Know who holds your personal data, and what you can lawfully do about it.
Aberions helps individuals and businesses map where their personal data is actually stored, exercise GDPR access and transparency rights, and reduce unnecessary exposure of identity and financial information. Operators, verification vendors and public registers hold far more than most people expect.
About Aberions
Most people underestimate how much is stored about them.
Every account you open leaves records in more places than the service you signed up with. Identity documents pass through verification vendors, payment histories sit with processors and banks, behavioural logs accumulate with the operator, and regulated sectors add supervisory registers on top. Aberions helps you build an accurate picture of that footprint, then decide which rights are worth exercising and in which order.
Advisory areas
Access, transparency, and disciplined data minimisation.
Subject access requests under Article 15
The right of access is the most useful tool that most people never use. We help you draft a request that actually gets answered, covering the categories of data held, the purposes of processing, the recipients, the retention periods, the source of the data, and any automated decision-making applied to you. We also help you read the response critically, because incomplete answers are common and the follow-up is where most of the value sits.
Central registers and monitoring systems
Regulated sectors run central systems that record participation, restrictions and deposit activity. Several EU and EEA states operate one: OASIS and LUGAS in Germany, ROFUS in Denmark, Spelpaus.se in Sweden, CRUKS in the Netherlands, RGIAJ in Spain. We explain what your national system records, which authority acts as the controller, how to request insight into your own entry, and what the statutory retention and review periods mean in practice. A registration in one country's system does not automatically apply in another, and the rules for access and review follow the country where the register is kept. The aim is accurate orientation about your data, not promises about outcomes.
Data minimisation and onboarding discipline
Some identity checks are legally required and some are requested only because they are convenient for the provider. We help you tell the difference, prepare the questions worth asking before you upload anything, avoid duplicate document submissions across vendors, and keep your future data footprint smaller than your past one.
Your data footprint
Where your personal data actually sits.
The operator you signed up with
Account records, session and device logs, IP history, communication transcripts, marketing consents, and behavioural profiles built from how you use the service. In regulated sectors this usually also includes risk scoring and internal flags that are never shown to the customer, but which are disclosable to you on request.
The verification and payment chain
Identity documents rarely stay with the company that asked for them. Verification vendors, anti-money-laundering screening services, payment processors and acquiring banks each retain their own copy under their own retention policy. Anti-money-laundering law commonly requires five years of retention, which is why erasure requests for this category are usually refused while marketing data can still be deleted.
Regulators, registers and marketing partners
Supervisory bodies operate central registers, and each is a controller you can approach directly. Separately, most consumer businesses share hashed identifiers with advertising platforms and affiliate networks. That downstream sharing is often the part people are least aware of, and the part an access request is most useful for exposing.
Who we advise
Built for people who need clear, lawful guidance.
Individuals
People who want to know what a specific company or authority holds about them, often after an unexpected decision, a breach notification, or a restriction they did not anticipate.
Business owners and freelancers
Founders and self-employed professionals who need a defensible approach to the personal data they collect, the vendors they pass it to, and the access requests they must answer as controllers themselves.
Cross-border residents
People living or operating across EU markets who need plain-language orientation on which supervisory authority is competent and how national systems interact with GDPR rights.
Realistic expectations
What an access request returns, and what it will not.
A well-drafted Article 15 request usually produces more than people expect: account and transaction histories, categories of recipients, retention schedules, and a description of any automated profiling applied to you. It rarely produces everything on the first attempt. Controllers redact, omit third-party data, and sometimes answer only the easy parts, which is why the follow-up matters as much as the original request.
How we work
Measured advice. Clear next steps.
Every engagement begins with your situation, the controllers and systems likely to hold data about you, and the rights available under applicable law. We explain options in plain language, note uncertainties honestly, and leave you with a written outline you can act on, or take to a licensed professional if needed.
- Confidential intake of your questions and relevant context
- A map of the controllers, vendors and registers likely to hold your data
- A written outline of next steps, including when to escalate to a supervisory authority
Our principles
Transparent advice within the law.
We help you
- Map which companies, vendors and registers are likely to hold data about you
- Exercise GDPR rights such as access, rectification, objection and portability
- Reduce unnecessary data sharing where the law allows a lighter approach
- Prepare a complaint to the competent supervisory authority when a controller does not comply
We do not
- Assist with unlawful circumvention of regulatory, identity or self-exclusion measures
- Promise outcomes, removals, or approvals that depend on third parties
- Replace licensed legal representation where that is required
- Sell access to restricted services or so-called workarounds
Questions
Frequently asked questions
Short answers to common questions about our advisory work. For case-specific guidance, book a strategy call.
Aberions provides informational consultation on data protection rights and register transparency. Where your matter requires licensed legal representation, we will say so clearly and help you prepare for that conversation.
Nothing, in most cases. A controller must provide the first copy free of charge and respond within one month, extendable by two further months for complex requests. Our fee, where one applies, covers preparing the request and interpreting the response, never the right itself.
No one can guarantee removal, and we do not offer it as a service. What we do explain is what the register records about you, which authority acts as controller, how to request insight into your own entry, and what the statutory review periods mean in practice.
No. We advise on data minimisation and privacy-aware choices within the law. We do not assist with unlawful circumvention of KYC, age, or self-exclusion measures.
Non-response is common, and it is itself a breach of the regulation. The usual next step is a reminder that cites the deadline, followed by a complaint to the competent supervisory authority under Article 77. We help you prepare both and explain which authority is competent in your case.
Our public materials are prepared with readers in Germany, Denmark, Sweden, Spain and the Netherlands in mind. Applicable rules still depend on your individual situation and jurisdiction.
Book a 30-minute strategy call
Share a brief outline of what you need clarity on, for example which company you believe holds your data, an access request that went unanswered, or an onboarding process you are unsure about. A member of our team will respond personally. There is no fee to submit this form.