Data Subject Rights Request Guide
Data Subject Rights Request Guide
* Gartner, “Market Guide for Subject Rights Request Automation”, Nader Henein, Bart Willemsen, Bernard Woo, 21 February 2020
** Gartner, “Predicts 2020: Embrace Privacy and Overcome Ambiguity to Drive Digital Transformation”, Nader Henein,
Bernard Woo, Bart Willemsen, 14 November 2019
2
Here are just a few of those regulations:
California Consumer Privacy Act (CCPA) — Applies to every for-profit business that does business in California;
collects, shares or sells the personal data of California consumers; and satisfies certain other conditions.
General Data Protection Regulation (GDPR) — Applies to any organization that processes the personal
data of EU residents.
Lei Geral de Proteção de Dados (LGPD) — Applies to any business or organization that processes the
personal data of consumers located in Brazil.
New York Privacy Act (NYPA) (proposed) — If passed in its current version, will apply to companies of
any size that operate in New York, not just for-profit businesses.
These and other laws require companies to satisfy DSARs within a specified time period — securely and
accurately.
3
Data Subject Rights at a Glance
Different regulations establish different rights, but here are the key ones to know about and what they are
named in two of the key laws.
4
The Right to Be Informed (GDPR) or the Right to Notice (CCPA)
Your organization must be transparent and honest about what personal data you collect and what you do with
it. You must have this information available to individuals at any time and especially at the point of collection,
without request from a data subject.
It is no longer needed
It appears online
5
Your organization can deny the erasure if the request violates:
However, if you retain personal data, you must have the subject’s consent for further processing of the data.
Compliance with this requirement often means moving data to another internal IT system.
6
The Right to Opt Out (CCPA)
Data subjects must be given the option to opt out of having their data sold to third parties.
There are three valid reasons for performing automated processing and profiling:
7
Types of Data Subject Requests
Individuals can exercise most of these rights by making a data subject request. DSARs can be grouped into four
categories, according to the rights involved:
8
What DSAR Processing Includes
In most instances, you have 30 to 45 days to respond to each DSAR. The process is often time-consuming and costly:
* Gartner, “Market Guide for Subject Rights Request Automation”, Nader Henein, Bart Willemsen, Bernard Woo, 21 February 2020
Here is a simplified version of the DSAR process, based on the one provided in the Gartner Market Guide for
Subject Rights Request Automation:
Step 1: Step 2:
Request Capture Request Logging
Step 4: Step 3:
Request Prioritization Identity Verification
Step 5: Step 6:
Data Collection Response Validation
Step 7:
Response Communication
9
Step 1 : Request Capture
Unless you give your customers an easy way to submit DSARs, they are likely to use the first company email
address they find. That starts your clock, even though the contact might not be responsible for anything related
to regulatory compliance.
It’s smart to have an online DSAR form, since it helps ensure that requests go to the correct place and contain
all the required information. However, you must offer multiple channels for submitting DSARs, to ensure you
don’t discriminate against any segments, such as people who don’t have access to the internet.
10
Step 5: Data Collection
Collect all records containing the individual’s data, along with the following supplementary documentation:
The recipients (or categories of recipients) with whom you shared the personal data
Advice on any additional rights the user has, such as the right to object to processing or the right to
request erasure or rectification, or to lodge a complaint with a supervisory authority
Where you obtained the data, if it was not directly from the subject
The existence of any automated decision-making that took place using the data
The data collection step is one of the most complicated and labor-intensive of the DSAR process. After all,
organizations collect enormous amounts of data and store it in a variety of places, including email servers,
personal computers, file stores, databases and cloud-based platforms.
Finding the right data in all these mountains of dispersed data sources requires both expertise and access
permissions. Only a limited number of employees have the knowledge and ability to carry out a DSAR search
manually. Fulfilling such requests diverts those employees from their primary tasks, reducing productivity. To
speed up this time-consuming part of the process, you may want to look to automate this step.
11
Automation Is the Key to Scalability
A manual approach is unsustainable. Clearly, automating data collection offers profound savings in both time
and budget.
A simple and clear interface lets non-IT staff, such as employees in the marketing and legal departments,
easily learn and use the tool to process DSAR cases.
The solution automates the discovery and exporting of personal information associated with an
individual.
You can get progress notifications, such as when case status is updated.
Robust data security capabilities help protect sensitive data and mitigate the risk of data exposure or
misuse.
12
Additional Benefits
Moreover, the Netwrix data security platform helps you achieve, maintain and prove compliance with other
aspects of privacy mandates, not just DSARs, and improve security. In particular, the solution helps you:
Pass compliance audits with less effort and expense. Instead of scrambling to collect evidence that
you have the required controls implemented across your environment, simply run predefined reports
mapped to the key provisions of the regulation. Answer ad-hoc questions from auditors easily using
the interactive search.
Improve risk management. The Netwrix platform includes a risk assessment dashboard, so you can
spot security weaknesses at a glance, such as improperly configured systems. You can also automate
remediation workflows, such as automatically moving sensitive data from unsecure location to the
secure one, and revoking excessive permissions to sensitive data before you suffer a breach.
Improve data management. The Netwrix platform enables you to mitigate risks to data throughout
its lifecycle, automate data management processes to reduce costs and boost efficiency, and improve
productivity by keeping valuable content organized and discoverable. In particular, you can discover
and classify data at its creation or ingestion, ensure that critical data is stored securely, and clean up
data that is no longer needed to reduce risk and costs while enhancing user productivity and decision-
making.
In short, the Netwrix data security platform helps you establish a mature privacy posture to ensure security
and regulatory compliance. As a result, you can avoid hefty fines, enhance customer trust and client retention,
reduce costs, and drive business success.
13
Discover more useful information on this topic
Data subject access requests (DSARs): The essentials
CCPA vs GDPR: What GDPR-ready companies need to know about the CCPA
How you can get ready for GDPR audits: GDPR compliance checklist
How you can handle DSAR requests more easily and with less expense
How Netwrix solutions help you achieve and prove GDPR compliance
Read how Promocil ensures GDPR compliance and allocates its security budget more efficiently by accurately
discovering personal information
Read how Horizon Leisure Centers maintains GDPR compliance and saves £80,000 annually
14
About Netwrix
Netwrix is a software company that enables information security and governance professionals to reclaim
control over sensitive, regulated and business-critical data, regardless of where it resides. Over 10,000
organizations worldwide rely on Netwrix solutions to secure sensitive data, realize the full business value of
enterprise content, pass compliance audits with less effort and expense, and increase the productivity of IT
teams and knowledge workers.
Founded in 2006, Netwrix has earned more than 150 industry awards and been named to both the Inc. 5000
and Deloitte Technology Fast 500 lists of the fastest growing companies in the U.S.
Next Steps
One-to-One Demo — schedule a personalized product tour with Netwrix expert: netwrix.com/livedemo
In-Browser Demo — see the unified platform in action, no deployment required: netwrix.com/browser_demo