The register is signed; the request arrives on Friday
This retrospective on 2018 was written and published in 2026. GDPR became applicable on 25 May 2018. CNIL guidance is consulted in its current version; any later developments are not retrospectively attributed to that year. The article proposes programme and service arrangements without replacing the data protection officer's or legal adviser's assessment.
In this educational scenario, Léa, customer relations manager, receives an email requesting a former customer's personal data. The register lists CRM, billing and marketing. The customer also appears in a shared mailbox, complaint spreadsheet and export sent to a supplier. Teams participated in the compliance project, but nobody knows who coordinates the response. Characters and volumes are fictional; no CYTIZEN client situation is disclosed.
The difficulty is not discovering another legal text. It is connecting an understandable request to distributed tasks, systems and a checked response. Moving from project to daily operation requires a journey owner, reachable contacts and evidence that teams can handle an exception.
Separate legal accountability from work coordination
Processing classifications, legal bases and decisions about rights belong to the appropriate accountable functions. The programme director organises collection, dependencies and service transition. They do not alone decide that an export may be disclosed or that a request is abusive. The data protection officer advises and monitors within their role; that does not mean personally performing every business extraction.
Léa owns the operational customer-request journey. CRM extracts necessary data; finance searches billing records; the complaint owner checks its files; the supplier is asked to assist under the relevant contract and processing arrangement. An authorised reviewer checks the response before disclosure. Responsibilities correspond to actions and decisions, not a matrix completed only for audit.
Support recognises a request even when the email never mentions GDPR. A dedicated channel can help, but should not mean ignoring a valid request received elsewhere. Teams receive an escalation contact and a simple instruction: forward promptly, retain receipt date and avoid an improvised answer.
The complete access-request journey
The framework separates recording, qualification, search, review and response. The general legal response period is one month. Extensions exist subject to conditions, including complexity or request volume, with the person informed within the applicable period. Qualification must therefore happen promptly; uncertainty about calculation or extension conditions goes to the legal contact.
Identity checks are proportionate to risk and genuine doubt; an identity-document copy is not automatically demanded from everyone. Search extends beyond exporting the main CRM screen. Teams identify relevant personal data, copies and material held by processors. They then examine third-party information and applicable limits before disclosure.
The response must be intelligible and transmitted through a channel suited to its sensitivity. A sheet containing only internal column names and unexplained codes may not make the data accessible to the person. The coordinator records scope examined, approvals and transmission, under a defined retention rule for this evidence file.
Follow a request end to end
| Stage | Operational owner | Evidence |
|---|---|---|
| Receipt, day 0 | Customer relations | Date, channel, subject and forwarding to coordinator. |
| Qualification, day 2 | Coordinator and legal contact where required | Scope, proportionate identity check and calculated deadline. |
| Search, days 3–10 | CRM, finance, complaints and supplier | Sources queried, queries, negative responses and data found. |
| Review, days 11–15 | Authorised reviewer | Third-party protection, coherent file and intelligible wording. |
| Delivery, before deadline | Coordinator | Chosen channel, date and sending evidence; justified extension if applicable. |
| Learning | Journey owner | Previously unknown copy added to inventory and ownership assigned. |
The forgotten export exposes a process weakness
The supplier returns a file with contact details updated six months earlier. CRM does not contain that version. Léa discovers that the business exports a marketing list weekly and corrects details directly in the supplier's tool. The register alone cannot explain the cycle. The issue becomes a data dependency and correction responsibility.
The team does not hurriedly delete the file to simplify matters. It checks why the file exists, justified retention, who receives corrections and instructions governing the service. The controller and competent functions decide necessary changes. The programme implements authorised synchronisation or deletion, then tests that a source correction reaches the right destinations.
A second educational request includes a complaint containing somebody else's information. The reviewer must isolate relevant data and explain limitations. The exercise uses fictional data or an authorised environment: testing compliance does not justify exposing real data to every participant.
Make the register a living reference
The register maps processing activities; the technical inventory supplies execution detail. A stable reference connects them. A supplier, purpose, population or retention change triggers review of the relevant activity. Accuracy should not wait for the next major project.
The business owner reports change before commitment. Procurement examines supplier obligations, security relevant measures, legal processing conditions and IT data flows. Each works within its domain. Approval is not an unexplained “GDPR OK” box that records neither examination nor decision.
In Léa's case, the record names necessary operational copies, the supplier contact and correction propagation. Support knows where to search. Earlier versions are retained under traceability rules, and the updated version reaches people operating the process.
Connect the processor to the service
The contract is an operating dependency. Who receives assistance requests? In what format does the supplier provide information? How does the client recover its data when the service ends? Check these against responsibilities and applicable contract terms. A commercial contact does not replace somebody able to initiate a search.
The coordinator tests a request within the agreed scope and records actual elapsed time. If the supplier needs eight working days, that enters the internal journey. A theoretical penalty does not produce tomorrow's answer. Supplier management fixes assistance and escalation while legal examines qualification and obligations.
Do not confuse erasure with destruction of every record. Applicable obligations or grounds can require or permit some retention. Document decisions activity by activity. The programme implements approved rules and checks execution instead of applying a blanket deletion instruction to the whole information system.
Measure blind spots, not imaginary compliance
Internal qualification time, searches covering identified sources and newly discovered copies help improve the journey. None establishes compliance alone. A fast response may be incomplete; an exhaustive search may still lead to inadequately checked disclosure.
Here, coverage is documented relevant sources searched divided by sources identified for the request. Eight of ten is 80%; explain each missing source individually. The coordinator also tracks approaching deadlines and unanswered supplier chasers. Alerts support action on a live case rather than a reassuring annual score.
Each previously unknown copy triggers cause analysis: necessary unrecorded export, unjustified retention, missing integration or working practice. The goal is to prevent the next request exposing the same gap. The processing owner approves correction and the team verifies the result in the actual flow.
The constraints depend on the file
For HR, searches may involve emails, appraisals or procedural material. Third-party rights and personal data within documents require competent review. IT does not hand over an entire mailbox merely because extraction is technically possible.
In healthcare or pharmaceuticals, sensitivity and traceability require suitable measures. Tests use fictional data and limited access. In marketing, circulation of exports, amendments and suppression lists between tools may dominate. The operational owner follows that full cycle, including supplier exit.
Transition to ordinary operation is accepted when contacts can handle a request, change and exception with necessary checks. Awareness training and a signed register are means. The ability to respond appropriately to a person is the operational evidence sought.
Sources and method
The legal basis is the European regulation, supplemented by official CNIL pages consulted in 2026. Work allocation and internal milestones are original recommendations requiring adaptation and legal review. The illustrative journey is neither personalised legal advice, a compliance attestation nor a reconstruction of a client case.
- European Union — Regulation (EU) 2016/679, notably Articles 12, 15, 28 and 30
- CNIL — Records of processing activities, current guidance in French
- CNIL — Responding to an access request, current guidance in French
Links checked on 4 October 2026. The scenarios and thresholds in this article are educational; they do not describe a client engagement or an outcome delivered by CYTIZEN.