Practical guide

How to draft a formal notice to the data controller with AI

4 min read · Updated June 2026 · Editorial oversight: Avv. Federico Papa

The formal notice (diffida) to the data controller is the essential out-of-court tool to demand compliance with the obligations set forth in Regulation (EU) 2016/679. Pursuant to Art. 12 GDPR, the controller must facilitate the exercise of data subject rights and provide a response without undue delay. This document is used when the controller ignores an access request or continues unlawful processing despite a formal objection. It also serves to document the breach in view of a potential action for damages.

In brief

Drafting a formal notice with AI to the data controller is the out-of-court tool under Art. 12 GDPR to demand compliance with data protection obligations. The document requires identification of the controller and DPO, description of the contested conduct, and citation of legal bases like Articles 12 and 17 GDPR. It must set a compliance deadline, usually one month, and include a warning regarding complaints to the Data Protection Authority and damage claims under Art. 82 GDPR. Transmission via PEC or registered mail provides proof of default for potential litigation.

The steps

  1. 1.

    Identification of the controller and DPO

    The first step consists of precisely identifying the data controller by consulting the privacy notice or public registers. If the organization has appointed a Data Protection Officer (DPO), the communication must also be addressed to the latter to ensure proper internal handling. Accurate identification is essential to avoid objections regarding a lack of passive legal standing. It is also necessary to verify the registered office for proper delivery of the notice.

  2. 2.

    Analytical description of the premises

    It is necessary to set out in detail the relationship between the data subject and the controller, along with the specific contested conduct. The notice must specify whether the violation concerns a failure to respond to a prior request or processing carried out in the absence of an appropriate legal basis. Attaching or referencing documentary evidence of the unaddressed request reinforces the sender's position. This section provides the factual background necessary to legally qualify the breach.

  3. 3.

    Legal framing of the violation

    The notice must explicitly cite Art. 12 GDPR as the statutory basis for the obligation to provide a timely and transparent response. If the request concerns data erasure, Art. 17 GDPR must be invoked, explaining why processing is no longer necessary for the original purposes. Legal references must be precise to demonstrate the rigorous legal basis of the claim. This step converts a generic grievance into a formal legal challenge.

  4. 4.

    Formulation of the notice and deadline

    The document must contain a formal demand to comply within a reasonable deadline, typically one month pursuant to Art. 12 GDPR. The specific requested action must be clearly set out, such as the cessation of commercial communications or the de-indexing of harmful content. Fixing a deadline is essential to put the controller in default for the purpose of potential litigation. Without a precise demand and time limit, the document lacks the efficacy of a formal notice.

  5. 5.

    Warning regarding compensation actions

    The document should state that, in the event of continued inertia, a complaint will be lodged with the Data Protection Authority. Furthermore, explicit reservation must be made to bring a civil action for damages pursuant to Art. 82 GDPR. This warning serves a deterrent function, highlighting the financial liabilities associated with the infringement. Reserving legal remedies distinguishes a formal legal notice as a precursor to litigation.

  6. 6.

    Signature and proof of receipt

    The notice must be signed by the data subject or by counsel provided with a specific power of attorney attached to the document. To ensure legal certainty regarding the delivery date, transmission must occur via PEC (certified email) or registered mail with advice of receipt. Proof of delivery is indispensable to establish the commencement of time limits for lodging a complaint with the Data Protection Authority. Non-traceable transmission would prevent establishing that the recipient was duly put in default.

Legal basis: art. 12 GDPRart. 17 GDPRart. 82 GDPR

The template structure

The standard sections that make up the document. The full template can be opened and completed directly on edit.legal.

  1. Sender

    Identifies the data subject or legal representative sending the formal communication.

  2. Recipient

    Indicates the identifying details of the data controller and any appointed Data Protection Officer (DPO).

  3. Premises

    Sets out the factual background and previous unaddressed requests justifying the formal notice.

  4. Formal Notice

    Contains the demand to cease the unlawful conduct or comply within a reasonable deadline.

  5. Warning

    Formulates the reservation to act before the Data Protection Authority or judicial authority for damages.

  6. Place, date, signature

    Indicates the place, date, and handwritten or digital signature of the sender.

Mistakes to avoid

  • Failure to include the DPO (Data Protection Officer) among the recipients, leading to delays in internal handling.
  • Setting an excessively short deadline that fails to account for the complexity of the request under Art. 12 GDPR.
  • Generic description of the violation without specifying the breached GDPR provision, rendering the document vague.
  • Failure to attach a copy of the applicant's identity document when the notice is not digitally signed.

Frequently asked questions

What is the deadline for the controller's response under Art. 12?

The controller must respond without undue delay and at the latest within one month of receipt, which may be extended by two further months where necessary, taking into account the complexity of the request.

Can damages be requested directly in the formal notice?

Yes, Art. 82 GDPR entitles the data subject to claim compensation for material and non-material damages suffered as a result of the infringement.

Is a lawyer's intervention mandatory to send the formal notice?

No, the data subject may send the notice independently. However, legal assistance is recommended to ensure correct legal framing in view of potential litigation.

Avv. Federico Papa
Editorial oversight: Avv. Federico Papa·ICAM

What edit.legal automates

  • Automatic generation of updated legal citations for Articles 12, 17, and 82 of the GDPR.
  • Intelligent AI-powered editor with variable fields for quick input of Data Controller and DPO details.
  • Search tools to identify Data Protection Authority precedents relevant to the contested violation.

Put edit.legal to the test on actual cases

Try edit.legal for free on an active case. No credit card required.

Try edit.legal for free