12–22 is subject to fines of up to €20 million or 4% of global annual turnover (Article 83(5)). Supervisory authorities have issued significant fines for DSR failures: Clearview AI received fines from multiple EU authorities totalling over €50M partly for failing to respond to access and erasure requests; TikTok received a €345M fine from the Irish DPC for children's rights violations including inadequate DSR handling. Beyond fines, data subjects may seek compensation under Article 82 for material or non-material damage caused by DSR non-compliance.

✉ Save This Checklist

Enter your email and we'll send you a clean copy — plus updates when requirements change.

We also offer a free personalized gap analysis for your specific situation.

Related Resources

Assess Risk Now →