Skip to content
Audience: DPO / Compliance

Data subject rights (DSR)

Six rights from Articles 15–22, two ways a request can arrive, one statutory deadline, and the places where the app watches it for you — and those where it does not.

Last reviewed:

A patient files a request themselves, in the portal, or by any other route — e-mail, post, telephone, at the front desk. Both routes end in the same record with the same deadline, counted from the date it arrived.

Heltio handles six rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), portability (Art. 20) and objection (Art. 21). The right to information under Article 13 is discharged by the practice's own information notice, and Article 22 does not apply — Heltio takes no decisions by automated means alone.

How to do it

01

The patient files a request in the portal

The Privacy and your data section of the patient portal lists the six rights, each described in plain language with a button: Request a copy, Request a correction, Request deletion, Request restriction, Request a transfer, Object.

Above the form stands the sentence: "We will confirm by e-mail and reply within one month. If the request is complex we may need up to two more months, and we will tell you why." A deletion request adds a warning that the record and the account will disappear irreversibly.

Regardless of any formal request, the patient can take a copy immediately from the Download your data now section — as a file or via Print / Save as PDF.

02

Register a request that arrived outside the portal

In Settings → GDPR & Privacy → Data subject requests click Register a request. The dialog asks for: the patient, the type of request, the channel (E-mail, Post, Telephone, In person), the Date received, and a description of how the requester's identity was verified — that field is mandatory (Art. 12(6)).

The hint under the date says it plainly: "The one-month deadline under Art. 12(3) GDPR runs from this date. Entering a request late does not extend it." A request entered after the deadline is flagged as overdue straight away.

03

Work the request

On the request row you have: Start, Await controller, Extend, Complete, Complete and generate export, Refuse. The statuses on the practice side are Received, In progress, Awaiting controller, Extended, Completed and Refused. The patient sees the same states described in their own terms — Received, Being handled, With the clinic for a decision, Extended, Answered, Not granted.

Extension may be applied once and requires a reason — the patient receives an e-mail with the new deadline and the justification. Refusal also requires a reason; the text reaches the patient together with a notice about the right to complain to the supervisory authority and about the judicial remedy (Art. 12(4)).

04

Hand over the copy

Complete and generate export first creates and stores a redacted copy of the data; if that fails, the request stays open rather than closing without a file. The patient downloads it from the portal over a short-lived link — "The link is valid for a few minutes. Come back here for a fresh one at any time."

If you delivered the copy outside the app, enter its identifier in the field labelled Storage key of a file you delivered yourself — anything there skips automatic generation.

What restriction under Article 18 actually does

Restriction is not an annotation. The patient record gets a marker that blocks writes across the whole application, halts marketing sends, and excludes the patient from the lists of candidates for deletion after the retention period. Reading the records remains possible.

When something does not work

Warning

No acknowledgement was sent — the patient has no e-mail address on file. Confirm the deadline to them another way.

What this means: You are registering a request for a patient with no e-mail address on the record.

What to do: Confirm the deadline in writing and note it on the request. The clock runs regardless of the missing acknowledgement.
Error

Record how you verified the requester's identity.

What this means: The identity-verification field is empty.

What to do: Write down what you checked — for instance that the sender's address matches the record, or that an identity document was shown.
Warning

You already have a pending deletion request.

What this means: The patient has an earlier request of the same kind still open.

What to do: Resolve the first request. The second is not a separate matter, only a repetition of it.

Was this article helpful?