30% of CNIL (National Commission for Information Technology and Civil Liberties) sanctions concern failure to comply with the exercise of rights.
At Dipeeo, we see it every day: GDPR requests GDPR on the rise within companies.
The reason? Citizens are becoming increasingly well-informed, cases are receiving media coverage, and there has been a proliferation of tools that collect personal data (CRM, HR tools, marketing platforms, business software).
The GDPR clear on this point: these rights must be easy to exercise, free of charge, and handled efficiently.
Clients, prospects, employees, former employees, job applicants… anyone can exercise their rights at any time.
Above all, a request can come from anywhere: to a generic address, via a form, to client service, marketing, HR, a manager, or even verbally. The channel is irrelevant under the GDPR.
Once a request has been made, it must be taken into account.
And your company is on the front line
Right of access, erasure, objection… Requests related to GDPR rights GDPR now one of the leading causes of complaints and penalties.
In 2024 and 2025, the CNIL (National Commission for Information Technology and Civil Liberties) dozens of decisions related to poorly handled requests: late, incomplete, non-existent, or impossible to prove responses.
In most cases, these are not complex situations, but rather a lack of method, organization, or traceability.
A guide to stop improvising when dealing with GDPR requests
This guide has been designed for all companies that want to respond correctly, on time, and without stress, even without GDPR expertise.
It helps you turn a legal claim into a clear, controlled, and traceable process, rather than a source of tension, wasted time, or risk.
Who is this guide for?
This guide is intended for all organizations, public or private, regardless of their size, and in particular:
-
Legal officers and DPOs
-
Human resources
-
Marketing, sales, and client support
-
Senior management and managers
Any person who may receive a request for rights, by email or any other channel
Discover our article: GDPR individual rights GDPR Your key obligations.
At Dipeeo, we support nearly 500 companies and handle requests to exercise rights on their behalf on a daily basis.
Since October 2025, we have seen a fivefold increase in the volume of requests processed, with a sharp rise in HR litigation contexts.
This guide is directly derived from:
-
real-life situations encountered in business,
-
the specific expectations of the CNIL (National Commission for Information Technology and Civil Liberties),
-
errors that most often lead to a penalty.
"In most of the CNIL (National Commission for Information Technology and Civil Liberties) audits we assist CNIL (National Commission for Information Technology and Civil Liberties) , the difficulties do not stem from data leaks, but from requests for rights that have been mishandled, poorly documented, or simply forgotten." Raphaël Buchard, CEO of Dipeeo
With Dipeeo, no more headaches: we manage all your rights requests, from receipt to response to proof of compliance.