What a data subject request actually looks like
A prospective or former client emails asking what personal information your firm holds on them, or asking you to correct or delete it. Under POPIA this is a data subject request, and it triggers a formal obligation to respond - not just a courtesy reply.
The three request types and what each requires
| Request type | What it requires |
|---|---|
| Access | Confirm what data is held and provide a copy in an understandable form |
| Correction | Correct or update inaccurate, outdated, or incomplete information |
| Deletion/destruction | Delete data no longer authorised to be retained, unless a legal ground for retention exists (e.g. matter records) |
What most firm websites are missing
There's usually no visible process for submitting one of these requests, no defined internal owner, and no documented response timeline. That means requests land in a general inbox and get handled inconsistently or missed entirely - which is itself a compliance gap the Information Regulator can act on.
Frequently asked questions
Can we refuse a deletion request for an active client matter?
Yes, where a lawful basis for continued retention exists - ongoing engagement, statutory record-keeping, or an unresolved legal claim. The refusal and its basis should be documented and communicated to the requester, not simply ignored.
Does the website need a dedicated form for this?
Not necessarily, but it should clearly state how to make a request (an email address and expected response timeframe) rather than leaving the visitor to guess.