FieldRegister
Every field · Consent, preferences and rights

Rights request or deletion flag

A record of a rights request (access, deletion, correction) is itself evidence for CPRA recordkeeping (CCR 7101) and GDPR Art. 12.

personal data
personal data?
standard
sensitivity
usable
AI use
legal obligation
lawful basis usually relied on

Keep it how long

For the request record: the limitation period. The data it concerns: as the request requires.

The gap we see most

Deletion handled by anonymising the name and leaving the rest of the record intact.

What holding it is evidence for

Requirement text and artefacts from a human-verified corpus licensed to Field Register.

Rights requests GDPR Art.12 · GDPR Art.15 · GDPR Art.17 · CCPA/CPRA §1798.105 · CCPA/CPRA §1798.130(a)(2) · ISO/IEC 27701:2019 7.3.9
GDPR Art.12 Transparent information, communication and modalities for rights

Provide the Article 13 and 14 information and every Article 15 to 22 and 34 communication in a concise, transparent, intelligible and easily accessible form, in clear and plain language, with particular care where the information is addressed to a child, normally in writing including by electronic m...

Evidence an auditor accepts: The request register showing receipt date, response date, and any extension with its notification and stated reasons; Readability evidence for the privacy information, such as a plain language review or a reading age assessment; The identity verification standard applied, with the reasoning that it is proportionate rather than routine
GDPR Art.15 Right of access by the data subject

On request, confirm whether personal data concerning the data subject is being processed and, where it is, provide access to that data together with the purposes, the categories of personal data, the recipients or categories of recipient including any in third countries or international organisation...

Evidence an auditor accepts: The search methodology showing every system, archive and unstructured store searched, and how completeness was assured; A worked response covering all the supplementary information items, not only the copy of the data; The redaction position and the applied redaction log where third party data was withheld, with a reason recorded per redaction
GDPR Art.17 Right to erasure (right to be forgotten)

Erase personal data without undue delay where the data is no longer necessary for the purposes it was collected or processed for, where consent is withdrawn and no other legal ground applies, where the data subject objects under Article 21(1) and there are no overriding legitimate grounds or objects...

Evidence an auditor accepts: Erasure records showing the ground relied on, the decision, and the date the data actually left each system; A deletion capability map covering production, replicas, warehouses, logs, search indexes, backups and processors, with method and lag for each; Where an exemption is applied, the specific Article 17(3) ground and the necessity reasoning for the data actually retained
CCPA/CPRA §1798.105 Right to Delete Personal Information

Consumers have the right to request deletion of PI a business has collected from them. Upon receipt of a verifiable request, the business shall delete the PI from its records and direct service providers, contractors, and third parties to delete the PI, unless a statutory exception applies (e.g. com...

Evidence an auditor accepts: Deletion request intake mechanism (web form, toll-free number); Verification procedures; Deletion request log with timestamps and outcomes
CCPA/CPRA §1798.130(a)(2) 45-Day Response Window and Identity Verification

Businesses must disclose and deliver requested information to the consumer free of charge within 45 days of receiving a verifiable consumer request. The 45-day period may be extended once by an additional 45 days when reasonably necessary, provided the consumer is notified within the first 45 days. ...

Evidence an auditor accepts: Request workflow with SLA timers; Extension notification templates and logs; Identity verification policy (matching to existing records, signed declaration)
ISO/IEC 27701:2019 7.3.9 Handling requests

The organization must define and document policies and procedures for handling and responding to legitimate requests from individuals, which can include requests for a copy of data or to lodge a complaint, handling them within appropriate defined response times, taking account of jurisdictions that ...

Evidence an auditor accepts: Documented request handling procedure covering identification, triage, response and escalation; Response times published in the privacy policy and measured in operation; Delay notification procedure and evidence of use

Do this for your whole CRM

Paste your field list and get this classification for every field at once, with the record of processing per object, the gaps, and the controls the register is evidence for. No account for the first run.

Build my field register

Opt-out, do-not-contact or unsubscribe flag · Call recording or transcript