Managed request operations

A controlled workflow for GDPR data requests.

Map the intake, identity state, systems, evidence trail and decision boundary across access, erasure and other rights without treating every request as the same case.

What is GDPR data request management?

GDPR data request management is the operational process of handling rights requests — access, erasure, rectification, restriction and portability — from intake to recorded response. It covers identity checks, finding the requester’s data across every system, authorised human review and evidence of what was done. The controller stays accountable for each response.

The operating problem

The request is one email. The work is not.

A single person may appear in authentication, product, billing, support and storage systems under different identifiers. The legal deadline does not create an operational owner.

01 / INTAKE

Capture what was actually asked

Record the right being exercised, received time, identity status, scope and response target—without assuming every privacy email is the same request.

02 / SOURCES

Map the evidence path

Link identifiers to the relevant systems, document access methods and make missing or uncertain sources visible.

03 / REVIEW

Keep judgement with people

Put the export, response draft, exception notes and event timeline in front of a qualified person before anything is sent.

One review boundary

What a review-ready pack contains.

The exact output depends on the right, verified scope and available records. Trace does not describe a pack as complete when a source or decision is still outstanding.

01 / CASE

Case summary

Request classification, identity state, scope, dates, customer instructions and open questions.

02 / EVIDENCE

Source inventory

Records located by source, retrieval method, identifier and any known coverage gap.

03 / ACTION

Reviewed next step

Draft response or action plan, exception flags, delivery package and timestamped case events.

Legal clock, operational plan

The controller still owns the response.

Under GDPR Article 12, the controller must provide information on action taken without undue delay and, in general, within one month. A further two months may be available where necessary because of complexity or number of requests, but the individual must be informed within the first month. The European Data Protection Board explains the timing; the legal text is in Article 12 GDPR.

Trace’s proposed operations model is deliberately narrower than the controller’s legal duty: it would assemble agreed case materials for review. It is not a replacement deadline, legal guarantee or promise that a request can be closed on a particular public timeline.

Product truth: Trace is pre-launch. Source coverage, reviewer capacity, security terms and operating milestones must be agreed in writing before any live personal data is handled.

Start with the request you actually receive

A right-of-access request has specific requirements under Article 15 GDPR. Erasure, rectification, restriction, objection and portability are distinct rights with their own conditions. The workflow should preserve that distinction and escalate uncertainty rather than force every case through the same template.

Sources

Official sources used for legal statements.

This is operational guidance based on primary EU materials, not legal advice.

Scope before automation

Questions product teams ask first.

Clear boundaries matter more than broad feature claims when personal data and legal rights are involved.

Which GDPR requests can enter the workflow?
The proposed workflow can record access, erasure, rectification, restriction, objection and portability requests. Each right has different legal conditions and outputs, so the workflow preserves the request type and routes uncertainty to an authorised privacy professional rather than treating every request as a DSAR.
Does Trace complete the legal response for us?
No. Trace is developing operational preparation, not legal decision-making or response approval. An authorised privacy professional retains legal judgement and approval, and the customer remains accountable as controller.
Who decides what is disclosed or deleted?
An authorised human reviewer. Trace is being designed to assemble evidence, document gaps and prepare a draft. It does not autonomously determine exemptions, resolve competing rights or approve a response.
Can we start without permanent connectors?
A future scoped engagement may use controlled exports, time-limited read-only access or a customer-operated query after the data-handling boundary is agreed. No live request data should be sent through this public website.

Founding design partners

Map the workflow before a live request exposes the gaps.

The proposed Readiness Sprint maps up to three systems and rehearses one synthetic request. No live request data should be sent through this website.