Skip to main content
Data Subject Rights Checklist: Audit Your GDPR Access ChannelsData Privacy
5 min readFor Internal Auditors

Data Subject Rights Checklist: Audit Your GDPR Access Channels

When a consumer association filed a complaint against Securitas Direct, the issue wasn't the absence of compliant channels for data subject rights. It was that their signage directed people to a chargeable 902 phone number. The Spanish Data Protection Authority (AEPD) imposed a 100,000 EUR fine for violating Article 12(2) of the General Data Protection Regulation, which requires controllers to facilitate rights exercise free of charge.

The enforcement decision highlights a critical compliance gap: having compliant processes isn't enough if you're directing data subjects toward non-compliant ones. This checklist helps you audit every touchpoint where someone might try to exercise their rights under Articles 15-22 of the General Data Protection Regulation.

Prerequisites

Before starting this audit, gather:

  • All public-facing privacy notices (website, signage, contracts, mobile apps)
  • Complete inventory of contact channels (phone numbers, email addresses, web forms, postal addresses)
  • Telecommunications billing records showing which numbers incur charges
  • Documentation of your current Data Subject Access Request intake process
  • Records of how rights requests were received in the past 12 months

You'll need access to customer service teams, legal, and whoever manages your physical premises signage.

Checklist Items

1. Audit every channel listed in your privacy notices

Review each privacy notice and extract every contact method you've published for rights exercise. Don't limit this to your main privacy policy. Check product-specific notices, cookie banners, video surveillance signage, marketing preference centers, and mobile app settings.

Good looks like: A spreadsheet listing every published contact method, the document where it appears, and the date you last verified it's still accurate.

2. Verify that phone numbers are toll-free or standard-rate

For every phone number you've published for rights exercise, confirm with your telecom provider whether it's free to the caller or incurs charges. Premium-rate numbers (like Spain's 902 prefix) violate Article 12(2). Standard landline rates may be acceptable, but toll-free is safest.

Good looks like: Written confirmation from your provider that each published number is either toll-free or standard-rate, with no per-minute charges beyond what a caller would pay for a local call.

3. Test your web forms for accessibility

Submit a test Data Subject Access Request through every web form you offer. Time how long it takes. Note whether the form requires account creation, login, or information the requester might not have. Check whether it works on mobile devices.

Good looks like: You can complete and submit a rights request in under three minutes without needing to log in or provide information beyond what's necessary to verify identity.

4. Check that email addresses don't bounce

Send a test message to every email address listed in your privacy documentation. Verify that it reaches a monitored inbox and that someone responds within your documented timeframe.

Good looks like: Each email address delivers to an active inbox monitored by trained staff, with auto-acknowledgment sent within 24 hours.

5. Review physical signage for chargeable contact methods

If you operate physical locations with video surveillance or other processing that requires signage, photograph every notice. Check whether any direct data subjects to contact methods that cost them money.

Good looks like: Signage provides at minimum one free contact option (toll-free number, email, or web form), prominently displayed.

6. Verify that alternative channels are equally prominent

The Securitas Direct case confirms that having free alternatives on your website doesn't cure directing people to chargeable numbers in your notices. Check whether your privacy notices give equal or greater prominence to free channels.

Good looks like: Free contact methods appear first or in larger text than any standard-rate options. If you list multiple channels, the free one isn't buried at the bottom.

7. Document your fee policy for manifestly unfounded or excessive requests

Article 12(5) allows you to charge for manifestly unfounded or excessive requests, but you need documented criteria for making that determination. Review whether you have a written policy and whether staff know how to apply it.

Good looks like: A written policy defining "manifestly unfounded" and "excessive" with examples, plus a log of any instances where you've applied these exceptions.

8. Test your identity verification process

Submit test requests using minimal information. Determine what additional information you request to verify identity. Confirm you're not creating barriers that effectively make rights exercise difficult.

Good looks like: You can verify identity using information the data subject would reasonably have (name, email, account number) without requiring documents they might not possess or that cost money to obtain.

9. Review your response templates for hidden costs

Check whether your standard responses direct data subjects to paid services for follow-up questions or clarifications. Verify that you're not outsourcing rights fulfillment to third parties who charge fees.

Good looks like: Response templates provide free contact methods for follow-up, and any third-party processors you use are contractually prohibited from charging data subjects.

10. Audit your vendor contracts for rights exercise obligations

If processors handle personal data on your behalf, verify that your contracts specify they must facilitate rights exercise free of charge and must not direct data subjects to chargeable contact methods.

Good looks like: Data processing agreements explicitly state that the processor will not charge data subjects for rights exercise and will use only free-to-caller contact methods in any communications.

Common Mistakes

Assuming standard-rate is the same as free. Regulators interpret "free of charge" strictly. If a data subject pays anything beyond what they'd pay for a local call, you're creating a barrier.

Treating online channels as sufficient. Not everyone has internet access or digital literacy. You need at least one offline option that's genuinely free.

Burying the free option. Listing a toll-free number in fine print while prominently displaying a chargeable number creates the same problem Securitas Direct faced.

Requiring account creation to submit requests. Making someone create an account to exercise rights adds friction that may violate Article 12(2)'s facilitation requirement.

Outsourcing without oversight. If your call center or customer service provider directs people to chargeable numbers, you're liable even if you didn't make that decision directly.

Next Steps

Schedule this audit annually, but also trigger it whenever you:

  • Update privacy notices or signage
  • Change contact center providers
  • Launch new products or services
  • Receive a rights request through an unexpected channel

Assign someone to monitor regulatory enforcement decisions from EU data protection authorities. The Securitas Direct case won't be the last enforcement action on Article 12(2) compliance. When you see new decisions, ask whether your current processes would withstand the same scrutiny.

Finally, brief customer-facing teams on why this matters. The person updating video surveillance signage might not realize that choosing a 902 number over a toll-free alternative could trigger a six-figure fine. Make Article 12(2) compliance part of your vendor onboarding checklist and your signage approval process.

You Might Also Like