Skip to content

Right requests

A right request is a data subject exercising one of their rights: asking for a copy of their data, asking you to correct it, asking you to delete it. GDPR gives you one month to answer, so the register exists to prove two things — that the request was handled, and that it was handled in time.

Privacy → Right Requests in the sidebar. Trace a request opens the form.

FieldNotes
Ref IDYour internal case reference
Name / DescriptionWhat was asked. Keep the subject’s identity out of the free text unless your process requires it
DomainScopes permissions — normally the DPO’s domain
OwnerThe actors handling the case
Requested onRequired — the date the request landed. This is the date the clock starts from
Due dateThe deadline you are working to
Request typeSee below
StatusNew, In Progress, On hold or Done
ProcessingsThe processing activities the request touches
ObservationWorking notes, decisions taken, what was sent back
  • Access / Extract — a copy of the data held.
  • Rectification — correction of inaccurate data.
  • Deletion / Erasure — the right to be forgotten.
  • Portability — a machine-readable export.
  • Restriction — freeze processing while a dispute is resolved.
  • Objection — stop a processing based on legitimate interests or direct marketing.
  • Other — anything that does not fit the list.

The list shows Ref ID, Name, Request type, Status, Owner, Requested on, Due date and Domain, newest request first, and filters by domain, request type, status and processing. Filtering on the statuses that are not Done gives you the live queue; the Open Requests counter on the privacy dashboard is the same number.

Attaching the processings a request touches is what makes the answer tractable. Once a request names an activity, the register tells you which personal-data categories it involves, where that data is stored, and which recipients and contractors also hold it — so an erasure request turns into a concrete list of places to go and delete from. The link is visible from both ends: a processing’s detail page shows the requests that named it, read-only.