The GDPR gives you rights including access, correction, erasure and objection. You can exercise them directly with the organisations holding your information, or authorise a person or organisation to act on your behalf. The European Data Protection Board (EDPB) and national authorities such as France's CNIL provide guidance on how representation works. Here are the practical points.
Exercising rights through an authorised representative
GDPR Article 12 requires data controllers to facilitate the exercise of rights under Articles 15 to 22. You do not necessarily have to manage every request yourself. An appropriately authorised representative can act within the scope of the authority you give them, subject to applicable rules and verification.
An authorisation may cover access, erasure, correction, restriction, portability or objection. Organisations receiving the request, including websites, brokers and directories, should assess it within the applicable rights framework, verifying the authorisation and identity where necessary.
What the EDPB guidance explains
The EDPB published its Guidelines 01/2022 on data subject rights: right of access for consultation in January 2022, adopting the final version in 2023. These explain how controllers should apply Article 15 and facilitate access rights in practice.
The guidelines address requests made through a representative. A controller needs to establish that the third party is authorised to act and that personal data is not disclosed to an unauthorised person. The guidance provides useful context for individuals who delegate requests to a service provider or association.
Read the EDPB Guidelines 01/2022. Their specific subject is the right of access; other rights also require attention to the relevant legal rules.
The CNIL recommendation on authorisation
In June 2021, the CNIL published a recommendation concerning the exercise of rights through a mandate. It explains good practice for representatives acting for individuals and for controllers receiving their requests.
Key points include:
- Scope and form: you expressly authorise a third party to exercise all or specified rights. The CNIL provides a model authorisation.
- Verification: the controller may request evidence of the authorisation and proportionate information needed to verify the individual concerned. Verification may require direct contact with you.
- Deadlines and refusals: the usual response rules still apply, including the normal one-month period and rules for manifestly unfounded or excessive requests.
This offers a practical framework for French services sending erasure or access requests on your behalf. After your free scan, you can authorise Data Knight to send removal requests for the sites and brokers you select.
Why delegate requests?
Acting yourself takes time: identify each controller, locate its privacy contact or form, send the request and follow up. Authorising a specialist organisation can centralise that work. You decide what falls within the authorisation and which data or rights the representative should address.
Data Knight uses this approach: you run a free scan of the public web, brokers and known breaches, give the necessary authorisation, select what to address and confirm the sending of removal requests. Our method explains the scan, authorisation, sending and tracking process. For practical details, read GDPR Article 17, broker follow-ups and CNIL complaints and the digital footprint guide.
Want to request removal without managing every message yourself? Start a free scan, then choose your removal targets and authorise us to send the requests on your behalf.
See also: Personal data rights explained · The right to erasure · Brokers that do not reply · Data brokers and removal



