Intake
Capture request type, requester identity/contact and enough context to locate the relevant service scope.
TRUST
Route rights requests through identity verification, scope classification, system ownership and accountable fulfilment.
Capture request type, requester identity/contact and enough context to locate the relevant service scope.
Verify requester/authority proportionately before disclosing or changing personal data.
Coordinate export, correction, restriction or other supported action with the responsible controller/system owner.
Record request state, decision, fulfilment date and applicable exception/retention basis.
Available rights and response obligations depend on applicable law, controller role and the customer deployment; the site does not promise an unsupported universal workflow.
Submit a rights request with sufficient identity/contact and service context; do not include more health data than necessary to locate the relevant record.