Data Subject Requests

viktoriadov
Contact
We help you respond to client requests regarding their personal data.
legal it group

Why Choose Us

Experts in GDPR since 2018

We’ve been systematically building and implementing privacy programs since the early days of the GDPR.
  • A Team of Three FIPs

    Certified professionals with CIPM, CIPT, CIPP/E, and CIPP/US credentials — all holding the prestigious Fellow of Information Privacy (FIP) designation
    sircles
  • Privacy Advocates

    We host regular in-person and online events dedicated to privacy and data protection.
    about_icon2
  • Authors of “GDPR for Divers”

    Our in-house lawyers and privacy managers are proud co-authors of a widely respected practical guide.
    about_icon3
  • Connected with German Partners

    We implement the best European privacy practices through close collaboration with trusted German experts.
    about_icon4
Send a request
decor

The Path to Responding to a Data Subject Request The Path to Responding to a Data Subject Request

  • 01

    Contacts and forms

    We add contact details and request forms for exercising GDPR rights
  • 02

    Request registry

    Each request must be logged and stored
  • 03

    Identification

    We distinguish relevant requests from the general flow of incoming inquiries
  • 04

    Request analysis

    We verify the request, assess it, and locate the relevant data
  • 05

    Response preparation

    We develop strategies and prepare draft responses
  • 06

    Support

    We assist in responding to any follow-up questions from the requester

What’s included? What’s included? What’s included? What’s included? What’s included? What’s included?

red-folder Request
Process
  • Access

    Access request, DSAR, data subject access request
  • Deletion

    Deletion request, right to be forgotten request
  • Rectification

    Rectification of data or data modification
  • Consent withdrawal

    Consent withdrawal or opt-out (often related to marketing)
  • Compensation

    If the data subject provides evidence of a violation
  • Delegated request

    Submitted via automated messaging systems or a representative
  • Missed deadline

    One month to respond — extensions require a formal procedure
  • Incomplete response

    Missing data or partial disregard of the request
  • No violations

    In cases of unfounded or unjustified requests
  • Request spamming

    Aiming to disrupt the company’s normal operations
  • Corporate intelligence

    Requests used to identify vulnerabilities in the company
implementation_icon

The response strategy will depend on the nature of the request and the complexity of data processing in your company

  • Data deletion request

    implementation_icon1
    Data subjects ask to delete all data about them, even if some of it cannot be deleted under the law
  • Request for a copy of data

    implementation_icon2
    Data subjects ask for all data collected about them, even if such data is not in the database
  • Request for information about data

    implementation_icon3
    Data subjects ask for an explanation of the privacy policy or information about the company’s operations
  • Do not sell my data request

    implementation_icon4
    This request is more common in California, but it also appears in the EU
  • Request to disclose third parties

    Data subjects ask to disclose service providers, advertising partners, and SaaS tool vendors

How much does it cost?

€100/hour
Depends on the complexity of the request, the state of your compliance program, and the amount of data your company processes
Send a request
Команда

Team

Key privacy experts

From discovery to a structured compliance dashboard. What’s inside?
  • Катерина Дубас Legal IT Group

    Kateryna Dubas

    Head of Privacy Practice at Legal IT Group
  • Антон Тарасюк Legal IT Group

    Anton Tarasiuk

    Managing partner at Legal IT Group
  • Антон Демчук Legal IT Group

    Anton Demchuk

    Junior IT/Privacy Lawyer at Legal IT Group
  • Дмитро Нефьодов Legal IT Group

    Dmytro Nefodov

    Junior AI/privacy lawyer at Legal IT Group

Certified GDPR / CCPA / CPRA experts

We hold 10+ certifications in the field of privacy

Our expertise is internationally recognized.

CIPT_Dubas.pdf

Nova Post

International logistics company
  • we provide personal data protection services in Ukraine

  • we provide GDPR-compliant personal data protection services

Hyalual

Global developer and manufacturer of solutions for aesthetic medicine
  • we provided support with data privacy compliance

Readdle

Product IT company engaged in application development
  • we worked with the Readdle team on their data flow mapping

  • we helped them to add even more transparency to the relationship between Readdle and their customers

Spark

Fast cross-platform email designed to filter out the noise
  • we are honored to act as DPO for Snovio.io

  • we help with other legal issues

Snov.io

Smart automation of cold sales
  • we are honored to act as DPO for Snovio.io

  • we help them with other legal tasks

Trionika

A company for traffic generation and monetization in Western markets
  • we helped with worldwide trademarks and intellectual property issues

ZONE3000

International IT company providing software development services
  • we have provided many consultations on various legal issues

Englishdom

Online school for learning English
  • we helped with solving GDPR compliance issues

WildCraft

Online animal life simulator
  • we act as a DPO

  • we help with other legal tasks

blog_iconCurrent and practical articles

  • Data protection officer
  • AI compliance officer
  • Data privacy compliance
  • Дія.City
  • Digital Millennium copyright Act
  • Торгова марка в IT
Go to Blog

We write about what we practice

IP, GDPR, contracts and disputes, and the legal aspects of implementing technologies like artificial intelligence or best practices for delivering concrete legal solutions.