Capture what was actually asked
Record the right being exercised, received time, identity status, scope and response target—without assuming every privacy email is the same request.
Managed request operations
Map the intake, identity state, systems, evidence trail and decision boundary across access, erasure and other rights without treating every request as the same case.
What is GDPR data request management?
GDPR data request management is the operational process of handling rights requests — access, erasure, rectification, restriction and portability — from intake to recorded response. It covers identity checks, finding the requester’s data across every system, authorised human review and evidence of what was done. The controller stays accountable for each response.
The operating problem
A single person may appear in authentication, product, billing, support and storage systems under different identifiers. The legal deadline does not create an operational owner.
Record the right being exercised, received time, identity status, scope and response target—without assuming every privacy email is the same request.
Link identifiers to the relevant systems, document access methods and make missing or uncertain sources visible.
Put the export, response draft, exception notes and event timeline in front of a qualified person before anything is sent.
One review boundary
The exact output depends on the right, verified scope and available records. Trace does not describe a pack as complete when a source or decision is still outstanding.
Request classification, identity state, scope, dates, customer instructions and open questions.
Records located by source, retrieval method, identifier and any known coverage gap.
Draft response or action plan, exception flags, delivery package and timestamped case events.
Legal clock, operational plan
Under GDPR Article 12, the controller must provide information on action taken without undue delay and, in general, within one month. A further two months may be available where necessary because of complexity or number of requests, but the individual must be informed within the first month. The European Data Protection Board explains the timing; the legal text is in Article 12 GDPR.
Trace’s proposed operations model is deliberately narrower than the controller’s legal duty: it would assemble agreed case materials for review. It is not a replacement deadline, legal guarantee or promise that a request can be closed on a particular public timeline.
Product truth: Trace is pre-launch. Source coverage, reviewer capacity, security terms and operating milestones must be agreed in writing before any live personal data is handled.
A right-of-access request has specific requirements under Article 15 GDPR. Erasure, rectification, restriction, objection and portability are distinct rights with their own conditions. The workflow should preserve that distinction and escalate uncertainty rather than force every case through the same template.
Sources
This is operational guidance based on primary EU materials, not legal advice.
Scope before automation
Clear boundaries matter more than broad feature claims when personal data and legal rights are involved.
Founding design partners
The proposed Readiness Sprint maps up to three systems and rehearses one synthetic request. No live request data should be sent through this website.