Skip to main content
The state of ai impact assessment
DPAs Issued Hundreds of Right-to-Object DecisionsData Subject Rights
5 min readFor Compliance Officers

DPAs Issued Hundreds of Right-to-Object Decisions

The European Data Protection Board updated its One-Stop-Shop case digest on the Right to Object and Right to Erasure in June 2026, adding hundreds of new enforcement decisions since the original publication. This update reveals how Data Protection Authorities assess organizational processes for handling these rights under Articles 17 and 21, highlighting frequent violations and corrective measures.

If you're a compliance officer building or auditing your data subject rights response program, this digest offers enforcement insights you won't find by reading the General Data Protection Regulation text alone.

What the Updated Digest Shows

The digest synthesizes One-Stop-Shop decisions from the EDPB's public register under Article 60. These are cross-border cases where a lead supervisory authority coordinates with concerned authorities across member states. The update focuses on the right to object (Article 21) and the right to erasure (Article 17).

The cases cover practical scenarios your team likely handles: individuals objecting to direct marketing, users requesting account deletion, and data subjects demanding removal of their online profiles. DPAs evaluated how organizations structure their internal processes to receive, verify, and execute these requests, not just whether they comply in theory.

The digest identifies recurring infringements and documents which corrective measures supervisory authorities applied. This isn't abstract guidance. It's a record of what actually triggered enforcement and what DPAs required organizations to fix.

Key Findings

DPAs scrutinize process design, not just outcomes. Authorities assess the mechanics of your rights fulfillment workflow. They examine how you receive requests, verify identity, determine legitimate grounds to refuse, and communicate decisions. A compliant outcome on one request doesn't protect you if your process creates systematic barriers.

Direct marketing objections remain a high-frequency violation area. Article 21(3) requires informing data subjects of their right to object to direct marketing "at the latest at the time of the first communication." Cases in the digest show that DPAs enforce this timing strictly and that organizations often fail to make the objection mechanism "explicitly brought to the attention of the data subject and shall be presented clearly and separately from any other information."

Erasure request handling exposes gaps in data mapping. When a data subject requests erasure under Article 17, your response deadline is one month from receipt. The digest cases reveal that organizations struggle most when they can't quickly identify where personal data resides across systems. DPAs don't accept "we're still searching" as grounds for delay beyond the one-month window, which you may extend by two additional months only if the request is complex, and you must inform the data subject of the extension within the first month.

Refusal justifications must be specific and documented. Article 17(3) provides exceptions to erasure (legal obligation, public interest, legal claims). The digest shows DPAs require you to document which specific exception applies and why. Generic responses citing "legitimate interest" without tying it to a concrete legal basis or explaining the balancing test fail scrutiny.

Corrective measures extend beyond fines. While financial penalties appear in some cases, DPAs frequently issue orders requiring organizations to implement technical measures, revise policies, conduct staff training, or submit to follow-up audits. The digest documents these non-financial corrective actions, which often impose longer-term operational burdens than a one-time penalty.

What This Means for Your Team

Your data subject rights response program needs to withstand process scrutiny, not just produce correct outcomes on individual requests. When a DPA investigates, they'll review your procedures, timelines, communication templates, and escalation paths.

If you handle cross-border processing and fall under One-Stop-Shop procedures, these digest cases represent the enforcement baseline. The lead supervisory authority coordinates with concerned authorities, but the standards they apply come from this body of decisions.

Your current response time metrics matter less than whether you've built a system that can consistently meet the one-month deadline. A backlog of erasure requests signals a structural problem, not a temporary resource constraint.

Action Items by Priority

Map every system that stores personal data, now. You can't fulfill erasure requests on time if you're discovering data repositories during the response window. Create and maintain a data inventory that includes: system name, data categories stored, retention rules, and technical deletion method. Update this inventory whenever you deploy new tools or migrate data.

Audit your direct marketing opt-out presentation. Review the first communication in every marketing channel (email, SMS, in-app, postal). Verify that the right to object appears as a separate, clearly labeled element, not buried in a privacy notice footer. Test that the objection mechanism works and that it suppresses the data subject's information across all marketing systems within your processing environment.

Document your Article 17(3) exception framework. Build a decision tree your team can apply when a data subject requests erasure. For each exception (legal obligation, public interest, establishment/exercise/defense of legal claims), define what evidence you need to invoke it and who approves the decision. Store this documentation with each request record.

Implement identity verification that doesn't create delay. DPAs recognize that you must verify identity before fulfilling requests, but the digest cases show they won't excuse missed deadlines because your verification process is cumbersome. If your current method adds more than a few days to response time, streamline it. Consider risk-based verification: higher confidence for erasure requests, proportionate methods for objection to marketing.

Train your first-line responders on timeline requirements. The person who receives a data subject request via your web form, email, or customer service channel must know to route it immediately. A request that sits in a general inbox for two weeks before reaching your privacy team has already consumed half your response window. Create routing rules, set up dedicated intake channels, and train customer-facing staff to recognize rights requests even when the data subject doesn't use the exact regulatory language.

Review corrective measures in digest cases similar to your processing. The EDPB's public register (which feeds this digest) allows you to filter by processing type and infringement category. Identify cases involving your sector or processing activities. Read what DPAs ordered organizations to fix. Apply those corrective measures proactively before you face enforcement.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like