Controllers often face challenges when they receive requests from data subjects for information about the processing of their personal data or for the exercise of other rights under the GDPR. Checking databases and archives, preparing a response and providing information require considerable time and human resources. In addition, the short deadlines for responding and the possibility of penalties for incomplete or incorrect performance add further pressure.

What is a request to exercise rights under the GDPR?

The data subject may submit their request in various ways: by e-mail, by telephone, through a website or via the controller's social media profiles. The request may be in free text and need not follow a particular template or contain terms such as “personal data” or “GDPR”. Examples of such requests include:

  • “Please provide me with all the information you hold relating to me.”
  • “I want to know what information you have about me.”
  • “I want to know where you obtained this information about me.”

In order to recognise such requests, staff must undergo training and follow an internal procedure for handling them.

Requirements for the validity of the request

A request to exercise rights under the GDPR must be in writing in order to be valid. If it is sent electronically, it must be signed with an electronic signature. Nevertheless, according to the practice of the Commission for Personal Data Protection, if the controller responds to an invalid request by e-mail, the request is deemed to be recognised as valid.

The requirements as to the content of the request include:

  • The name, Unified Civil Number (ЕГН) and address of the data subject;
  • A description of the request;
  • The preferred form for receiving the information;
  • A signature and the date of submission;
  • An address for correspondence.

If the request is submitted by an authorised representative, a power of attorney is required (without notarial certification). If a parent submits an application for a child's data, the child's birth certificate may be required. Where an application is incomplete, the controller must notify the person of the necessary corrections and may offer a template.

Deadline for responding to the request

The controller is obliged to respond to the request, or to inform the data subject of the action taken, within one month of receiving the request. This period may be extended once by two months where the requests are of great complexity or numerous.

If the initial request is incomplete and subject to correction, the period for responding begins to run from the date on which the irregularities are rectified. It is good practice to note the start and end dates of the period on the request.

Fees for a data subject request

Responding to such requests is free of charge, regardless of the costs and time involved. An exception is made for manifestly unfounded or excessive requests, e.g. frequently repeated ones, in respect of which the controller may charge a fee reflecting the administrative costs.

If the data subject's data change frequently, frequent requests may be justified. The assessment of whether a request is unfounded or excessive is carried out on a case-by-case basis.

If you need advice, the drafting of documents or training in connection with the protection of personal data, contact us on tel.: 0887550706 or by e-mail: [email protected]