- The document provides guidance to companies on complying with data subject rights under the GDPR, such as the rights to access, rectify, erase, and port personal data.
- It outlines 5 steps companies should take: 1) determine if they are a controller, processor or joint controller; 2) consider if an exception applies when only pseudonymous data is collected; 3) establish a policy for handling requests; 4) provide a way for individuals to submit requests via email or website; 5) take 5 specific actions now to prepare.
- Key issues addressed include how to respond when only pseudonymous data is held, verifying identity of requestors, and determining responsibility between controllers and processors.