Aberions

Know who holds your personal data, and what you can lawfully do about it.

Aberions helps individuals and businesses map where their personal data is actually stored, exercise GDPR access and transparency rights, and reduce unnecessary exposure of identity and financial information. Operators, verification vendors and public registers hold far more than most people expect.


About Aberions

Most people underestimate how much is stored about them.

Every account you open leaves records in more places than the service you signed up with. Identity documents pass through verification vendors, payment histories sit with processors and banks, behavioural logs accumulate with the operator, and regulated sectors add supervisory registers on top. Aberions helps you build an accurate picture of that footprint, then decide which rights are worth exercising and in which order.

Advisory areas

Access, transparency, and disciplined data minimisation.

Closed archival folder on a dark desk

Subject access requests under Article 15

The right of access is the most useful tool that most people never use. We help you draft a request that actually gets answered, covering the categories of data held, the purposes of processing, the recipients, the retention periods, the source of the data, and any automated decision-making applied to you. We also help you read the response critically, because incomplete answers are common and the follow-up is where most of the value sits.

Central registers and monitoring systems

Regulated sectors run central systems that record participation, restrictions and deposit activity. Several EU and EEA states operate one: OASIS and LUGAS in Germany, ROFUS in Denmark, Spelpaus.se in Sweden, CRUKS in the Netherlands, RGIAJ in Spain. We explain what your national system records, which authority acts as the controller, how to request insight into your own entry, and what the statutory retention and review periods mean in practice. A registration in one country's system does not automatically apply in another, and the rules for access and review follow the country where the register is kept. The aim is accurate orientation about your data, not promises about outcomes.

Data minimisation and onboarding discipline

Some identity checks are legally required and some are requested only because they are convenient for the provider. We help you tell the difference, prepare the questions worth asking before you upload anything, avoid duplicate document submissions across vendors, and keep your future data footprint smaller than your past one.

Your data footprint

Where your personal data actually sits.

A wall of locked steel deposit boxes in low light

The operator you signed up with

Account records, session and device logs, IP history, communication transcripts, marketing consents, and behavioural profiles built from how you use the service. In regulated sectors this usually also includes risk scoring and internal flags that are never shown to the customer, but which are disclosable to you on request.

The verification and payment chain

Identity documents rarely stay with the company that asked for them. Verification vendors, anti-money-laundering screening services, payment processors and acquiring banks each retain their own copy under their own retention policy. Anti-money-laundering law commonly requires five years of retention, which is why erasure requests for this category are usually refused while marketing data can still be deleted.

Regulators, registers and marketing partners

Supervisory bodies operate central registers, and each is a controller you can approach directly. Separately, most consumer businesses share hashed identifiers with advertising platforms and affiliate networks. That downstream sharing is often the part people are least aware of, and the part an access request is most useful for exposing.

Who we advise

Built for people who need clear, lawful guidance.

01

Individuals

People who want to know what a specific company or authority holds about them, often after an unexpected decision, a breach notification, or a restriction they did not anticipate.

02

Business owners and freelancers

Founders and self-employed professionals who need a defensible approach to the personal data they collect, the vendors they pass it to, and the access requests they must answer as controllers themselves.

03

Cross-border residents

People living or operating across EU markets who need plain-language orientation on which supervisory authority is competent and how national systems interact with GDPR rights.

Realistic expectations

What an access request returns, and what it will not.

A well-drafted Article 15 request usually produces more than people expect: account and transaction histories, categories of recipients, retention schedules, and a description of any automated profiling applied to you. It rarely produces everything on the first attempt. Controllers redact, omit third-party data, and sometimes answer only the easy parts, which is why the follow-up matters as much as the original request.

An open blank folder and a pen on a dark desk at dusk
Stone office facade at dusk

How we work

Measured advice. Clear next steps.

Every engagement begins with your situation, the controllers and systems likely to hold data about you, and the rights available under applicable law. We explain options in plain language, note uncertainties honestly, and leave you with a written outline you can act on, or take to a licensed professional if needed.

  1. Confidential intake of your questions and relevant context
  2. A map of the controllers, vendors and registers likely to hold your data
  3. A written outline of next steps, including when to escalate to a supervisory authority

Our principles

Transparent advice within the law.

We help you

  • Map which companies, vendors and registers are likely to hold data about you
  • Exercise GDPR rights such as access, rectification, objection and portability
  • Reduce unnecessary data sharing where the law allows a lighter approach
  • Prepare a complaint to the competent supervisory authority when a controller does not comply

We do not

  • Assist with unlawful circumvention of regulatory, identity or self-exclusion measures
  • Promise outcomes, removals, or approvals that depend on third parties
  • Replace licensed legal representation where that is required
  • Sell access to restricted services or so-called workarounds

Questions

Frequently asked questions

Short answers to common questions about our advisory work. For case-specific guidance, book a strategy call.

Book a 30-minute strategy call

Share a brief outline of what you need clarity on, for example which company you believe holds your data, an access request that went unanswered, or an onboarding process you are unsure about. A member of our team will respond personally. There is no fee to submit this form.