CyberTRIZPEDIA

Implement Effective Data Subject Rights Management

Control
GDPR-DSR-001
Regulation
GDPR
Category
operational
Priority
high
Frequency
annually
Type
operational

What this control requires

Establish procedures to receive, authenticate, log, assess and respond to all DSR types within statutory timeframes (1 month standard, 3 months for complex). Cover: access (SARs), rectification, erasure, restriction, portability and objection. Maintain a DSR register. Train frontline staff on rights recognition and referral procedures.

Other GDPR controls