Rule 4

Consent Manager registration opens13 Nov 2026

myconsent+

Sec. 11–14 · Rule 14

Early access

A complaint about you is not a ticket

Sec. 11 to 12 ask you to do something. Sec. 13 says you did not. The second one gives the Data Principal a route to the Board, which is why putting both in the same inbox is the mistake that shows up in an audit.

Request types
4
Sec. 11–14
Clock each
1
Rule 14
Shared queues
0
Sec. 13
Named officer
1
Sec. 13(1)
Who it is for

For the Data Protection Officer and whoever actually answers the requests — support, most often.

Admin Console — Requests
  • DSR-2471SummarySec. 11Verified9 days
  • DSR-2470ErasureSec. 12(3)Awaiting downstream4 days
  • GRV-0148GrievanceSec. 13With the DPO2 days
  • DSR-2468CorrectionSec. 12(1)Completed
  • DSR-2465NominationSec. 14Recorded

GRV-0148 is a grievance under Sec. 13. It is owned by the Data Protection Officer by name, not by whoever picks up the queue, and its clock runs whether or not the DSRs above it are cleared first.

Two reference series, deliberately. A DSR and a GRV do not share a queue, an owner or a clock.

Four rights, and the one escalation

  1. Sec. 11

    A summary that is generated, not assembled

    The right is to a summary of the personal data being processed and the processing activities undertaken. If the register already says which activities touch a principal, the summary is a query. Without one it is a week of asking around, which is why this module and RoPA are the same purchase in practice.

  2. Sec. 12

    Correction and erasure that reach the processors

    An erasure that stops at your own database is not an erasure. The request propagates over the same webhooks a withdrawal uses, and each downstream system acknowledges with a timestamp — so the record shows what was erased where, rather than that somebody clicked a button.

  3. Sec. 13

    Grievances kept out of the support queue

    A grievance is a complaint that a duty was not met, and the Data Principal may approach the Board if it is not resolved. It gets its own reference series, its own clock and a named Data Protection Officer as owner. Filing it as a ticket is how the response window quietly becomes best-effort.

  4. Rule 14

    One clock per request type, published

    Each type carries its own response window, shown to the person when they file and counted from verification rather than from receipt. An overdue item is visible before it is overdue, because a clock you only look at afterwards is a report, not a control.

Sec. 13

Ours is published

The grievance page on this site names the officer who answers, the route to reach them and the window they answer in — because a company selling this module and hiding its own grievance route behind a contact form would be making the argument for the other side.

Questions people ask

What is the difference between a rights request and a grievance?
A rights request under Sec. 11 to 14 asks you to do something: give a summary of processing, correct or erase data, or record a nomination. A grievance under Sec. 13 says a duty was not met — including the duty to answer a rights request. They differ in what happens if you do nothing: an unanswered rights request becomes a grievance, and an unresolved grievance gives the Data Principal the right to approach the Data Protection Board. That escalation is why the two do not belong in one queue.
How long do we have to respond?
The Act does not put a single number on every request type; the Rules and your own published policy do the work. What the Act is firm about is that a Data Fiduciary must publish the means by which a Data Principal can exercise these rights and must respond within the period specified. The practical consequence is that the window you publish becomes the window you are held to — so the module makes you set it per request type, and then counts against it.
Do we need a Data Protection Officer to use this?
You need a contact who answers, and you have to publish who. Sec. 13 requires a Data Fiduciary to publish the business contact information of a Data Protection Officer, where one is required, or of the person able to answer questions about processing. Appointing a DPO is a Sec. 10 obligation and applies to a Significant Data Fiduciary; publishing a name that answers applies to everyone.
How do you verify who is making the request?
Identity verification proportionate to what is being asked for. A summary request is answered to the verified account that holds the data; an erasure over a record with no account behind it needs more. The failure mode people worry about is real and works both ways — handing a stranger a summary is a breach, and refusing a legitimate erasure until the person proves something unreasonable is a grievance waiting to be filed.
Is Rights & Grievance available today?
It is in early access. The queue, the per-type clocks, identity verification and the grievance separation run. What is not finished is automatic generation of the Sec. 11 summary from the RoPA register; until that lands, the summary is assembled with a person in the loop.

Next step

See it against your own processing

A walkthrough runs on your activities and your purposes, not a demo tenant. Thirty minutes, and you keep the notes.

Book a demo