Data protection
Rights procedure: what to do when someone asks to see or delete their data
General information about the law. It’s no substitute for a lawyer’s advice or a look at your specific case.
Direct answer: anyone can ask you to see, correct or delete the data you hold about them, among other rights. The RGPD (arts. 15 to 22) requires you to deal with those requests and, as a general rule, to reply within one month. Having a written procedure for how they are received and answered stops a request going unanswered and turning into a complaint to the AEPD. Tranquilia sets up that procedure for you, along with the reply templates.
Contents
- What rights can a person exercise?
- How long do you have to reply?
- Why do you need a written procedure?
- What risk do you run if you don't reply?
- How Tranquilia solves it
- Frequently asked questions
- Official sources
What rights can a person exercise?
The RGPD recognises several rights, sometimes summed up as "ARSOPL rights":
- Access (art. 15): knowing what data of theirs you hold and getting a copy.
- Rectification (art. 16): correcting data that is wrong.
- Erasure (art. 17), the "right to be forgotten": asking you to delete data when it is no longer needed.
- Objection (art. 21): asking you to stop processing it, for advertising for example.
- Restriction (art. 18): "freezing" the processing while a disagreement is being settled.
- Portability (art. 20): taking their data to another provider.
They do not all apply all the time: there are exceptions (for example, you cannot delete an invoice the law requires you to keep). But you do have to reply to every request, even if only to explain why it does not apply.
How long do you have to reply?
The general rule in art. 12 RGPD is one month from when you receive the request. You can extend it by two more months if the case is complex, but you have to tell the person within the first month, explaining why.
Replying "free of charge" is the norm: only in clearly excessive or repetitive cases can you charge or refuse, and you have to justify it.
Why do you need a written procedure?
Because requests do not arrive through a single, orderly channel: they come by email, by WhatsApp, by phone or in person, and often the person who receives them first is not the one who knows what to do with them. A written procedure answers three questions in advance:
- How you identify the person asking (so as not to hand someone's data to a third party).
- Who is responsible for replying, and within what deadline.
- What you reply for each type of right, with a template.
What risk do you run if you don't reply?
Not dealing with a right is one of the most frequent causes of complaints to the AEPD (Agencia Española de Protección de Datos, Spain's data protection authority): the person gets tired of being ignored and turns to it. The RGPD sets the maximum penalties at two levels: up to 10 million euros or 2 % of turnover, and up to 20 million or 4 %, depending on the infringement (art. 83 RGPD); the higher figure applies.
For an SME, what is expensive is usually not the fine but the loss of control: a request that gets lost in an inbox and ends up as a complaint when replying to it in time would have been enough.
How Tranquilia solves it
Tranquilia sets up the rights-handling procedure for you and the reply templates for each one (access, erasure, objection...), with the deadlines already marked. That way, when the first request arrives, you know exactly what to do instead of improvising.
Frequently asked questions
Do I have to reply even if the request reaches me by WhatsApp?
Yes. The law does not require any particular form: if someone asks you for their data through whatever channel, the request is valid and the deadline starts to run. That is why it is worth having a procedure that covers every channel.
Can I ask for the DNI (Spain's national identity card) to identify the person making the request?
You can ask for what is reasonable to make sure they are who they say they are, without going too far. The point is not to hand one person's data to another by mistake, not to put up obstacles to discourage the request.
What if they ask me to delete data the law requires me to keep?
You explain it to them. There is data you cannot delete while a legal obligation requires you to keep it (invoices, for example). In that case you refuse the erasure with reasons, but you still reply within the deadline.
Official sources
- Reglamento (UE) 2016/679 (RGPD), articles 12 to 22 (and art. 83, penalties) — text at EUR-Lex.
- Agencia Española de Protección de Datos (AEPD).
- BOE — Ley Orgánica 3/2018 (LOPDGDD), articles 12 to 18.
General information about the rules. It does not replace a lawyer's advice or an analysis of your specific case. If you have any doubts, check with your gestoría (a firm that handles other businesses' administrative paperwork) or with a legal professional.
Review: Translation of the Spanish original, which prevails in case of divergence.
Get your clients GDPR-compliant in 15 minutes.
No card, no sales calls. Two companies free, for as long as you like.