Right requests
A right request is a data subject exercising one of their rights: asking for a copy of their data, asking you to correct it, asking you to delete it. GDPR gives you one month to answer, so the register exists to prove two things — that the request was handled, and that it was handled in time.
Where to find it
Section titled “Where to find it”Privacy → Right Requests in the sidebar. Trace a request opens the form.
The record
Section titled “The record”| Field | Notes |
|---|---|
| Ref ID | Your internal case reference |
| Name / Description | What was asked. Keep the subject’s identity out of the free text unless your process requires it |
| Domain | Scopes permissions — normally the DPO’s domain |
| Owner | The actors handling the case |
| Requested on | Required — the date the request landed. This is the date the clock starts from |
| Due date | The deadline you are working to |
| Request type | See below |
| Status | New, In Progress, On hold or Done |
| Processings | The processing activities the request touches |
| Observation | Working notes, decisions taken, what was sent back |
Request types
Section titled “Request types”- Access / Extract — a copy of the data held.
- Rectification — correction of inaccurate data.
- Deletion / Erasure — the right to be forgotten.
- Portability — a machine-readable export.
- Restriction — freeze processing while a dispute is resolved.
- Objection — stop a processing based on legitimate interests or direct marketing.
- Other — anything that does not fit the list.
Working the queue
Section titled “Working the queue”The list shows Ref ID, Name, Request type, Status, Owner, Requested on, Due date and Domain, newest request first, and filters by domain, request type, status and processing. Filtering on the statuses that are not Done gives you the live queue; the Open Requests counter on the privacy dashboard is the same number.
Linking to processings
Section titled “Linking to processings”Attaching the processings a request touches is what makes the answer tractable. Once a request names an activity, the register tells you which personal-data categories it involves, where that data is stored, and which recipients and contractors also hold it — so an erasure request turns into a concrete list of places to go and delete from. The link is visible from both ends: a processing’s detail page shows the requests that named it, read-only.
Related
Section titled “Related”- Processings (ROPA) — the activities a request applies to.
- Personal data — what has to be extracted, corrected or erased.
- Privacy overview — open-request counts and the breakdown by type.
