Every contact you publish for GDPR data requests must be easy to use on its own

Kenneth Graupner photo Kenneth Graupner Published 23 Sep 2026 AI drafted 7 min read
Every contact you publish for GDPR data requests must be easy to use on its own

For ten years, Securitas Direct fixed a small sign to the homes and buildings where it installed alarm cameras in Spain. Under the logo it read (my translation): "902 366 366 securitasdirect.es. Images and sounds recorded, right of access and objection at the number shown." A 902 number costs money to call. The Spanish data protection authority (the AEPD) fined the company 100,000 euros for that line and ordered every sign carrying it replaced within twelve months 2. Securitas pointed out that its privacy policy listed a free email address. The regulator's answer was that GDPR Article 12(2) requires a company to make data rights easy to use 1, and that every route the company names has to meet that test on its own 2.

Software products name routes like that sign all the time: the email address, form or settings page that a privacy policy gives for data requests. Under the AEPD's reasoning, a free privacy@ address does not excuse a second route that is hard to use, such as a settings page that only people with an account can reach. And a request that lands in a support inbox, where nobody recognises it, still counts.

What did the Spanish regulator fine Securitas Direct for?

It fined the company for pointing people to a costly phone line as the way to exercise two GDPR rights: seeing the footage held on them (the right of access) and objecting to being recorded (the right to object). The decision dates from 2023 and reached a wider audience in September 2026, when FACUA, the Spanish consumer group that filed the complaint, reported it and the European Data Protection Board (EDPB), the body of all EU data protection authorities, put it on its news page.

The facts, from the AEPD's 71-page resolution 2:

  • The signs. Securitas had been installing them since 2011, and those already on buildings were still there when the complaint arrived in 2021.
  • The defence. Securitas argued the 902 number was never the only route. Its privacy policy listed two free ones: an email address for its data protection officer (DPO) and its postal address.
  • Its own numbers. Asked how requests arrived in the first quarter of 2021, Securitas reported that exactly one had come in through the 902 line. The rest came through the DPO mailbox, other email addresses, sales calls and a free 900 customer line.
  • The contrast. In its advertising, Securitas gave prospective customers that free 900 number to call, not the 902.

Securitas offered the one-request figure as proof that nobody was harmed. The AEPD read the same figure the other way: people avoided the 902 line because it cost money, which showed the sign put them off. It also pointed out that many of the people making requests were not customers, so they had no contract in which to look up another route. And it treated the free sales line as evidence that Securitas knew what a paid number does to callers, which counted towards a higher fine.

The fine rested on the GDPR's duty to make rights easy to use, not on its separate rule that requests be handled free of charge. The AEPD found that rule intact, because none of the 902 call charge went to Securitas 2. What mattered was how hard the route was to use. A paid phone line is one way of making a route hard, and a login wall in front of someone with no account can be another.

Does your legal documentation match what you ship?

Lawcel watches your product changes and flags the moment your terms or privacy policy fall out of sync, then proposes the edits for your team to approve and publish.

Get started

Why did the free email address not save Securitas?

Because the regulator judged each route Securitas offered on its own, and the sign failed.

For people walking past a camera, the sign was the privacy notice 3, and it sent them to a paid number. Spain's data protection act adds that the routes a company offers "must be easily accessible" (my translation), and the AEPD read "routes" in the plural: every route has to be easy to use, not just one of them 2.

That reading leans on Spanish wording. The GDPR itself only says "facilitate", and a regulator in another country could weigh a hard route less harshly if an easy one sits next to it. I would not design for that possibility. The easier plan is to make sure every route you name for a data request passes on its own.

Does a request count if it arrives somewhere you did not ask for it?

Usually, yes. The GDPR sets no form for a rights request, and the EDPB's guidelines on the right of access say a request sent through a contact point the company provided counts, even when the company named a different one as preferred 4.

The guidelines give examples. A company lists a general address (CONTACT@) and a data protection address (QUERIES@) and asks for requests to go to the second. A person writes to the first. That request counts, the company should pass it on internally, and it cannot extend the deadline because the request reached the wrong inbox 4. The EDPB gives the contact details in a privacy policy or a website's legal notice as examples of routes a company has provided.

There is a limit. A request sent to an address that is clearly not meant for it, such as the cleaning staff's email in a gym changing room, does not have to be treated as a request, provided the company has published a proper route 4.

That guidance is written about access requests. Article 12(2) covers every data right, so I would treat a deletion or objection request that reaches a support inbox the same way. The deadline then runs from the day it arrives, and I covered what happens when a company misses it in the fine France's regulator, the CNIL, issued over 166 unanswered deletion requests.

What should a software company check?

If you run a product with EU users, the routes to check are the ones for people whose data you decide about: leads, sign-ups, account admins and users who deleted their accounts. Make every route you name for them easy to use on its own. Under the Spanish reading, a regulator can fine you over the hardest route however good the others are, and I would not bet on a softer reading elsewhere.

People using your customer's account are different when you hold their data on the customer's behalf. Their requests belong to your customer. Your job is to recognise one and pass it on quickly, as your data processing agreement with the customer says.

For your own routes, here is where I would start.

  • List every place you tell people how to use their rights. The privacy policy, the cookie banner, account settings, the help centre, email footers. Each is your version of the Securitas sign.
  • Try each route as someone who is not a paying customer. A lead who filled in a form, or a user who deleted their account. If the only route is "log in and open Settings", or a support chat that only paid plans get, add a monitored email address or a public form.
  • Compare it with your sales route. If booking a demo takes one click and a deletion request takes a login and a support ticket, that is the contrast the AEPD held against Securitas.
  • Make every published inbox forward requests. A request sent to support@ counts from the day it arrives, so whoever reads that inbox needs to recognise one and know where it goes.

These routes change more often than the policy that describes them: a chat widget moves behind a paid plan, a support tool is replaced, and the policy still names the old route. Lawcel, the compliance tool we build, reads each pull request against the legal documents you have published and flags the changes that leave them out of date.

FAQ

You can offer an in-app route and use the login to confirm who is asking. It should not be the only route, because leads and former users have the same rights and no account to log in to.
Usually not, if you hold their data on the customer's behalf. The request belongs to your customer; pass it on quickly and help them answer it, as your data processing agreement says.
Generally yes. The EDPB treats a request sent to a contact point you published as effective, and the one-month deadline does not stretch because it reached the wrong inbox.
One month from receipt under Article 12(3), extendable by two further months given the complexity and number of requests, if you tell the person within the first month.

References

  1. Regulation (EU) 2016/679 (General Data Protection Regulation) - accessed 23 Sep 2026
  2. AEPD, Resolución de procedimiento sancionador PS/00426/2021 (Secúritas Direct España, S.A.U.) - accessed 23 Sep 2026
  3. Ley Orgánica 3/2018 de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD), Article 12 - accessed 23 Sep 2026
  4. EDPB, Guidelines 01/2022 on data subject rights: Right of access, version 2.1 - accessed 23 Sep 2026

About the author

Kenneth Graupner

Kenneth Graupner

Co-founder, Chief Product Officer

Kenneth is Co-founder and CPO at Lawcel. He focuses on product strategy and on shaping workflows so legal, engineering, and GTM teams can ship continuously without treating compliance as a late-stage gate.

  • Product strategy
  • Compliance operations
  • SaaS delivery
GDPR

GDPR gives you one month to answer a deletion request, even if the data is already deleted

On 21 July 2026 the CNIL fined the IT consultancy EXTIA 300,000 euros over deletion requests, mostly because 166 people were never told what had happened to theirs. If you hold data on job applicants, leads or your own users, GDPR Article 12(3) gives you one month to answer, and deleting the data without telling the person does not count as answering.

GDPR

Two days from launch with no privacy policy. Twelve facts have to be true.

Before you publish a Privacy Policy, GDPR Article 13 requires twelve items. Two are close to boilerplate and one is your company's name. The remaining nine are claims about your own product: who you send data to, where it goes, how long you keep it, and what legal basis each purpose rests on. A generator only repeats what you type in, so make the list first.

Drift

Shipping every week? Five changes that put your privacy policy out of date.

Privacy policy drift is a document written once against a product that ships every week. Regulators name five changes users should hear about: reusing data you already hold, moving the contracting entity, changing how people exercise rights, adding a vendor that receives data, and sending data outside the EEA. The first has to be disclosed before you ship, and "check this page for updates" is not enough.

GDPR

If your SaaS imports personal data, list its sources. The 2026 GDPR transparency check asks your customers.

In 2026, 25 European data protection authorities are questioning recruiters, healthcare, finance, marketing and public bodies about their privacy notices. Where data came from a third party, GDPR Article 14 makes them name its source and categories. If your software supplied that data, list what it collects, from where, who receives it and how long it is kept.