Skip to main content
Category: Data Subject Rights

Modalities for Exercising Rights

Also known as: Modalities for the Exercise of Data Subject Rights, Method of exercising rights
Simply put

This term refers to the practical rules and procedures that govern how an individual can make a request to exercise their data protection rights, and how the organisation must respond. It covers matters such as how quickly a response is due, whether the individual has to pay, and how the organisation should confirm who the requester is. The aim is generally to make it straightforward for individuals to exercise their rights while allowing the organisation to handle requests appropriately.

Formal definition

Under the EU GDPR, the 'modalities for the exercise of the rights of the data subject' are addressed principally in Article 12, which frames the procedural obligations attaching to the substantive rights (for example access, rectification, erasure and the other rights set out in the relevant Articles). Broadly, and subject to verification against the current official text, these modalities typically require the controller to: provide information and act on requests in a concise, transparent, intelligible and easily accessible form using clear and plain language; respond without undue delay and, in most cases, within a defined period that may be extended in specified circumstances where the request is complex or numerous; act free of charge in general, while permitting a reasonable fee or refusal where requests are manifestly unfounded or excessive; and, where there are reasonable doubts as to the requester's identity, seek additional information to verify identity before acting. The controller also generally bears the burden of demonstrating that a request is manifestly unfounded or excessive. Practitioners should note that the equivalent provisions in the UK GDPR are broadly aligned but may diverge, that member state implementing law and derogations can affect specifics, and that supervisory authority guidance continues to shape how these modalities are applied in practice; precise timeframes, fee thresholds and authentication expectations should be confirmed against the applicable current legal text and guidance. This term is procedural and does not alter the scope of the underlying rights themselves.

Why it matters

The modalities for exercising rights are the operational backbone of data protection compliance. Substantive rights such as access, rectification and erasure only have practical value if individuals can actually invoke them and organisations respond appropriately. Article 12 of the EU GDPR frames these procedural obligations, requiring controllers to communicate in a concise, transparent, intelligible and easily accessible form using clear and plain language, and to act on requests without undue delay. Where the procedure is opaque, slow or burdensome, individuals are effectively deprived of rights the law grants them, and the organisation exposes itself to complaints and supervisory scrutiny.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs are typically responsible for designing and overseeing request-handling procedures that meet the Article 12 modalities, including response timeframes, the free-of-charge principle, and defensible handling of requests that may be manifestly unfounded or excessive. They should confirm precise timeframes and fee thresholds against the current legal text and applicable supervisory guidance.
Privacy and Data Protection Lawyers
Legal advisers assess whether an organisation's procedures satisfy the procedural obligations under Article 12 and the equivalent UK GDPR provisions, advise on identity-verification practices and refusals, and flag where member state derogations or evolving regulator guidance may affect the position. They generally caution that these modalities are procedural and do not alter the scope of the underlying rights.
Engineers and Product Teams
Those building request-intake channels, authentication flows and response tooling implement the modalities in practice, ensuring requests can be submitted through easily accessible means, that responses are delivered within applicable timeframes, and that identity checks are proportionate rather than creating undue friction for legitimate requesters.
Customer Support and Operations Teams
Front-line teams often receive and triage data subject requests, so they need to recognise them, avoid imposing improper fees or barriers, and escalate appropriately. Clear internal procedures help ensure requests are handled without undue delay and in clear, plain language consistent with the Article 12 requirements.

Inside Modalities for Exercising Rights

Article 12 as the governing provision
GDPR Article 12 sets out the general modalities for the exercise of data subject rights (Articles 15 to 22), establishing how controllers must facilitate and respond to requests. It frames the transparency, communication, and procedural obligations that apply across the individual rights, rather than creating the rights themselves.
Response timeframe
The controller must generally provide information on action taken without undue delay and in any event within one month of receipt of the request. This period may typically be extended by up to two further months where necessary, taking into account the complexity and number of requests, provided the data subject is informed of the extension and the reasons within the first month.
Free-of-charge principle
Information and communications, and actions taken in response to requests, are generally provided free of charge. Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, the controller may either charge a reasonable fee based on administrative costs or refuse to act. The burden of demonstrating the manifestly unfounded or excessive character generally rests on the controller.
Identity verification
Where the controller has reasonable doubts about the identity of the person making a request, it may request additional information necessary to confirm identity. This should be proportionate and should not be used to collect excessive data or to obstruct legitimate requests.
Form and format of the request and response
Requests may generally be made by any means, including electronically. Where a request is made electronically, information is typically to be provided in a commonly used electronic form unless the data subject requests otherwise. Communications must be concise, transparent, intelligible, and in clear and plain language.
Facilitation and refusal obligations
Controllers are generally required to facilitate the exercise of data subject rights and cannot refuse to act on a request solely because of inconvenience. If the controller does not act on a request, it must generally inform the data subject without delay, and at the latest within one month, of the reasons and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.

Common questions

Answers to the questions practitioners most commonly ask about Modalities for Exercising Rights.

Do organisations have to comply with every data subject request they receive?
Not without qualification. Article 12 permits a controller to refuse to act on a request, or to charge a reasonable fee, where the request is manifestly unfounded or excessive, in particular because of its repetitive character, and the controller bears the burden of demonstrating that character. Certain rights are also conditional on their own criteria (for example, the right to erasure applies only in the circumstances set out in Article 17). So while requests must be facilitated and taken seriously, the obligation to fully comply is not absolute and depends on the applicable right and the facts. Individual right exemptions may also arise under national implementing law, so verify the position in the relevant member state.
Is a controller always required to verify a requester's identity before responding?
Not in an absolute sense. Article 12 addresses identity verification: where the controller has reasonable doubts concerning the identity of the person making the request, it may request additional information necessary to confirm identity. This is a proportionality-based mechanism rather than a blanket obligation to demand documents in every case, and it should not be used to create unnecessary obstacles to the exercise of rights. The data minimisation principle continues to apply to any additional information collected for verification. Regulator expectations on proportionate authentication can vary, so approaches should be assessed against current guidance.
What timeframe applies to responding to a data subject request?
Article 12 sets a baseline that the controller provides information on action taken without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of requests, and the controller must inform the data subject of any such extension, together with the reasons, within one month of receipt. If the controller does not act on a request, it must inform the data subject without delay and at the latest within one month of the reasons for not acting and of the possibility of lodging a complaint and seeking a judicial remedy. Readers should verify precise periods against the current official text.
Can an organisation charge for handling a data subject request?
As a general principle under Article 12, information and communications and actions taken in respect of data subject rights are provided free of charge. An exception exists where requests are manifestly unfounded or excessive, in particular because of their repetitive character; in those cases the controller may either charge a reasonable fee taking account of the administrative costs of providing the information or communication or taking the action requested, or refuse to act on the request. Because reliance on this exception must be justified and documented, fee-charging should be treated as the exception rather than the norm.
In what format must information be provided to the data subject?
Article 12 requires that information be provided in a concise, transparent, intelligible and easily accessible form, using clear and plain language. Information is generally provided in writing, or by other means including, where appropriate, by electronic means. Where the data subject makes the request by electronic means, the information should generally be provided in a commonly used electronic form unless otherwise requested by the data subject. When requested by the data subject, information may be provided orally, provided that the identity of the data subject is established by other means. The specific structured, machine-readable requirements associated with data portability derive from the separate portability provisions and should not be assumed for all responses.
What must a controller do to facilitate the exercise of data subject rights operationally?
Article 12 places an obligation on the controller to facilitate the exercise of data subject rights. In practice this typically involves establishing accessible channels for submitting requests, internal procedures to log and route requests to the correct teams, mechanisms to meet the response timeframes, and a proportionate identity-verification process consistent with data minimisation. Where the controller processes a large volume of personal data, additional measures may be appropriate before providing information, such as requesting the data subject to specify the information or processing activities to which a request relates. The precise operational design is context-dependent and should be assessed against current regulatory guidance, which can differ between authorities.

Common misconceptions

A controller always has a full month or more before it needs to respond, so it can wait until the deadline.
Article 12 requires action without undue delay, and in any event within one month. The one-month figure is an outer limit, not a default waiting period. The extension of up to two further months is available only where justified by complexity or volume, and the data subject must be informed of the extension and reasons within the first month.
Controllers can charge a handling fee for data subject requests to cover their effort.
Responding to requests is generally free of charge. A reasonable fee, or refusal, is only permitted where a request is manifestly unfounded or excessive, particularly where repetitive, and the controller generally bears the burden of demonstrating this. A routine fee for ordinary requests would typically not be compliant.
Controllers may demand extensive identity documents before processing any request.
Additional identity information may only be requested where there are reasonable doubts about identity, and the request for such information must be proportionate. Requiring excessive verification data or using authentication as a barrier can itself be non-compliant and may conflict with data minimisation principles.

Best practices

Establish a documented intake and tracking process that logs the date of receipt so the one-month period, and any justified extension of up to two months with notification to the data subject, can be monitored and evidenced.
Default to providing information and responses free of charge, and reserve fees or refusals for cases you can demonstrate are manifestly unfounded or excessive, recording the reasoning for each such decision.
Design identity-verification steps to be proportionate to the sensitivity of the data and the doubt about identity, avoiding collection of more data than necessary and avoiding using verification to obstruct legitimate requests.
Enable requests to be made by multiple means, including electronically, and provide responses in a commonly used electronic form where the request arrives electronically, unless the data subject asks otherwise.
Draft standard response templates in clear, plain, and intelligible language, and always include information on the right to lodge a complaint with a supervisory authority and to seek a judicial remedy where you decline to act.
Verify current article numbering, timeframes, and any national implementing variations or regulator guidance against the official GDPR text before finalising internal procedures, as member state derogations and evolving guidance may affect the position.