Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
GDPR DSR Compliance Checklist: Audit Your Access ChannelsLaws and Regulations
4 min readFor DPOs (Data Protection Officers)

GDPR DSR Compliance Checklist: Audit Your Access Channels

A 100,000 EUR fine against Securitas Direct by the Spanish DPA highlights a common oversight: offering free channels for data subject rights isn't enough if you're also directing people to paid options. The violation involved video surveillance notices that instructed individuals to call a chargeable 902 number to exercise access and objection rights. Even though Securitas Direct had free alternatives on their website, directing individuals to a paid channel violated Article 12(2) of the GDPR.

This checklist will help you ensure your data subject rights infrastructure truly facilitates rights exercise without discouraging it.

Prerequisites

Before starting, gather:

  • Current templates for privacy notices, data collection forms, and surveillance signage
  • Documentation of all channels for submitting requests (email addresses, web forms, postal addresses, phone numbers)
  • Call center scripts and automated response templates
  • Your CMP configuration and consent notice text
  • Records of how requests are routed internally

Ensure access to someone who can verify telecom charges if you list phone numbers and someone who can test web form submissions end-to-end.

Checklist Items

1. Ensure all contact methods are genuinely free

Audit every privacy notice, surveillance sign, and data collection form for contact details. Verify that phone numbers are toll-free or local-rate, not premium-rate. Confirm email addresses accept standard SMTP mail without requiring proprietary clients or paid services.

Good practice: All phone numbers in privacy materials are standard geographic numbers or explicitly toll-free. Email addresses end in your domain and accept mail from any provider. Web forms require no account creation or payment.

2. Avoid privileging one channel over others

Review how you direct data subjects to exercise rights. The Securitas Direct case involved notices that specifically referred individuals to the 902 number, even though free options existed. If your privacy notice says "to exercise your rights, call..." but the call costs money, you're replicating their compliance failure.

Good practice: List all available channels with equal prominence. If one channel has limitations (e.g., "phone support available 9-5 weekdays"), state that clearly without making it the primary instruction.

3. Simplify web form access

Don't gate data subject request forms behind account login. If someone doesn't have an account or can't remember credentials, you've added friction that Article 12(2) prohibits. Verify identity after receiving the request.

Good practice: Your DSR web form is publicly accessible. It collects the minimum information needed to process the request (name, contact method, nature of request) and explains what additional verification may be required.

4. Monitor postal addresses and ensure timely routing

Listing a postal address satisfies the "provide a channel" requirement, but if mail sits unopened, you're not facilitating rights exercise. Test your postal channel by sending a mock request and timing how long it takes to reach your DPO or privacy team.

Good practice: Postal requests reach the responsible team within 3 business days of delivery. Document the internal routing so facilities staff know where to forward privacy-related mail.

5. Maintain consistent contact details across all touchpoints

Check your website footer, mobile app settings, email signature blocks, printed contracts, and physical signage. Inconsistent contact information can mislead data subjects.

Good practice: The same DSR email address and web form URL appear in every privacy notice, regardless of format or location. If you must list different regional contacts, ensure the routing logic is clear and documented.

6. Ensure automated responses encourage follow-through

If your DSR email triggers an auto-reply, review that message. Does it acknowledge receipt clearly? Does it set realistic timelines? Does it ask for information you should have requested in your privacy notice? Vague or demanding auto-replies can discourage rights exercise.

Good practice: Auto-replies confirm receipt, reference the one-month response timeline under Article 12(3), and explain what happens next without requiring the data subject to provide information you already possess.

7. Ensure third-party processors follow your procedures

If you use service providers who interact directly with data subjects (call centers, customer support platforms, surveillance system operators), verify they're directing rights requests to your documented channels, not improvising their own procedures or charging for support.

Good practice: Processor contracts specify that DSR inquiries must be forwarded to your designated contact within 48 hours. Provide processors with approved language for responding to rights requests they receive directly.

Common Mistakes

Assuming "available somewhere" equals "facilitated": The Spanish DPA rejected Securitas Direct's argument that free channels on the website offset the chargeable phone number in notices. Where you point matters as much as what you offer.

Using identity verification as a gatekeeper: Verify identity proportionate to the risk after receiving a request. Don't require notarized documents or government ID upfront for every request type.

Ignoring the cost of "free" channels: A web form that requires extensive data entry or an email address that bounces automated requests imposes non-monetary costs that hinder rights exercise.

Failing to test from the data subject perspective: Your privacy team knows the right email address. Can a customer who read your privacy notice six months ago figure it out without calling general support?

Next Steps

Run this checklist quarterly or whenever you update privacy notices or change contact information. Assign someone outside the privacy team to test each channel as a data subject would experience it.

Document your findings. If you discover issues, fix them immediately and log the remediation. The Spanish DPA gave Securitas Direct 12 months to replace non-compliant notices, but you don't want to wait for enforcement action to prompt an audit.

Article 12(2) requires you to "facilitate" rights exercise. Your infrastructure should make it easier, not harder, for data subjects to reach you. If any element of your current process would discourage you from submitting a request, it probably discourages others too.

Article 12 GDPR

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like