Sec. 11–14 · Rule 14
Early accessA complaint about you is not a ticket
Sec. 11 to 12 ask you to do something. Sec. 13 says you did not. The second one gives the Data Principal a route to the Board, which is why putting both in the same inbox is the mistake that shows up in an audit.
- Request types
- 4
- Sec. 11–14
- Clock each
- 1
- Rule 14
- Shared queues
- 0
- Sec. 13
- Named officer
- 1
- Sec. 13(1)
For the Data Protection Officer and whoever actually answers the requests — support, most often.
- RefTypeProvisionStateLeft
- DSR-2471SummarySec. 11Verified9 days
- DSR-2470ErasureSec. 12(3)Awaiting downstream4 days
- GRV-0148GrievanceSec. 13With the DPO2 days
- DSR-2468CorrectionSec. 12(1)Completed—
- DSR-2465NominationSec. 14Recorded—
GRV-0148 is a grievance under Sec. 13. It is owned by the Data Protection Officer by name, not by whoever picks up the queue, and its clock runs whether or not the DSRs above it are cleared first.
Four rights, and the one escalation
- Sec. 11
A summary that is generated, not assembled
The right is to a summary of the personal data being processed and the processing activities undertaken. If the register already says which activities touch a principal, the summary is a query. Without one it is a week of asking around, which is why this module and RoPA are the same purchase in practice.
- Sec. 12
Correction and erasure that reach the processors
An erasure that stops at your own database is not an erasure. The request propagates over the same webhooks a withdrawal uses, and each downstream system acknowledges with a timestamp — so the record shows what was erased where, rather than that somebody clicked a button.
- Sec. 13
Grievances kept out of the support queue
A grievance is a complaint that a duty was not met, and the Data Principal may approach the Board if it is not resolved. It gets its own reference series, its own clock and a named Data Protection Officer as owner. Filing it as a ticket is how the response window quietly becomes best-effort.
- Rule 14
One clock per request type, published
Each type carries its own response window, shown to the person when they file and counted from verification rather than from receipt. An overdue item is visible before it is overdue, because a clock you only look at afterwards is a report, not a control.
Ours is published
The grievance page on this site names the officer who answers, the route to reach them and the window they answer in — because a company selling this module and hiding its own grievance route behind a contact form would be making the argument for the other side.
Works with
- Sec. 5–6 · Rule 3AvailableConsent ManagerNotice, consent and withdrawal in 22 languages, with a receipt for every decision.
- Sec. 8(1) · Rule 8AvailableRoPAOne row per processing activity, with retention and cross-border captured at the row.
- Sec. 11–14 · Rule 14Early accessRights & GrievanceAccess, correction, erasure and grievance requests, each on its own statutory clock.
Questions people ask
- What is the difference between a rights request and a grievance?
- A rights request under Sec. 11 to 14 asks you to do something: give a summary of processing, correct or erase data, or record a nomination. A grievance under Sec. 13 says a duty was not met — including the duty to answer a rights request. They differ in what happens if you do nothing: an unanswered rights request becomes a grievance, and an unresolved grievance gives the Data Principal the right to approach the Data Protection Board. That escalation is why the two do not belong in one queue.
- How long do we have to respond?
- The Act does not put a single number on every request type; the Rules and your own published policy do the work. What the Act is firm about is that a Data Fiduciary must publish the means by which a Data Principal can exercise these rights and must respond within the period specified. The practical consequence is that the window you publish becomes the window you are held to — so the module makes you set it per request type, and then counts against it.
- Do we need a Data Protection Officer to use this?
- You need a contact who answers, and you have to publish who. Sec. 13 requires a Data Fiduciary to publish the business contact information of a Data Protection Officer, where one is required, or of the person able to answer questions about processing. Appointing a DPO is a Sec. 10 obligation and applies to a Significant Data Fiduciary; publishing a name that answers applies to everyone.
- How do you verify who is making the request?
- Identity verification proportionate to what is being asked for. A summary request is answered to the verified account that holds the data; an erasure over a record with no account behind it needs more. The failure mode people worry about is real and works both ways — handing a stranger a summary is a breach, and refusing a legitimate erasure until the person proves something unreasonable is a grievance waiting to be filed.
- Is Rights & Grievance available today?
- It is in early access. The queue, the per-type clocks, identity verification and the grievance separation run. What is not finished is automatic generation of the Sec. 11 summary from the RoPA register; until that lands, the summary is assembled with a person in the loop.
Next step
See it against your own processing
A walkthrough runs on your activities and your purposes, not a demo tenant. Thirty minutes, and you keep the notes.
Book a demo