SOP: Handling a GDPR request
- Owner
- Bence
- Updated
- 20 August 2026
- Review
- quarterly
This SOP is thin on purpose. What the app does, and every field it touches, is in
erudeon/passtheyear/docs/COMPLIANCE.md. This page is the human process around it: the clock, who answers, and what must not happen.
Purpose
Answer a member exercising their rights, correctly and in time.
Scope
Access, export, rectification, erasure and objection, from students and Flow members alike. erudeon is the data controller for both.
The clock
One month from receipt. It can be extended by two further months for genuinely complex requests, but the extension has to be communicated within the first month. The clock starts when the request arrives, not when somebody notices it.
RACI
| Step | Responsible | Accountable | Consulted | Informed |
|---|---|---|---|---|
| Acknowledge | Bence | Bence | — | — |
| Verify identity | Bence | Bence | — | — |
| Execute | Bence | Bence | — | — |
| Confirm to the member | Bence | Bence | — | — |
Steps
1. Acknowledge and start the clock
- Who: Bence
- When: same day where possible
- How: reply confirming receipt and the date. Record the date somewhere durable.
- Output: the member knows they have been heard, and the deadline is fixed
2. Verify who is asking
- Who: Bence
- When: before anything is exported or deleted
- How: the request must come from, or be provable against, the account's own verified email.
- Output: confidence you are not handing one person another person's data
This step is the one that goes wrong. An export sent to the wrong person is itself a personal data breach, and it is a worse outcome than answering late.
3. Execute
- Who: Bence
- When: within the month
- How: the app's own export and erasure paths. See
docs/COMPLIANCE.mdfor what each one covers, what is pseudonymised rather than deleted, and what is retained under a legal obligation. - Output: the request carried out
4. Confirm
- Who: Bence
- When: on completion
- How: tell the member plainly what was done, and what was kept and why.
- Output: a closed request
Exceptions
| Situation | What to do |
|---|---|
| Erasure would delete an invoice | Invoices are retained seven years under Dutch law. Erase the rest, keep the accounting record, and say so |
| The request is vague | Ask one clarifying question. The clock keeps running |
| Identity cannot be verified | Do not act. Explain why and what would satisfy you |
| The request arrives via a channel nobody watches | Fix the channel. A right delayed by an unread inbox is still a breach of the deadline |
What must never happen
Do not record any part of the request, or the person's details, in this repository. That is the rule this whole repository is built around, and a GDPR request is exactly the place it would be tempting to break it.
Related
erudeon/passtheyear/docs/COMPLIANCE.md— the PII map, retention, what erasure covers../../legal/processing-register.md— the Article 30 record