Subject requests and breaches: the complete file, before the deadline
An access request lands on a Friday evening; one month starts running from the moment it was received. A supplier reports an incident on a Saturday morning; seventy-two hours start running from the moment you become aware of it. In between, you have to establish an identity without collecting too much, query eight systems, find what belongs to a third party, separate established facts from unknowns, and produce a file an inspection can read back. <strong>The agent does that work in full and hands you the file in minutes</strong>: complete, quantified, sourced, with the dated rule that produced it. You keep the signature — the one that binds you, and the one that, on that day, is worth more than anything else.
Updated on
What I have already done: identity established from the two items the person already had on file with you, six sources queried, six replies obtained, 214 occurrences deduplicated down to 61, and the extract is assembled.
What is waiting for you: four items contain exchanges in which a third party appears. I have redacted them reversibly, each with its reason — you lift or you confirm, in four clicks.
⛓ Sourced · privacy portal, CRM, HRIS, DMS, mail, warehouse
What I need from you is one signature, and it is not a formality: sending personal data to the wrong recipient is itself a breach. The mandate you write sets who validates, within what limits, and it is withdrawn with a word.
Want the shortcut? Give me a standing mandate on access requests where identity is established and no third-party data is involved: those will go on their own, and you will only review the rest. Over your last twelve months, that would have covered 31 files out of 47.
✎ Framework · written mandate, capped, dated, revocable
Established facts: one payslip export, 3 systems, a 41-hour window. Unknowns, and I am leaving them unknown: the exact number of people affected — the investigation is open, and I am not writing zero in its place.
What I am putting on your table: the draft initial notification is written from the settled facts, and Article 33(4) expressly allows information to be provided “in phases”. You do not wait until you know everything to notify — you notify what you know, and I prepare the follow-up.
⛓ Sourced · processor report, application logs, ITSM
A Blue Lemon Agent specialised in operational files: it opens every data subject request and every breach with its enforceable date of receipt, verifies identity and mandate without collecting more than necessary (Article 12(6)), queries the systems in scope while recording failures and non-responses, prepares reversible redactions, assembles the response file, documents the breach by separating established facts, estimates and unknowns, and drafts the notifications. The one-month (Art. 12(3)) and 72-hour (Art. 33(1)) deadlines are shown with their starting point. You keep your hand on what binds you: the notification goes out under your signature, and the agent has already drafted, dated and sourced what you will send.
Reference points describing how our offer is built, not results measured at a client. Case volume, source coverage and time returned are confirmed by a pilot on your own scope.
Two clocks that do not stop, and work that cannot be delegated
A subject request and a breach have almost nothing in common, except this: they arrive when nobody expects them, and a deadline starts immediately. The rest of the work — establishing an identity, bounding a scope, getting a reply from eight systems, two of which are run by a provider, finding what belongs to a third party — is done by hand, under pressure, by the person with the least time.
! What is at stake
The breaking point is almost never the law: it is documentary. Nobody can say, at the end of a search, whether all eight systems answered or whether two stayed silent. A silent source looks like an empty source, and an absence of results in a system ends up being read as an absence of data in the organisation. That confusion is what loses inspections.
On breaches the difficulty is the mirror image: the organisation waits to know everything before notifying, and the clock runs. Yet Article 33(4) GDPR provides for exactly the opposite — where the information cannot be provided at the same time, it “may be provided in phases without undue further delay”.
✓ Our answer
The agent holds both clocks from a proven starting point, bounds the search to the authorised scope, and keeps for each source its result, its failure, its freshness and its coverage. A source that did not answer produces an unknown state, never a void. On a breach, it separates what is established from what is estimated and what remains unknown, and proposes the initial notification that Article 33(4) allows to be completed later.
The four decisions that bind you — notifying the authority, communicating to data subjects, refusing a request, lifting a redaction — reach you instructed rather than open. Each comes with its facts, its unknowns, its grounds and its draft text: what used to take you half a day of preparation is settled in a few minutes of reading. Articles 33 and 34 assign those acts to a named person; the agent does everything that precedes them, and hands you the decision while it still counts.
A rights tool handles, by design, the data of your data subjects
A rights file contains everything the organisation holds about a person. A breach file contains the anatomy of its incident. Here is how the architecture keeps them separate and protected.
Local inference
The agent can run on a machine inside the company: neither the extracts nor the incident files leave the network.
Hosted in France
Otherwise, a dedicated and isolated resource hosted in France under French law, with processing and access operated within the European Union as the deployment objective.
Partitioned by entity
A file belongs to a tenant and an entity. No role, not even the connector administrator, crosses that boundary — refusal is the default.
Reduced extraterritorial exposure
Architecture designed to reduce exposure to extraterritorial legislation, location alone not guaranteeing immunity.
What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.
- The applicable location is that of the architecture set out in the quotation and verified before commissioning.
- Local execution is announced only for the configuration explicitly described and accepted in the quotation.
- The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
- The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
See the agent at work
4 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.
A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.
The company in this demonstration
Fictional companyMaison Aurore — a homeware retail chain, 22 stores and an online shop
- Sector
- Specialist retail: household linen, tableware, small furniture
- Headcount
- 480 staff, including a privacy officer at half time and an incident manager in the IT department
- People served
- Consumers in France — 840,000 active loyalty accounts
- Order of magnitude
- 47 rights requests received last year, 6 systems in the search scope, 2 breaches reported
- Tools in place
- Privacy portal, loyalty CRM, HRIS, document management system, corporate mail, data warehouse
- Who decides
- The privacy officer validates the redactions and the replies; the managing director, as controller, signs every notification
- Room for improvement
- 16 of the 47 requests were closed beyond one month, and none of them says how many systems actually answered
Maison Aurore handles its rights requests by hand from the privacy portal: the officer writes to six departments, waits, chases, and assembles whatever comes back. At the end, nobody can say whether all six answered. The agent is connected to those six systems and works continuously; redacting an item, replying to the requester and signing a notification remain human acts.
This company, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real client.
Identity: established. The requester gave their loyalty card number and the address declared when the account was opened; the two match. I asked for no identity document — Article 12(6) allows one only where there are “reasonable doubts”, and there were none.
Search run on the six systems in scope, six replies obtained. 214 occurrences found, brought down to 61 after deduplication: the same checkout transaction appeared up to four times across the CRM, the warehouse and the DMS.
The extract is assembled and waiting for you. source-coverage_six-out-of-six-file-AUR-2026-041.pdf6 sources queried, 6 replies, 214 occurrences brought down to 61
⛓ Sourced · privacy portal, loyalty CRM, HRIS, DMS, corporate mail, warehouse
What I can tell you with certainty: each of the six systems recorded in the scope returned a dated result, and I keep the query, the time and the volume returned for every one of them.
What I am proposing, and this is where you gain: I compared your scope with your signed processing contracts. Two services handle customer data without appearing among your six — the online review tool and the in-store returns platform. Add them to the scope and the same request becomes eight out of eight. I query them as soon as you record them.
✎ Framework · scope settled from your contracts, not guessed
Four items out of 61 contain a third party: three after-sales exchanges in which another customer is named, and one complaint in which a sales assistant's name appears. I have redacted them reversibly, each with its written reason, and I present them side by side: original version on the left, redacted version on the right.
You lift or you confirm, in four clicks. I never remove an item on my own: a redaction applied silently would be undetectable on review, and that is exactly what an inspection looks at. The work is done; the act that remains is yours, and it takes two minutes. reasoned-redactions_four-items-file-AUR-2026-041.pdf4 reversible redactions, a reason per item, before/after access-extract_file-AUR-2026-041.pdf61 occurrences, 6 dated sources, remedies included
⛓ Sourced · 61 items analysed, 4 carrying an identified third party
File AUR-2026-044 — erasure. The request comes from an address that resembles a customer's: same name, same format as your business addresses. A resemblance between addresses is not an identity. Erasing on that basis means erasing someone else's account — and it is irreversible.
File AUR-2026-046 — access. Two accounts carry the same name and the same town. I am not merging them, and I am not choosing between them: replying on the wrong account would disclose a third party's purchases to someone with no right to them.
What I have prepared for both: the message that lifts the doubt, calibrated to the minimum necessary. identity-protocol_two-files-pending.pdfItems requested, items set aside, short retention period
⛓ Sourced · privacy portal, loyalty CRM
Article 12(6) GDPR allows you to request “additional information necessary to confirm the identity of the data subject” where there are “reasonable doubts”. The text speaks of necessary information, not of the heaviest document available.
What I propose instead, file by file: for AUR-2026-044, the order number of a purchase the person is bound to know — you already hold it, and you add nothing to your database. For AUR-2026-046, the last four digits of the payment method, which separate the two namesakes in a single reply.
Across your 47 files from last year, this method would have lifted the doubt in 41 cases without collecting a single identity document. For the remaining 6, the document is requested — and I then keep it for a short period, separate from the file, because a copy of an identity card left lying in a compliance file is itself a risk.
✎ Framework · GDPR Art. 12(6) — necessary, proportionate information
That file is your best evidence if a complaint is made: it shows that you handled the request, within the deadline, and that the silence came from the other side. A file closed without a trace shows nothing.
You decide what follows — reasoned closure or a further reminder — and I hand it to you in one screen, with both texts already drafted.
⛓ Sourced · file log, timestamped reminders
Article 33(1) GDPR requires notification “without undue delay and, where feasible, not later than 72 hours after having become aware of it”. The CNIL sets the starting point: the moment the controller has “a reasonable degree of certainty that an incident has occurred and has affected personal data” (our translation of the CNIL’s French guidance).
That date is yours to set, and I record it with the item that grounds it — here the read receipt of the email. I do not guess it: it is what makes the whole timeline enforceable.
Deadline shown: Thursday, 9:14. And it is not a drafting deadline — it is a decision deadline. breach-timeline_incident-AUR-INC-2026-002.pdfEstablished facts, estimates, unknowns — three separate columns
⛓ Sourced · processor's email, read receipt, application logs
What is established: unauthorised access on 3 of the provider's systems, a 41-hour window, an export of delivery files confirmed by their logs.
What is estimated, and announced as such: the order of magnitude of the records exposed, drawn from the size of the export.
What is unknown, and stays so: the exact number of people concerned. I am not writing zero in its place, and I am not writing a reassuring range either — the provider's investigation is open, and a declared unknown is worth more than a figure you will have to retract.
Both notifications are prepared: the initial one, drafted with what is established and what is estimated, and the follow-up, already framed around the unknown named above — together with the item that will ground it the day it arrives. The entry in the internal register of Article 33(5) is made in the same move, because it is always the one that gets lost when it is left for later. What these two texts lack is not a sentence: it is your signature. draft-notification_initial-and-follow-up-AUR-INC-2026-002.pdfInitial notification, framed follow-up, internal register under Art. 33(5)
⛓ Sourced · provider's logs, ITSM, processing contract
What I looked at on your case, and it is a fact, not an opinion: the delivery files carried name, postal address and telephone number, in clear. Encryption at rest covered the database, not the exports — and it is the export that left. The material condition of 34(3)(a) is therefore not met on this scope: I tell you so with the encryption inventory that establishes it, and the assessment remains yours.
The draft communication to data subjects is written, in plain language, with the nature of the breach, the likely consequences and the measures taken. The decision to send it belongs to the controller — and you have it on the table, reasoned, at D+1 of three.
⛓ Sourced · encryption inventory, contents of the export
The three, and why: two were waiting on an identity that never came — they are documented, chased, defensible. The third waited eleven days for a reply from the data warehouse, whose nightly export was failing without alerting anyone. That one is on my side of the fence, and I have fixed it: a source that does not answer within 48 hours now moves to the top of your queue.
What has changed measurably: coverage has gone from “unknown” to six or eight sources out of eight, written on every file. The median handling time is 4 days against 19 before, and above all: you now know what you do not know.
What the quality of these files is worth, measured rather than asserted: all 31 carry their versioned evidence — queries run, sources questioned, replies received, redactions and their reason, exports and acknowledgements. Two files out of 31 have a missing piece of evidence, both on the side of a source that never answered: they are named on the file rather than counted as zero, and that is what makes the steering dashboard defensible before the authority. rights-dashboard_two-months-maison-aurore.pdf31 files, 2 incidents, turnaround, coverage, overruns explained
⛓ Sourced · log of the 31 files, coverage records
· I open the file and date its receipt the moment it arrives through the portal, by email or by post. A clock that starts late is never caught up.
· I chase a silent source at 24 h, then at 48 h. If it answers afterwards, coverage updates on its own — and the reverse is true too: a source that fails again goes back to unknown the same day.
· I move to the top of the queue any file whose deadline falls below five working days, and any breach whose clock falls below 24 hours.
Everything else waits for a decision, and I have written who takes it for each act in the attachment. This is not a list of things I leave aside: it is the map of your mandates, and it changes with a word. mandates-and-acknowledgements_who-decides-what.pdfRoles, reserved acts, mandates proposed, acknowledgements required
✎ Framework · three automatic acts, all reversible
What I propose: automatic sending of the access replies whose identity is established AND which contain no third-party data. Across your 31 files from the last two months, that covers 19 files — the ones that brought you no decision to take and cost you, on average, 26 minutes of review each. That is 8 hours returned over two months, and you would only review the 12 files that deserve your eye.
The mandate is capped and dated: it covers access only, never erasure or portability; it stops at the first item containing a third party; it expires in six months; it is withdrawn with a word.
And it changes nothing about two things, because no mandate can: a notification to the authority goes out under the controller's signature, and no file closes without a verifiable acknowledgement — an attempted send is not a received send. access-sending-mandate_capped-and-dated-draft.pdf19 files out of 31 eligible, cap, expiry, immediate withdrawal
⛓ Sourced · 31 files analysed, 19 eligible, review time recorded
Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit →
Twelve modules in the core, and the extensions quoted separately
The twelve core modules cover the whole chain, from the receipt of a request to the retention of its evidence. Security, traceability, human validation and the demonstrators never leave the core to become options. The three extensions below widen the scope, the volume or the connectivity: they are quoted, and nothing else is added to them.
Receipt and enforceable clock
Opens every request or incident from the portal, email, post, an API or a ticket, and keeps the channel, the date of receipt, the time zone, the acknowledgement and the computed deadline.
Identity, mandate and safe channel
Verifies identity, representation, contact details and reply channel through a proportionate procedure, without collecting more than necessary (GDPR Art. 12(6)).
Qualifying the right invoked
Distinguishes access, copy, rectification, erasure, restriction, objection and portability (Art. 15 to 21), and keeps composite requests, ambiguities and language.
Mapping and scope
Links the request to the record of processing, controllers, processors, applications, archives, backups and retention periods, with visible coverage.
Federated search and collection
Runs bounded searches, deduplicates occurrences, and records queries, sources, dates, failures and partial results.
Review, third parties and redaction
Spots third-party data, secrets and sensitive items, and prepares reversible redactions with their reason, subject to validation.
Response dossier
Assembles the reply, the copy, the portable format, explanations, remedies, items and log, and checks legibility, integrity and recipient.
Personal data breach reporting
Centralises facts, systems, categories, people, volumes, measures and unknowns, without concluding prematurely.
Risk assessment
Applies a versioned likelihood and severity grid, distinguishes risk from high risk, and documents factors, disagreements and unknowns.
Prepared notifications
Timeline, initial or follow-up notification (Art. 33(4)), communication to data subjects and internal register (Art. 33(5)): drafted, dated, sourced, ready to go under your signature.
Deadlines, escalations and acknowledgements
Tracks milestones, reasoned extensions, reminders, approvals, dispatches and acknowledgements, and refuses any closure on a mere send click.
Evidence, quality and steering
Versions sources, rules, decisions, exports, accesses and deletions, and measures coverage, turnaround, reworks, errors and human workload.
Need to go further?
These agents handle a different business process, with their own owner and their own price. They are added to this one.
DPO / GDPR support
The substance of the role — record of processing activities, impact assessments, processor monitoring — belongs to the DPO support agent. This agent only handles dated files: a subject request, a breach. If you already run DPO support, rights and breaches are covered there and are not billed again here.
DPO / GDPR support from 668 € excl. VAT / month Discover the agent →Regulatory control
Applying a rulebook to documents and returning findings is the business of the regulatory control agent. This agent applies rules only to one data subject’s file, and its clock starts from a receipt or from an awareness date.
Regulatory control from 721 € excl. VAT / month Discover the agent →Cybersecurity & logs
Detecting the incident, correlating events and running the technical investigation belong to security monitoring. This agent starts where that stops: at the awareness date you set, and it documents the breach.
Cybersecurity & logs from 601 € excl. VAT / month Discover the agent →In 15 minutes we identify the most relevant agent — without oversizing the project.
Where the time of a file goes, and where it goes back
The effort moves from collection to judgement. The proportions below illustrate that shift; they do not represent any client measurement.
The stages of your AI agent project
Audit & scoping
15 minutes to target the use case with the best return.
Quote or direct sign-up
A catalogue offer is bought online; a specific need gets a costed quote.
Design
We design the agent and its guardrails.
Integration & testing
We connect your tools to the agent, which is itself hosted in France.
Rollout
Going live and training your team.
Operation
Continuous supervision and improvement.
This agent is quoted against your own scope
It cannot be ordered online, and that is deliberate: the real work depends on three things only your organisation knows — how many systems have to be queried, how many entities have to be kept apart, which intake channels have to be connected. The twelve modules and the twelve checks are in the core. The thirty-eight sector variants share this identifier and change the content, never the scope. And if you already run our DPO support agent, say so up front: data subject requests and breaches are covered there and are not billed again here — only a genuine extension of scope, volume, connectivity or service enters the quotation.
Four guarantees that matter on a rights file
Your questions, our answers
Can the agent refuse a request on its own?
How does it prove identity without collecting too much data?
How does it know that every application has answered?
Does it handle third-party data and redactions?
Can it notify the supervisory authority automatically?
How does it compute the one-month and 72-hour deadlines?
What happens when a processor does not reply?
How does it keep proof of the dispatch and of the decision?
Other compliance agents
Let us measure your real turnaround on your last twelve files
15 minutes to map your intake channels, your systems and your deadlines — hosted in France, supervised, no commitment.