← Privacy Guides

EU / GDPR corner

When a GDPR request is ignored: follow up and complain

What to do when an organisation ignores, refuses or half-answers your GDPR access, erasure or objection request: the deadlines, escalating to the data protection officer, lodging a complaint with a supervisory authority, and your right to go to court.

  • Medium threat
  • Time 1 hour to prepare an escalation, then a wait of weeks to months
  • Difficulty Moderate
  • Last verified

What this protects, and what it doesn't

Protects

  • Against a controller that stays silent: the law gives you a deadline and named next steps you can use.
  • Against a refusal with no valid reason, or an answer that leaves out data, recipients or the source.
  • Against being stuck: you can escalate to a supervisory authority and, if needed, to a court, at no filing cost to the authority.

Does not protect

  • This is general information, not legal advice. For a specific dispute, high stakes or a court case, get a qualified lawyer in the relevant country.
  • It does not guarantee an outcome. A supervisory authority may find the controller acted lawfully, or that an exception applies to your request.
  • It does not guarantee a timeline. Authorities handle a large caseload; a complaint can take many months, and there is no fixed deadline for its final decision.
  • It cannot force data to reappear if it was lawfully deleted, or override a legal ground the controller has to keep it (for erasure, Art. 17(3)).

Prerequisites

  • A GDPR request you already sent (access, erasure, objection or another right), with the date you sent it. If you have not sent one yet, use the GDPR Request Generator first.
  • Proof of what you sent and when: a copy of the letter or email, and ideally a delivery or read receipt, or a registered-post slip.
  • Any reply you received, kept in full. A simple tracking list (controller, right used, date sent, reply date, what was missing) makes every later step quick.

Step by step

  1. Know the deadline the controller has to meet

    For a request under your rights of access, rectification, erasure, restriction, portability or objection (GDPR Articles 15 to 22), the controller must act without undue delay and in any event within one month of receiving your request (Art. 12(3)).

    It can extend that by two further months where the request is complex or there are many of them, but only if it tells you within the first month and gives the reason. If no such notice reached you, the deadline stays at one month.

    If the controller decides not to act on your request, it must tell you within that same month why, and inform you of your right to lodge a complaint with a supervisory authority and to seek a judicial remedy (Art. 12(4)). Silence is not a lawful answer.

  2. Check whether the answer is actually complete

    A reply can arrive on time and still fall short. For a right-of-access request (Art. 15), a complete answer confirms whether your data is processed and, if so, gives you a copy plus:

    • the purposes of the processing;
    • the categories of data;
    • the recipients or categories of recipient it was disclosed to (Art. 15(1)(c));
    • the retention period, or the criteria used to set it;
    • any available information on the source of the data where it was not collected from you (Art. 15(1)(g));
    • whether there is automated decision-making, and meaningful information about the logic.

    For erasure (Art. 17) or an objection to direct marketing (Art. 21(2)), a complete answer confirms the data was deleted or that marketing has stopped. Note precisely what is missing or wrong; that is what you will raise next.

  3. Go back to the controller and its data protection officer

    Before involving an authority, give the controller one clear, dated chance to put it right. This is usually faster, and a supervisory authority will expect to see that you tried.

    1. Reply in writing, referencing your original request and its date. State plainly what is late, missing or refused, and quote the article (for example "my request under Article 15 of 1 September remains unanswered after one month").
    2. Address it to the organisation's data protection officer (DPO) if it has one. The DPO's contact details are normally in the privacy notice; where appointed, the DPO is the point of contact for data subjects (GDPR Art. 38(4) and Art. 37(7)).
    3. Set a short, reasonable final deadline (for example 14 days) and say you will otherwise complain to a supervisory authority.
    4. Keep the message and any reply with your tracking list.
  4. Lodge a complaint with a supervisory authority (Art. 77)

    If the controller still does not answer, refuses without a valid reason, or keeps processing after you objected, you have the right to lodge a complaint with a supervisory authority (GDPR Art. 77). You can do this in particular in the EU country of your habitual residence, place of work, or where the alleged infringement took place.

    Worked example — Luxembourg's CNPD (Commission nationale pour la protection des données):

    1. The CNPD asks that you contact the controller first to assert your rights; your reminder in the previous step covers this.
    2. Lodge the complaint using the CNPD's online complaint form, which it recommends because it speeds up handling. You can instead print the form and post it to the Service des réclamations, 15 Boulevard du Jazz, L-4370 Belvaux, Luxembourg.
    3. If the controller refused or restricted your request, the CNPD lets you use the same form to exercise the right indirectly: choose "Other" as the subject and state the right concerned.
    4. Attach your original request, the date sent, and any reply.

    The supervisory authority checks whether the complaint is justified and tries to resolve it before using any coercive measures. It must keep you informed of the progress and the outcome of your complaint (Art. 77(2)).

  5. Any EU/EEA resident: use your own national authority

    The CNPD is only the example here. Every EU/EEA country has its own supervisory authority, and you normally complain to the one where you live, work, or where the problem happened. You do not have to complain in the country where the company is based.

    1. Find your national authority and its complaint channel on the EDPB list of members, which gives each authority's address, website, email and phone.
    2. Some countries split competence between several authorities (for example by region or sector); the EDPB list notes these cases.
    3. If your complaint crosses borders, authorities cooperate through the GDPR's one-stop-shop mechanism, but you still lodge it with your own authority.
  6. If that fails: your right to go to court (Art. 78 and 79)

    A complaint to an authority is not your only route, and it is not the end of the road.

    • Against the authority (Art. 78). You have the right to an effective judicial remedy against a legally binding decision of a supervisory authority that concerns you. You can also go to court if the authority does not handle your complaint or does not inform you within three months of its progress or outcome (Art. 78(2)).
    • Against the controller or processor (Art. 79). Separately, you have the right to an effective judicial remedy against the organisation itself if you consider your GDPR rights were infringed. Proceedings can be brought before the courts of the Member State where the controller or processor has an establishment, or, alternatively, where you have your habitual residence (unless the defendant is a public authority acting in its public powers) (Art. 79(2)).

    Going to court has costs and deadlines that differ by country. This guide is general information, not legal advice: take qualified legal advice before starting a case.

Common mistakes

  • Treating silence as a refusal you cannot challenge. No answer within the deadline is itself a ground to complain under Art. 77.
  • Counting the deadline from when you think they read it. It runs from receipt of the request, so keep proof of sending and delivery.
  • Assuming an answer is complete because something arrived. Check for the recipients and the source of the data, which are often left out.
  • Complaining to the company's home-country authority when you can use the one where you live or work.
  • Throwing away the paper trail. Without your original request, dates and the reply, the authority has little to act on.
  • Thinking the complaint is your last option. The right to a judicial remedy against the authority and against the controller exists in parallel (Art. 78 and 79).

Going further

If you have not sent the underlying request yet, or want a clean, dated one to escalate from, use the GDPR Request Generator: it produces an access, rectification, erasure, portability or objection letter with the one-month deadline stated, and nothing is uploaded.

For the broader picture of which companies hold your data and how to make them stop, read Remove yourself from data brokers. This guide is general information about a legal process, not legal advice; for a specific or high-stakes dispute, consult a qualified lawyer in the relevant country.