Data Subject Request After a Cold Email: Response Template and Action Plan
A lawyer asks for the source, the legal basis and your double-opt-in logs. The full response template with placeholders, explained section by section, plus a deadline plan and an escalation plan.
Not legal advice — use at your own risk
This guide describes how a data subject access request works structurally and how a response letter can be built. It is not legal advice, does not replace case-specific review by a qualified lawyer, and creates no attorney-client relationship. The template is a structural pattern, not a vetted legal document: it does not know your facts, your data sources, your processes, or the wording of the letter that landed on your desk.
Use is entirely at your own risk. A badly answered access request can make your position worse, not better. If you have received an actual letter, instruct a lawyer — before you answer.
CegTec is not a law firm and accepts no liability for the use of this material. Note that the legal provisions referenced here are German and EU law; other jurisdictions differ.
What this guide is for
You sent a cold email. Weeks later a letter arrives from a law firm, demanding information on behalf of the person you contacted: source of the data, legal basis, proof of a double opt-in. No injunction demand, no contractual penalty — not yet.
This guide gives you four things:
- a deadline plan, so the answer is not late,
- a response template with placeholders, commented section by section,
- the five mistakes that turn a request into proceedings,
- an escalation plan for the case where a cease-and-desist follows.
Why the letter looks the way it does — and why the three questions serve two different bodies of law — is covered in A Lawyer’s Letter After Your Cold Email. The short version: the GDPR governs whether you were allowed to process the address (Article 6(1)(f), legitimate interest). Section 7(2) No. 2 of the German UWG governs whether the email was allowed to go out — and there it requires prior express consent, for which legitimate interest is no substitute.
Step 1: The first 24 hours
Do not answer immediately. There is no advantage in speed and considerable risk in a reply typed out of the inbox.
Do five things instead:
- Record the date of receipt. Not the letter’s date. The clock starts when it reaches you; note the date and channel (email, post, fax) and keep proof of delivery.
- Pull and freeze the record. Everything you hold on this address: when collected, from which source, which search or dataset, which enrichment steps, which sends at which times. Document changes to this record from now on rather than overwriting them.
- Stop sending to this address. Suppression list, immediately — and verify it cannot re-enter through the next sourcing run. Another email after the letter arrives is the most expensive avoidable mistake there is.
- Instruct a lawyer. Before the answer goes out. Asking after you have sent costs more in repair than the review would have cost.
- Open a case file. The letter, proof of receipt, the record export, your draft, the legal feedback, the letter as sent. If this escalates, that file is your foundation.
Step 2: The deadline plan
| What | When | Basis |
|---|---|---|
| Response to the data subject | without undue delay, at the latest 1 month after receipt | Art. 12(3) GDPR |
| Notify extension (complex requests) | within the first month, with reasons | Art. 12(3) GDPR |
| Maximum total period with extension | 1 + 2 = 3 months | Art. 12(3) GDPR |
| Erasure/suppression after objection | without undue delay | Art. 21 GDPR |
Two things regularly go wrong here. The clock is counted from the letter’s date instead of from receipt — with law firm post that can be several days, and they count against you. And the extension is taken silently instead of being communicated and justified within the first month. An unnotified extension is not an extension.
A late or absent response is a separate infringement with its own complaint route to the supervisory authority. One question becomes two proceedings — regardless of how the first one ends.
Step 3: The response template
Everything in square brackets is a placeholder and must be adapted to your facts. The bracketed notes in capitals are instructions to you, not part of the letter. If your correspondence is in German, write the letter in German — this is the English rendering of the same structure.
[Your Company]
[Street and number]
[Postcode] [City]
By email to: [law firm's email address]
[Name of the law firm]
[Street and number]
[Postcode] [City]
[City], [Date]
Your letter of [date of the letter] (your reference: [file reference])
Dear Sirs,
thank you for your letter of [date of the letter] on behalf of your client.
I. Your client's request
We understand your client's request to be an assertion of their right to
confirmation and access with regard to the following specific questions raised
in your letter:
"[Verbatim quote of the first question — source of the data]
[Verbatim quote of the second question — legal basis]
[Verbatim quote of the third question — proof / double opt-in]"
Please let us know if we have misunderstood your client's request.
II. Response to the above request
We answer your client's specific questions (section I) as follows:
We can confirm that we have processed an email address relating to your
client. The email address originates from [SPECIFIC SOURCE — the actual
technical process: which source, which search or which dataset, at what
point in time].
We processed the email address exclusively for the purpose of direct business
outreach on the basis of our legitimate interest in the B2B context. Our
legitimate interest lay in [SPECIFIC PURPOSE — e.g. initiating a business
cooperation].
[ONLY IF APPLICABLE:] No data was collected by way of a double-opt-in
procedure. Log data within the meaning of your request therefore does not
exist by design.
Your client's data has [in the meantime been erased / been added to our
suppression list in order to exclude any further outreach]. No further contact
will take place.
Should you have any questions or further concerns, please do not hesitate to
contact us.
Yours faithfully
[Name]
[Position]
Why the template is built this way
Section I reflects the request back, verbatim. That has two effects. It bounds the subject matter of the disclosure to what was actually asked — and, through the invitation to correct, it makes transparent what you are answering. Paraphrasing the questions instead of quoting them opens the door to the accusation that you answered past the question.
Confirmation comes before the answer. Article 15 GDPR starts with the right to obtain confirmation as to whether data is being processed at all. Sidestepping that confirmation gains nothing and costs credibility for everything that follows.
The source has to become specific. This is the placeholder where most templates fail, because the information does not exist. Article 15(1)(g) GDPR requires “all available information as to their source” — available means: what you hold. Anyone who documented nothing has nothing available and has to write that. It is uncomfortable, but it is the truth, and the alternative is an inaccurate disclosure.
State the purpose and legal basis as you actually relied on them. Not as they sound best. A legal basis you never applied in practice will not survive the first follow-up question.
The double-opt-in sentence is conditional. It belongs in the letter only if there genuinely was no consent. If there was, the log data belongs enclosed. What belongs in no version: an asserted consent without proof, or promised log data that does not exist. Both are verifiable, and they will be verified.
The letter stays with the processing. Whether the sending was permissible under Section 7 UWG is not the subject of an Article 15 access request. That question does not belong in this letter — and a volunteered self-assessment on it belongs there even less. You answer what was asked, fully and truthfully. You supply nothing that was not asked.
Step 4: The five mistakes
- Answering from the sending inbox. The answer comes from a named responsible person, not from the mailbox that sent the campaign. Anything else signals that no process exists.
- Asserting a consent that never happened. That turns a data protection question into a question about the accuracy of your disclosure — with an entirely different exposure.
- Continuing to send after receipt. If another email goes to the same address after the letter arrives, the question of intent stops being theoretical. Suppression list first, answer second.
- Counting the deadline from the letter’s date. It runs from receipt. And an extension not communicated within the first month does not exist.
- Arguing unprompted. An access request is not an occasion to defend the lawfulness of your outbound. Every sentence on competition law you volunteer is a sentence you will later have to explain.
Step 5: If a cease-and-desist follows
The case you are preparing for: instead of a follow-up question, your answer is met with a demand to cease, a pre-drafted undertaking, a contractual penalty promise and a costs note.
What applies then:
- The deadlines are short and real. They run in days, not weeks. An extension is possible but must be requested before expiry.
- Do not sign the pre-drafted undertaking. It is routinely drafted wider than the conduct complained of and operates indefinitely with a contractual penalty. Whether a modified undertaking makes sense is a decision for your lawyer, not for a template.
- Your answer to the access request is now on the record. That is why step 3 has to be done carefully: what stands there stands in the file later.
- The incident deserves a review. Which source, which sourcing run, which campaign — and what gets changed systematically so the same path does not lead there a second time.
Risk, cost ranges and the response steps in detail are in Cease-and-Desist for Cold Outreach: Risk, Costs and the Right Response.
Step 6: The preparation that happens beforehand
The question “from which specific source?” is not decided when you answer but when you source — months earlier. Four things you can set up independently of any letter:
- Record provenance per contact. Source, timestamp, technical process, search term or dataset — on the row, not in a separate log that is lost at the next export.
- A suppression list that holds. An address that has once objected must not come back through a new sourcing run. Verify that rather than assuming it.
- A named point of contact. One address and one person for data subject requests, not hanging off the sending operation.
- A response path that already exists. Anyone who builds the template under deadline pressure builds it badly.
This provenance documentation is exactly why, in GTM Goat, it sits on the cell where the data point originated rather than in a side log: a disclosure you cannot give is a compliance problem that only becomes visible when it matters. The four-week free trial shows it in your own data model.
Again, because it matters: this is not legal advice but a structural pattern. The template does not know your case. Use at your own risk — and with an actual letter in hand, go to the lawyer first, not to the template.