Skip to Content

The rights of individuals (RGPD)

The RGPD gives individuals back control over their data by granting them a series of rights. Knowing how to recognize them and respond within the required deadlines is an obligation, and a powerful marker of trust for your customers and employees.

BCIT Formation logo
BCIT Formation is rated Excellent
4,7 · Trustpilot
🎓 +1000 learners trained

Rights at the heart of the RGPD

Any person whose data you process may exercise their rights with you. You must then respond within one month (extendable by two months for complex requests), free of charge in most cases, and after verifying the applicant's identity. Failure to respond exposes you to a complaint to the CNIL.

Organizing the handling of these requests is an essential part of a RGPD compliance approach, generally led by the DPO and supported by the processing records.

The main rights

Access & information

Know whether data concerning them is being processed, what data, why, and obtain a copy of it.

Rectification

Have inaccurate data corrected or incomplete data completed.

Erasure (“right to be forgotten”)

Obtain the deletion of their data in certain cases (data no longer necessary, consent withdrawn…).

Restriction

Request the temporary “freezing” of processing, for example while verifying the accuracy of the data.

Objection

Object to processing, particularly direct marketing, at any time and without justification in that case.

Portability

Retrieve their data in a reusable format in order to transmit it to another organization.

What about automated decision-making?

The RGPD also governs fully automated decisions producing significant effects (granting credit, screening applications…): the person has the right not to be subject to them without human intervention, to be informed of the underlying logic, and to challenge the decision. An increasingly prominent issue with the rise of AI, directly linked to theAI Act.

Respond properly, without improvising

Responding to a rights request requires a process defined in advance: an identified intake channel, proportionate identity verification, the ability to retrieve all of a person's data (hence the importance of the records), and deadline tracking. Improvising on a case-by-case basis risks missed deadlines and complaints. A clear, tested operating procedure known by the teams is preferable.

Organize rights management, step by step

1

Open a dedicated channel

Provide a simple, clearly identified way to exercise rights (address, form…).

2

Verify identity

Ensure the applicant's identity, in a proportionate manner, before any communication of data.

3

Retrieve the data

Locate all of the person's data using the records and the processing map.

4

Respond within the deadline

Handle the request within one month, giving reasons for any refusal and informing the person of the right to refer the matter to the CNIL.

5

Track requests

Keep a record of requests and the responses provided, as part of accountability.

6

Train the teams

Raise awareness among employees in contact with the public so that they know how to recognize and route a request.

Why get support from BCIT?

Ready-to-use procedures

We build your response templates and deadline tracking based on your actual request volume, not a generic kit: channel, templates, and tooling match your organization.

DPO support

Our outsourced DPO handles or supervises sensitive requests.

Aware teams

We train your first-contact teams (reception, support, HR) using practical cases, so they can identify a rights request in a few seconds and know how to route it without waiting for validation.

Make rights a reflex, not an emergency 🚀

Let's take 15 minutes to structure the management of individual rights in your organization and avoid rushed responses.