The six kinds
| Kind | What the person is asking for |
|---|---|
| Access | A copy of their data and information about the processing |
| Erasure | Deletion, where one of the statutory grounds applies |
| Rectification | Correction of inaccurate or incomplete data |
| Portability | A machine-readable copy, or transmission to another controller |
| Objection | A stop to processing based on legitimate interests or direct marketing |
| Withdrawal | Revocation of a consent previously given |
Article 12(3) uses one month, not a universal 30-day period. The register’s shorter internal target can be used as an operational safety buffer, but the displayed legal deadline should be calculated as a calendar month and adjusted for the applicable jurisdiction, identity-verification timing and permitted extensions.
What the register does not do
Stated plainly, in the product as well as here
StrongPrivacy holds consent decisions, not your customer records. Fulfilling an access or erasure request means acting in your own systems as well as here. The subject reference is whatever you entered. Verify identity through your own process before acting on it. Closing a request records your decision; it does not notify the requester.
Those limits are the honest ones. A register that implied it could delete a customer from a warehouse, a CRM and a mailing platform would be a liability rather than a control.
Common questions
How long do I have to respond?
Under the GDPR and UK GDPR, generally one calendar month from receipt, with a possible two-month extension for complex or numerous requests if the requester is informed in time. Other jurisdictions use different periods. Treat any 28- or 30-day product reminder as an internal buffer, not the statement of law.
Does a withdrawal need to go through the register?
Not usually. A visitor withdrawing in the preference centre is recorded automatically as a new decision. The register is for requests that arrive by other routes and need tracking to a conclusion.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- Regulation (EU) 2016/679 (GDPR)
Legislation
Checked
- ICO: responding to a right-of-access request
Regulator guidance
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.