GDPR – Processing data subject rights requests
1. Purpose
The General Data Protection Regulation (GDPR) aims to safeguard individuals’ fundamental rights and freedoms, particularly their right to privacy and control over their personal data. It is based on the principles of transparency, fairness, and accountability, requiring organizations to process data lawfully, fairly, and securely.
Beyond legal compliance, the GDPR embodies an ethical approach designed to establish a relationship of trust between data controllers and data subjects. It requires the implementation of organizational and technical measures to uphold individuals’ rights, mitigate risks, and demonstrate compliance at all times (the accountability principle).
The purpose of this procedure is to define within GravitHy the rules, responsibilities, and steps required to receive, assess, process, and respond to requests from data subjects exercising their rights under the General Data Protection Regulation.
2. Scope
This procedure applies to all personal data processing activities carried out by GravitHy in its capacity as either a data controller or a data processor as part of its commercial, administrative, and technical operations.
It applies to all data subjects involved in such processing activities, including:
- Employees and job applicants;
- Partners and service providers;
- Customers and prospects;
- Any other individual whose personal data is processed by the company.
This procedure covers all requests to exercise rights granted under the GDPR (Articles 12 to 23), regardless of the channel through which the request is received (email, postal mail, online form), and applies to all systems and media used for data processing (IT databases, paper files, business applications).
3. References
- French Data Protection Act of January 6, 1978 (Loi Informatique et Libertés);
- General Data Protection Regulation of May 25, 2018 (EU Regulation 2016/679).
4. Definitions
Personal Data
Any information relating to an identified or identifiable natural person. A natural person may be identified:
- Directly (e.g., first and last name);
- Indirectly (e.g., through a telephone number, vehicle registration number, identifier such as a social security number, postal or email address, voice, or image).
A person may be identified:
- Using a single data element (e.g., a name);
- By combining multiple pieces of information (e.g., a woman living at a specific address, born on a particular date, and a member of a specific association).
Processing
Any operation or set of operations performed on personal data, regardless of the means used, including collection, recording, organization, storage, adaptation, modification, extraction, consultation, use, disclosure by transmission or dissemination, or any other form of making data available, as well as matching or combining data.
Data Controller
The natural or legal person, public authority, agency, or other body that alone or jointly with others determines the purposes and means of processing personal data. For the purposes of this procedure, the Data Controller is GravitHy.
Data Processor
The natural or legal person, public authority, agency, or other body that processes personal data on behalf of the Data Controller. In the course of its activities, GravitHy may act as a processor or appoint processors.
5. Right to Information
This right guarantees that any individual whose personal data is processed is informed in advance, in a transparent and understandable manner, of the key aspects of the relevant processing activity (Article 13 GDPR).
6. Right of Access
Provided for under Article 15 GDPR, this right allows a data subject to obtain confirmation as to whether their personal data is being processed, to access such data, verify its accuracy, and obtain copies at any time without restriction.
7. Right to Rectification
Provided for under Article 16 GDPR, this right allows any data subject to obtain from the Data Controller the correction of inaccurate personal data or the completion of incomplete data.
8. Right to Erasure (Right to be Forgotten)
Provided for under Article 17 GDPR, this right allows a data subject to request that the Data Controller delete their personal data without undue delay, subject to certain conditions.
The right to erasure does not apply where processing is necessary for:
- Exercising the right to freedom of expression and information;
- Compliance with a legal obligation or performance of a task carried out in the public interest;
- Public interest reasons in the area of public health;
- Archiving in the public interest, scientific or historical research, or statistical purposes;
- The establishment, exercise, or defense of legal claims.
9. Right to Restriction of Processing
Provided for under Article 18 GDPR, this right allows a data subject to request that their personal data no longer be processed but only stored, particularly when:
- They contest the accuracy of the data (during the verification period);
- The processing is unlawful, but they oppose the erasure of the data;
- The Data Controller no longer needs the data, but it is required for legal claims;
- They have objected to processing (Article 21 GDPR) pending verification of overriding legitimate grounds.
10. Right to Data Portability
Provided for under Article 20 GDPR, this right enables a data subject to receive their personal data in a structured, commonly used, and machine-readable format and to transmit it to another Data Controller without hindrance when:
- The processing is based on consent or a contract;
- The processing is carried out by automated means (excluding paper records);
- The data concerns information provided directly by the data subject (excluding derived or inferred data).
11. Right to Object
Provided for under Article 21 GDPR, this right allows a data subject to object at any time, on grounds relating to their particular situation, to the processing of their personal data when such processing is based on:
- The legitimate interests of the Data Controller or a third party;
- The performance of a task carried out in the public interest or in the exercise of official authority;
- Direct marketing purposes. In this case, the objection is absolute and must be respected without conditions.
12. Right Not to Be Subject to Automated Individual Decision-Making
Provided for under Article 22 GDPR, this right allows an individual to request that a decision based on their personal data not be made solely through automated processing or algorithmic analysis, but also be subject to review or verification by a natural person.
13. Procedure
Requests to exercise GDPR rights must be sent to:
Email:
rgpd@gravithy.eu
Or by post:
GravitHy
Attention: GDPR Contact Person
5 Rue du Louvre
75001 Paris
France
If a request is initially made orally, it must subsequently be confirmed in writing by the requester to facilitate, among other things, proper identification.
13.1 Receipt of the Request by GravitHy
Each request received shall be recorded by the Personal Data Contact Person in a centralized register containing:
- Date of receipt (which marks the start of the statutory response period);
- Identity of the requester;
- Type of right exercised;
- Reception channel;
- Internal reference number;
- Responsible Data Controller;
- Date the response was sent.
13.2 Acknowledgement of Receipt
The GDPR Contact Person shall acknowledge receipt of the request as soon as possible (within a maximum of 72 hours).
The acknowledgement must specify the maximum response period (one calendar month). If the request is unclear or incomplete, additional information may be requested.
13.3 Verification of the Requester’s Identity
The identity of the individual exercising their rights must be verified to ensure that the request does not relate to a third party.
Where there is reasonable doubt concerning the identity of the requester, proof of identity may be requested. However, this should remain an exceptional measure.
13.4 Qualification and Admissibility of the Request
The GDPR Contact Person shall determine the nature of the request (access, erasure, rectification, etc.).
The Contact Person shall then assess its admissibility, ensuring in particular that:
- The data concerns the requesting individual;
- GravitHy is the relevant Data Controller;
- No legal exception applies to the exercise of the right concerned (e.g., legal retention obligations).
13.5 Processing of the Request
13.5.1 The Data Concerned Is Processed by GravitHy
After acknowledging receipt, qualifying the request, and assessing its admissibility, the Personal Data Contact Person shall forward the request to the relevant department(s).
The relevant department(s) must provide a response to the Contact Person within a maximum period of ten (10) days from receipt of the request, including the requested information or confirmation that the requested action has been completed (erasure, rectification, etc.).
The relevant departments shall prepare, in collaboration with the GDPR Contact Person, a response file containing all personal data effectively held in an intelligible format and explaining:
- The purposes of processing;
- The categories of personal data concerned;
- The recipients of the data;
- The retention period;
- The existence of automated decision-making and/or profiling;
- The source of the data where it was not collected directly from the individual;
- Safeguards applied to transfers outside the European Union, where applicable.
13.5.2 The Data Concerned Is Processed by a Processor
GravitHy remains the sole point of contact for the requester.
The GDPR Contact Person shall notify the processor without delay and provide formal instructions specifying:
- The right being exercised (access, erasure, etc.);
- The identity of the requester;
- The scope of the personal data concerned;
- The contractual response deadline agreed between GravitHy and the processor, as well as the statutory response deadline (one month).
Upon receipt of the information from the processor, the GDPR Contact Person shall verify:
- The completeness of the information provided;
- The absence of unfiltered third-party data;
- Compliance with the right exercised by the requester.
The GDPR Contact Person shall also obtain evidence that the requested action has been carried out (e.g., confirmation of deletion or modification).
In all cases, the Data Controller must refuse a request for erasure where the request is not legally justified (for example, where the data remains necessary for the performance of a contract).
13.6 Response to the Request
A response must be provided in writing within a maximum of one month. This period may be extended by an additional month in the case of multiple and complex requests.
Where the data is processed by a processor, the response must always be issued by GravitHy in its capacity as Data Controller.
14. Record Retention
Requests and responses shall be retained for three (3) years as evidence in the event of an inspection by the French Data Protection Authority (CNIL).
15. Updates
This policy is the property of GravitHy.
It may be amended at any time to reflect legislative, regulatory, case law, or technical developments, as well as changes in our practices relating to the processing of personal data.