Skip to content
PeekWellThe Rulebook
Join now

Data subject rights: no clear way to ask or delete

At a glance

EU-07HighGDPR Art. 12(2); Art. 83(5)(b)

Peeky looks for a described way to ask for your data or ask you to delete it, and a contact route that actually opens.

Last checked against the source:

I need to fix thisI need the rule

The rule

Article 12 sits at the head of the chapter on the rights of the data subject, the person the data is about. Paragraph 2 is the sentence this check rests on: “The controller shall facilitate the exercise of data subject rights under Articles 15 to 22.” Paragraph 1 asks for information and communication about those rights in a “concise, transparent, intelligible and easily accessible form, using clear and plain language”. Paragraph 3 requires the controller to act on a request “without undue delay and in any event within one month of receipt of the request”, with a possible extension of two further months “where necessary, taking into account the complexity and number of the requests”.

Articles 15 to 22 are the rights themselves. Access is Article 15. Article 17 is the right to erasure, headed “right to be forgotten” in the text. Article 20 is data portability, the right to receive data in “a structured, commonly used and machine-readable format” and to have it sent to another controller where technically feasible. Each has its own conditions, and some have exceptions. Article 12 is about the path that leads to them, whichever right a person is asking for.

The Regulation does not say which channel a company must offer. It names no form, portal or address. What it requires is that the company facilitates, and the EDPB has said what that looks like in practice.

The EDPB notes that the GDPR “does not impose any requirements on data subjects regarding the form of the request”, and “encourages controllers to provide the most appropriate and user-friendly communication channels, in line with Art. 12(2) and Art. 25 GDPR, to enable the data subject to make an effective request” (paras. 52 and 53). A request made through a channel the controller itself provides should in general be treated as effective even if it is not the preferred one. The controller is not obliged to act on a request sent to a random or incorrect address, or to a channel clearly not meant for such requests, where it has provided an appropriate channel (para. 54). The EDPB also recommends, as good practice, mechanisms such as autoresponders and internal forwarding so that requests reach the right people (para. 56).

Penalties follow the usual two-tier structure. Article 83(5)(b) places “the data subjects’ rights pursuant to Articles 12 to 22” in the upper tier, with a ceiling of EUR 20 million or 4% of total worldwide annual turnover, whichever is higher. The EDPB adds that unjustified rejections of access requests “can be regarded as infringements of data subject rights pursuant to Art. 12 to 22 GDPR” open to fines under Article 83(5)(b), and that a person who thinks their rights were infringed may complain to a supervisory authority under Article 77 (para. 195).

What PeekWell checks and how

EU-07 asks two questions a visitor could answer in a minute: does the site describe a way to ask for access, erasure and portability, and does the contact route it names actually open?

The scan fetches the public privacy policy and the contact pages the site links to. It reads them for language about each right and for a mechanism to use it: an email address, a web form or a portal. A language model helps confirm that the text describes each right and a way to exercise it. The second question is settled by code: the scan checks that the email link, form page or portal address resolves. A missing right or a contact link that goes nowhere becomes a finding.

The scan does not send a request, fill in a form, write to the address or sign in. It cannot tell whether anyone reads the inbox, whether replies go out within the time limit, or whether the company handles requests correctly once they arrive. Those are the things the Uber and Garante decisions turned on, and they are outside what a visit can see.

The same method runs for UK sites under UK-09, with the UK rules applied. The scan has the usual limits, and the report says so. It sees the public pages it visited and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. A rights route offered only inside an account, or only by a phone call or letter, may not show up in a page read. A Passed means the expected wording and a working route were observed on the pages scanned. It does not say the company handles requests properly.

Why it matters for a company

This is a complaint-driven area. A person who cannot reach a company, or cannot get an answer, can complain to a supervisory authority, and the authority then looks at what the company offered. In the Uber matter, which ended in a EUR 10 million fine announced on 31 January 2024 (it also covers findings on retention and transfers), more than 170 French drivers went to a human rights association, which complained to the French authority, which passed the file to the Dutch one because Uber’s European headquarters is in the Netherlands.

The route is also something an authority can read for itself. The Dutch authority described a request form that existed but was hard to find, and an answer that arrived as a file that was hard to interpret. Its chair said Uber should have facilitated drivers, and that this is in the law. The Garante’s record is more ordinary: a request to the data protection officer’s address that went nowhere. When the person wrote again, to the DPO address and two other company addresses, all three messages bounced off the spam filter. Only a message to the company’s registered PEC address got a reply.

The one-month clock in Article 12(3) runs from receipt, so a blocked or unmonitored inbox does not stop it.

Smaller companies and larger companies

Article 12 has no size threshold. The same sentence applies to a two-person shop and to a platform with a hundred thousand drivers.

In a small company the route is usually an email address in the privacy policy, often copied from a template. It may point at a mailbox nobody checks, a former employee, or an address behind a spam filter that treats a stranger’s long message as junk. That is what happened in Italy: the request was left unanswered for a month without anyone deciding to ignore it. There may be no one whose job is to notice, so a complaint can be how it comes to light. The fine was EUR 45,000, and it covered several findings.

In a larger company the problem is more often the shape of the process. Requests may have to go through an account, an app menu or a support ticket, and the form may live where the product team put it, not where a person would look. The data may sit in many systems and come back as an unreadable export. Scale also raises the stakes: the Dutch authority took account of the size of the business and the seriousness of the findings, and about 120,000 drivers were working for Uber in Europe at the time.

Enforcement cases

Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

The Officer, squinting at a file.

Larger companies

  • Uber Technologies Inc. and Uber B.V.

    Autoriteit Persoonsgegevens (Netherlands), 2024€10 million

    The Dutch authority found that Uber made it unnecessarily complicated for drivers to ask for their data. The digital access form in the driver app was buried and scattered across menus, and the reply came as a file in which the data was not always structured and was hard to interpret. The fine also covers unclear information on retention and transfers. After Uber objected, the authority rejected the objection in May 2026 and Uber is appealing to the court.

    Read the Autoriteit Persoonsgegevens (Netherlands) publication about Uber Technologies Inc. and Uber B.V.

Smaller companies

  • Noi Compriamo Auto S.r.l.

    Garante (Italy), 2025€45,000

    A person emailed the company's data protection officer on 21 June 2023 to exercise their data rights, and got no reply. The company said its spam filter had blocked the message. When the person wrote again on 24 July 2023, to the DPO address and two other company addresses, all three messages bounced off the spam filter. Only a message to the company's registered PEC address got a reply. The Garante found the person was not allowed easy exercise of their rights, among other findings about promotional emails. The fine covers all of them.

    Read the Garante (Italy) publication about Noi Compriamo Auto S.r.l.

How to fix it

These steps follow the EDPB’s guidance on user-friendly channels and on making sure requests reach the right people. They are practical choices, not a list the Regulation prescribes.

  1. Say it in the privacy policy. Name each right in plain words: access, erasure, portability and the others that apply. Next to them, give one way to use them that a visitor can follow without a guide.
  2. Give the route a visible home. Link to it from the footer and from the privacy policy. A short page titled something like “Your data rights”, with an email address or a form, is easier to find than a paragraph in a long policy.
  3. Use a mailbox that someone owns. Create a shared address such as privacy@yourcompany, assign two people to it, and add an autoreply that says the request was received and when to expect an answer.
  4. Test the inbox from outside. Send a message from an address that has never written to you, with a long subject and no previous thread. Check it arrives, and not in a spam folder. Ask your email provider to allow-list the address that receives requests.
  5. Tell staff what a request looks like. A request can reach support, sales or a social account. Agree who it is forwarded to, and write down the date it arrived, since the one-month period runs from receipt.
  6. Re-scan. Run a scan again once the wording and the working route are live. The finding should clear when the page describes the rights and the contact link opens.

Whether a given setup meets Article 12 for your business is a question for your legal adviser, and Peeky reports only what it sees.

Questions

What are data subject rights under GDPR?

They are the rights a person has over their own data, set out in Articles 12 to 22 of the GDPR. They include access (Art. 15), erasure (Art. 17) and portability (Art. 20).

The company that decides why and how the data is used has to make them easy to use, and to answer without undue delay and within one month in the usual case.

Does a website need a special form for data subject requests?

No. The European Data Protection Board says, in its guidance on the right of access, that the GDPR sets no requirements on the form of a request, so email, post or a form can all work. It does expect the company to offer user-friendly channels, and Article 12(2) says the company must facilitate the exercise of the rights.

Is the right to erasure the same as the right to be forgotten?

Yes. Article 17 of the GDPR is titled right to erasure, with right to be forgotten in brackets. A person can ask for their data to be erased when one of the listed grounds applies, for example when it is no longer needed or when consent is withdrawn and nothing else justifies keeping it.

Does the GDPR give people a right to take their data elsewhere?

Yes, in some cases. Article 20 gives a right to receive data the person provided, in a structured, commonly used and machine-readable format, where the processing rests on consent or a contract and is done by automated means. It also covers having the data sent straight to another company where that is technically feasible.

How does Peeky check for a way to exercise data rights?

Peeky reads your public privacy policy and contact pages for wording about each right and a way to use it, then checks that the email link or form it finds opens. It never submits a request and never signs in. How a scan works has the full path.

Filed with

The rule

GDPR (Regulation (EU) 2016/679), Arts. 12, 15 to 22 and 83(5)(b)

Read the rule (GDPR (Regulation (EU) 2016/679), Arts. 12, 15 to 22 and 83(5)(b))

A case

Uber Technologies Inc. and Uber B.V.

Autoriteit Persoonsgegevens (Netherlands), 2024

Read the decision (Uber Technologies Inc. and Uber B.V.)

Your site

Is your website affected? Join now to find out.

Join now

Sources

  1. Regulation (EU) 2016/679 (GDPR), Art. 12, as adopted (text hosted by legislation.gov.uk)
  2. Regulation (EU) 2016/679 (GDPR), Art. 17, as adopted (text hosted by legislation.gov.uk)
  3. Regulation (EU) 2016/679 (GDPR), Art. 20, as adopted (text hosted by legislation.gov.uk)
  4. Regulation (EU) 2016/679 (GDPR), Art. 83, as adopted (text hosted by legislation.gov.uk)
  5. EDPB, Guidelines 01/2022 on data subject rights, right of access, version 2.1, adopted 28 March 2023
  6. Autoriteit Persoonsgegevens, Uber krijgt boete van 10 miljoen euro voor overtreden privacyregels, 31 January 2024 (updated 8 May 2026)
  7. Garante per la protezione dei dati personali, provvedimento of 4 June 2025 [10143278], Noi Compriamo Auto S.r.l.

Last checked against the source:

For information only. Not legal advice.