Data subjects have strong rights over their own personal data. KVKK requires a request to be concluded within 30 days at the latest. Meeting this deadline reliably is only possible with a process set up in advance. This guide explains, step by step, how to build an end-to-end request (DSAR) process — from identity verification to refusal grounds.
The Data Subject's Rights (KVKK Art. 11)
- Learn whether their personal data is processed,
- Request information about it if it is,
- Learn the purpose of processing and whether it is used accordingly,
- Know the third parties to whom it is transferred domestically/abroad,
- Request rectification if processed incompletely/incorrectly,
- Request erasure/destruction and that this be notified to parties it was transferred to,
- Object where an automated analysis produces an adverse result,
- Claim compensation for damages arising from unlawful processing.
Why a Process Is Essential
Requests often arrive through different channels (e-mail, registered e-mail, contact form, even social media) and at unpredictable times. Without a process, a request can get lost in an inbox and the 30-day deadline can pass unnoticed. Missing the deadline is itself a sanction and reputational risk.
The End-to-End DSAR Process
| Stage | What to do |
|---|---|
| 2. Logging | Record the request with date/time; the 30-day clock starts |
| 3. Identity verification | Verify the applicant is genuinely the data subject |
| 4. Scoping | Which right, which data does it cover? |
| 5. Data gathering | Compile the data from all relevant systems (CRM, HR, e-mail, logs) |
| 6. Assessment | Will the request be met, refused or partially met? |
| 7. Response | Reply with reasons, clearly and within the deadline |
| 8. Record/archive | Keep the request and response as proof |
Identity Verification: A Critical Step
Giving data to the wrong person is itself a breach. Make verification proportionate to the sensitivity of the requested data: account verification may suffice for a low-risk request, while sensitive data may require additional checks. But do not use this step as a "delay tactic"; asking for excessive documents can itself be treated as a violation.
When Can You Refuse or Limit a Request?
In some cases a request can be refused or limited, for example where it:
- Violates the rights and freedoms of others,
- Is manifestly unfounded or excessively repetitive,
- Concerns data subject to a legal retention obligation,
- Falls within exceptional situations such as crime prevention or investigation.
In every case, give reasons for your decision and remind the data subject of the available remedies, including a complaint to the Board.
Can You Charge a Fee?
As a rule the response is free; but if the operation entails an additional cost (e.g. a CD, a printout), a reasonable fee may be charged within the tariff set by the Board. Do not use the fee as a deterrent.
Example Scenario: Erasure Request vs. Legal Retention
A customer requests erasure of all their data. However, some invoice-related data must be retained for a set period under tax law. The right approach: erase what can be erased, explain — with reasons — the data under a legal retention obligation, and state that it will be deleted once the retention period expires. Both "we deleted everything" and "we can't delete anything" are wrong.
Checklist
- Request channels defined and announced on the website.
- A system that logs the request and tracks the deadline.
- Identity-verification procedure documented and proportionate.
- Data-gathering flow from all relevant systems ready.
- Refusal and partial-refusal grounds and templates prepared.
- Responses given with reasons and on time.
- Request/response archive kept for proof.
- Legal-retention exceptions assessed for erasure requests.
Frequently Asked Questions
How many days is the deadline and when does it start?
It is 30 days at the latest and starts the moment the request reaches you. That is why the intake and logging steps are critical; "when it arrived" must be provable.
Do I have to accept a verbal request?
Requests are expected to be made in writing or through the methods set by the Board. Clarify the channels in advance and announce them on your website.
Can I automate requests?
Yes. Automating intake, deadline tracking, identity verification and data gathering improves both speed and evidentiary strength and reduces human error.
Do I have to grant every request?
No. You can refuse or partially grant on legitimate grounds; but you must give reasons and state the available remedies.
This content is for general information only and does not constitute legal advice. With JUS. you can receive and manage data-subject requests from one place with deadline tracking — request a demo.