Ailance Alt TM Logo

Request for information: GDPR data subject rights & right to information

Request for information

GDPR data subject rights & right to information

In the experience of a data protection officer, the request for information under Art. 15 GDPR the most frequently used data subject right under the General Data Protection Regulation, alongside the right to Deletion (Art. 17 GDPR) or the right to object to Advertising (Art. 21 para. 2, 3 GDPR).

The Right to information has the advantage for the applicant/affected party that they can obtain almost all information on the Processing personal data that a company has on this data subject. The request for information creates the following conditions for the data subject with regard to data processing Transparencywhich the Data protection after the GDPR would like to achieve.

 However, this can result in considerable organizational difficulties for companies. The first hurdle is the amount and variety of information that needs to be provided. The GDPR prescribes exactly what information the affected person must be given access to "their" data:

  • the purposes of the Processing of the personal data;
  • the categories of data processed (e.g. name, date of birth, hobbies, etc.);
  • Recipients or categories of recipients to whom the personal data has been or will be disclosed, particularly if the recipients are located outside the EU;
  • if possible, the planned period for which the personal data will be stored, or, if this is not possible, the criteria used to determine the storage period;
  • the existence of further Rights of data subjectsnamely the right to Correction or Deletionthe right to restriction of Processing and the right to object;
  • the right to file a complaint with the competent Regulatory Authority to be able to file a complaint;
  • if the personal data was not collected from the data subject himself or herself, all available information regarding the origin of the data;
  • the existence of automated decision-making, including Profiling and, in these cases, meaningful information about the logic involved in the processing. Profiling and the scope and intended effects of this measure for the affected Person.

It is this combination of legal requirements and time pressure that can make information requests a significant risk for companies.

If information is not provided in a timely manner or is incomplete, a dissatisfied individual may quickly decide to file a complaint with the Regulatory Authority to complain. In the worst case, this can lead to a Fine for the company.

For these reasons, a responsible company must prepare in advance for a request for information.

As a first step, a central point of contact should be established. Requests for information that are received by the wrong department and circulate within the company for days can significantly shorten the remaining time within the one-month deadline. The data protection officer is, of course, the ideal person for this role. If no Data Protection Officer has been appointed, another person must assume this role. It is also important, of course, to inform all colleagues about this point of contact. This central point of contact is also responsible for verifying the identity of the requester. If it cannot be verified that the requester is who they claim to be, the company may request additional information. Only once it has been confirmed that the person is who they claim to be should the process continue.

The next step is to establish a process that allows all necessary information to be gathered as quickly as possible. This can be done with the help of employees who know where to find the necessary information, such as department heads or IT staff. Of course, this approach requires the involvement of employees. Depending on the complexity of the infrastructure from which this information must be extracted, several colleagues may spend weeks compiling the necessary information.

Request for Information Regarding 2B Advice PrIME

 

Another option is a software-supported solution. 2B Advice PrIME can be used to answer a request for information promptly and process it within the company. In 2B Advice PrIME, requests can be received centrally via a ticket system and created as tickets. For every type of data protection request (access, erasure, rectification, Revocation etc.), you can define and store your own workflows. In this way, company processes can be mapped in 2B Advice PrIME.

A workflow assigns tasks to individual employees within the company, which are then processed by those employees. The company always maintains an overview of the status of the information request and can intervene at any time if the process gets stuck at any point.

This software-supported processing means that all steps of the request for information can always be documented. In one measure, it is possible to set an internal deadline by which the information must be available. The central point of contact can use deadlines to ensure that the request for information is processed within the statutory period. 2B Advice PrIME also has extensive reporting functions that allow data protection requests to be monitored. The ability to fully document this process enables you to prove that you have done everything the law requires of you in the event of a dispute with the data subject. This also enables you to comply with the accountability requirement imposed on companies by Art. 5 para. 2 GDPR. GDPR in data protection matters.

The features in 2B Advice PrIME provide employees with optimal support in processing inquiries. This ensures that information requests are always centrally managed, thereby minimizing the risk of penalties.

Conclusion of the request for information

 

The Affected parties With his or her right of access, the data subject is also entitled to a copy of this information. However, this must not be understood in a way that allows the data subject to "access" all of their personal data. For example, no data may be disclosed that concerns persons other than the applicant or internal business secrets. For this reason too, a thorough process must be in place that also prevents unauthorized data from flowing to the applicant.

Once the process has been completed and all the necessary information has been compiled, the applicant should, in the opinion of the Regulatory Authority In North Rhine-Westphalia, these documents must be delivered by mail only. Sending them by email is considered too insecure. However, if you have implemented measures that ensure the secure electronic transfer of the data, this method may also be acceptable.

Picture of Marcus Belke

Marcus Belke

Marcus Belke is the CEO of 2B Advice GmbH. He drives innovation in data protection compliance and risk management and is responsible for the further development of Ailance, the next-generation compliance platform.

Share this post:

Request for information: GDPR data subject rights & right to information