The rights of individuals (RGPD)
The RGPD gives individuals back control over their data by granting them a series of rights. Knowing how to recognize them and respond within the required deadlines is an obligation, and a powerful marker of trust for your customers and employees.
Rights at the heart of the RGPD
Any person whose data you process may exercise their rights with you. You must then respond within one month (extendable by two months for complex requests), free of charge in most cases, and after verifying the applicant's identity. Failure to respond exposes you to a complaint to the CNIL.
Organizing the handling of these requests is an essential part of a RGPD compliance approach, generally led by the DPO and supported by the processing records.
The main rights
Access & information
Know whether data concerning them is being processed, what data, why, and obtain a copy of it.
Rectification
Have inaccurate data corrected or incomplete data completed.
Erasure (“right to be forgotten”)
Obtain the deletion of their data in certain cases (data no longer necessary, consent withdrawn…).
Restriction
Request the temporary “freezing” of processing, for example while verifying the accuracy of the data.
Objection
Object to processing, particularly direct marketing, at any time and without justification in that case.
Portability
Retrieve their data in a reusable format in order to transmit it to another organization.
What about automated decision-making?
The RGPD also governs fully automated decisions producing significant effects (granting credit, screening applications…): the person has the right not to be subject to them without human intervention, to be informed of the underlying logic, and to challenge the decision. An increasingly prominent issue with the rise of AI, directly linked to theAI Act.
Respond properly, without improvising
Responding to a rights request requires a process defined in advance: an identified intake channel, proportionate identity verification, the ability to retrieve all of a person's data (hence the importance of the records), and deadline tracking. Improvising on a case-by-case basis risks missed deadlines and complaints. A clear, tested operating procedure known by the teams is preferable.
Organize rights management, step by step
Open a dedicated channel
Provide a simple, clearly identified way to exercise rights (address, form…).
Verify identity
Ensure the applicant's identity, in a proportionate manner, before any communication of data.
Retrieve the data
Locate all of the person's data using the records and the processing map.
Respond within the deadline
Handle the request within one month, giving reasons for any refusal and informing the person of the right to refer the matter to the CNIL.
Track requests
Keep a record of requests and the responses provided, as part of accountability.
Train the teams
Raise awareness among employees in contact with the public so that they know how to recognize and route a request.
Why get support from BCIT?
Ready-to-use procedures
We build your response templates and deadline tracking based on your actual request volume, not a generic kit: channel, templates, and tooling match your organization.
DPO support
Our outsourced DPO handles or supervises sensitive requests.
Aware teams
We train your first-contact teams (reception, support, HR) using practical cases, so they can identify a rights request in a few seconds and know how to route it without waiting for validation.
Make rights a reflex, not an emergency 🚀
Let's take 15 minutes to structure the management of individual rights in your organization and avoid rushed responses.
The rights of individuals (RGPD)
The RGPD gives individuals back control over their data by granting them a series of rights. Knowing how to recognize them and respond within the required deadlines is an obligation, and a powerful marker of trust for your customers and employees.
Rights at the heart of the RGPD
Any person whose data you process may exercise their rights with you. You must then respond within one month (extendable by two months for complex requests), free of charge in most cases, and after verifying the applicant's identity. Failure to respond exposes you to a complaint to the CNIL.
Organizing the handling of these requests is an essential part of a RGPD compliance approach, generally led by the DPO and supported by the processing records.
The main rights
Access & information
Know whether data concerning them is being processed, what data, why, and obtain a copy of it.
Rectification
Have inaccurate data corrected or incomplete data completed.
Erasure (“right to be forgotten”)
Obtain the deletion of their data in certain cases (data no longer necessary, consent withdrawn…).
Restriction
Request the temporary “freezing” of processing, for example while verifying the accuracy of the data.
Objection
Object to processing, particularly direct marketing, at any time and without justification in that case.
Portability
Retrieve their data in a reusable format in order to transmit it to another organization.
What about automated decision-making?
The RGPD also governs fully automated decisions producing significant effects (granting credit, screening applications…): the person has the right not to be subject to them without human intervention, to be informed of the underlying logic, and to challenge the decision. An increasingly prominent issue with the rise of AI, directly linked to theAI Act.
Respond properly, without improvising
Responding to a rights request requires a process defined in advance: an identified intake channel, proportionate identity verification, the ability to retrieve all of a person's data (hence the importance of the records), and deadline tracking. Improvising on a case-by-case basis risks missed deadlines and complaints. A clear, tested operating procedure known by the teams is preferable.
Organize rights management, step by step
Open a dedicated channel
Provide a simple, clearly identified way to exercise rights (address, form…).
Verify identity
Ensure the applicant's identity, in a proportionate manner, before any communication of data.
Retrieve the data
Locate all of the person's data using the records and the processing map.
Respond within the deadline
Handle the request within one month, giving reasons for any refusal and informing the person of the right to refer the matter to the CNIL.
Track requests
Keep a record of requests and the responses provided, as part of accountability.
Train the teams
Raise awareness among employees in contact with the public so that they know how to recognize and route a request.
Why get support from BCIT?
Ready-to-use procedures
We build your response templates and deadline tracking based on your actual request volume, not a generic kit: channel, templates, and tooling match your organization.
DPO support
Our outsourced DPO handles or supervises sensitive requests.
Aware teams
We train your first-contact teams (reception, support, HR) using practical cases, so they can identify a rights request in a few seconds and know how to route it without waiting for validation.
Make rights a reflex, not an emergency 🚀
Let's take 15 minutes to structure the management of individual rights in your organization and avoid rushed responses.