Certus
← All insightsDSR Best Practices · 5 min read

The 30-day clock: handling data subject requests without the scramble

On paper, handling a data subject request looks simple: verify identity, locate the data, respond within the statutory window. In practice, the first real request usually reveals that no one owns the process end-to-end, that personal data lives in more systems than anyone remembered, and that legal, IT and the business unit have never actually rehearsed who does what.

The organisations that handle DSRs well share a few traits: a single intake point regardless of which channel the request arrives through, a pre-agreed identity verification standard that doesn't get improvised under pressure, and a tracking system that makes the deadline visible to everyone involved — not just the person who received the request.

Refusal grounds matter just as much as fulfilment. Knowing precisely when and how you can lawfully decline or limit a request — and documenting that decision defensibly — is as important as being able to produce the data when required.

None of this requires exotic technology. It requires a workflow that has been designed once, tested under realistic pressure, and owned by someone whose job it actually is.

Want this applied to your organisation?

Talk to a Certus privacy partner about what this means for your specific risk.