Home
ClikBy
ClikBy Knowledge Base
GDPR

GDPR: data-subject rights and checklist

Who is controller and processor, how to respond to requests, what to check before launching an EU campaign, and where to send data subjects in the ClikBy ecosystem.

14–18 min Updated: July 2026
DSAR1 month
DPAwith the processor
72hbreach

Коротко

  • The controller decides «why and how»; the processor acts on instructions — a DPA is required.
  • Rights: informed, access, rectification, erasure, restriction, portability, object, automated decisions.
  • Request response time — a 1-month guideline (+ up to 2 if complex, with notification).
  • Practice: data map → lawful basis → banner → policy → DSAR process → vendors/DPA → security/breach.

Not legal advice

An operational checklist. Appointing a DPO, DPIA and adequacy are point legal decisions.

A guide to structure and facts: www.cookieyes.com/… · www.cookieyes.com/… · www.cookieyes.com/…. Summary KB section: CookieYes → GDPR. Not legal advice and not a verbatim translation.

Controller and processor

Controller defines purposes and means. Bears primary responsibility for compliance, notices, choosing legal bases, and responding to data subjects.

Processor processes only under a contract/instructions, implements TOMs, helps with DSARs, does not use the data «for itself» against the mandate.

There can be joint controllers — if they jointly determine purposes; that is a separate regime with a transparent split of roles.

  • The ClikBy account client for clickers of their link is the controller;
  • ClikBy is the processor (authorized person) for these clicks;
  • Pixel ad vendors are often separate recipients / controllers or processors under their models — describe in the notice.

Without a DPA/contractual clauses with the processor you leave a hole in accountability.

Data subject rights

  • Right to be informed — a transparent privacy notice before/at the moment of collection.
  • Access — confirmation of processing + a copy/information on purposes, periods, recipients, transfers.
  • Rectification — correction of inaccurate data.
  • Erasure — the «right to be forgotten» under conditions (consent withdrawal, purpose exhausted, etc.).
  • Restriction — temporary restriction of processing.
  • Portability — a structured machine-readable copy; transfer to another controller if feasible.
  • Object — including to direct marketing (the right is stronger here) and to LI in a number of cases.
  • Automated decision-making — the right not to be subject to solely automated decision with legal/significant effects without safeguards (human review, contest).

How to respond to a DSAR

  • Intake: form / email / cabinet — convenient and found in the policy;
  • Identity verification before releasing data;
  • Deadline: without undue delay, guideline 1 month; +2 months if complex — with notification and reason;
  • Usually free (except clearly excessive/repetitive);
  • Log requests and responses — part of accountability;
  • Escalation to processors: you request ClikBy/vendors under your instructions.

The clicker writes to the link sender (you). The account client, for account data — to ClikBy using the Policy contacts.

Key business duties

  • Follow Art. 5 principles and have a lawful basis;
  • Privacy by design / by default;
  • TOMs and readiness for breach notification;
  • Manage processors through contracts;
  • Children's data: parental consent (16, or lower by country, not below 13);
  • DPIA at high risk (profiling, special categories at scale);
  • DPO — if public authority / large-scale systematic monitoring / large-scale special categories;
  • Transparent notices; control of international transfers.

Checklist: 10 practical steps

  • 1. Data mapping — forms, CRM, cookies, pixels, accounts, backups; cookie scan regularly.
  • 2. Lawful basis — a «processing → basis» table before campaign launch.
  • 3. Consent management — opt-in banner, equal Reject, tag blocking, consent logs.
  • 4. Privacy & cookie notices — clear language, current vendors and retention periods.
  • 5. DSAR process — process owner, templates, SLA.
  • 6. Privacy by design — minimum fields, access, DPIA before high-risk features.
  • 7. Security + breach plan — encryption, MFA, 72h playbook, breach register.
  • 8. Vendors & DPA — ClikBy, hosting, ads, analytics; SCCs/adequacy for transfers.
  • 9. Regular review — policies, banner, vendors, retention, team training.
  • 10. Accountability owner — DPO or an appointed privacy lead.

Cross-border transfers

Before transferring personal data from the EEA to «third countries» a mechanism is required: an adequacy decision of the European Commission, Standard Contractual Clauses (SCCs), binding corporate rules, or other permitted tools. Assess vendors (US ads/analytics, clouds) and reflect transfers in the notice.

The EU-US Data Privacy Framework and equivalents — check the current status; do not rely on the outdated Privacy Shield. The CookieYes KB has a card on the Framework — GDPR section.

Personal data breach

If there is a risk to the rights and freedoms of data subjects — notify the supervisory authority without undue delay, a 72-hour reference from the moment of awareness. Content: nature, categories/volume, consequences, measures. Sometimes subjects must be notified too. Keep an internal incident register even if you «did not report outward».

An ad-account «leak» or unauthorized access to a visits export are also candidates for a breach assessment.

Request and settings routes in ClikBy

SituationКуда
A clicker asks to delete click dataYou as controller → ClikBy support/DPA
Account client / accountContacts from the ClikBy privacy-policy
Withdrawal of marketing cookies on the site/cookies + tags wait for consent
Refusal on a redirect with pixelspixel_notification → Reject
Policy and rolesprivacy-policy.html + privacy-cookies-guide

In ClikBy for clicks on the client's links: Customer = controller, ClikBy = processor (privacy-policy §1.9). The EU representative in the Policy is Barcelona. Levers: Cookie Consent, pixel_notification on the redirect, a DPA if needed.

FAQ

Is a GDPR audit mandatory?

Clearly not always a «must», but regular audits are best practice for accountability (see CookieYes materials on a compliance audit).

Is GDPR enough for California?

No. You also need CCPA/CPRA disclosures and opt-out if there is sale/share. Comparison.

Link to 99-3

For a Belarusian operator and a local audience also see Law No. 99-3 and the BY section — GDPR does not replace it.

What’s next?

Check roles and the policy

Open the product mapping of GDPR in help and the full Policy text.