Certix

Category

Privacy & Rights

Guides on privacy, ARCO-POL rights, identity fraud and how to manage data subject requests under the GDPR.

The GDPR grants every individual a set of rights over their personal data that organisations are legally required to guarantee and fulfil. These are the ARCO-POL rights: access, rectification, erasure/cancellation, objection, portability, restriction of processing and the right not to be subject to solely automated decisions.

These rights are not just a legal requirement: they are the foundation of the trust relationship between an organisation and the individuals whose data it processes. Organisations that lack clear procedures for handling requests within the legal one-month deadline are exposed to complaints to the AEPD and direct sanctions.

In this section we also address identity fraud and the fraudulent use of personal data, a growing problem that affects both individuals and the organisations responsible for protecting that data.

Articles on Privacy & Rights

Articles in this category coming soon.

Frequently asked questions about privacy & rights

What rights does an individual have over their personal data?

The rights recognised by the GDPR are: access (knowing what data is held and how it is used), rectification (correcting inaccurate data), erasure or "right to be forgotten" (deleting data when no longer necessary), objection (refusing certain uses), portability (receiving data in a reusable format), restriction of processing and the right not to be subject to decisions based solely on automated processing with significant effects.

Within what deadline must a business respond to a rights request?

The general deadline is one month from receipt of the request. This may be extended by a further two months if the complexity or number of requests warrants it, but the data subject must be notified within the first month. If the organisation fails to respond within the deadline, the data subject may complain directly to the AEPD.

Can a business charge for handling an access request?

As a general rule, no. Handling requests is free of charge. A reasonable fee may only be charged in cases of manifestly unfounded, excessive or repetitive requests. Charging for a first legitimate request is a GDPR infringement.

Do you need a rights management protocol?

At Certix you will be attended by a data protection expert, with no sales teams involved.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →