Data Subject Management
Managing your Data Subjects from "Cradle to Grave" is an essential element of Data Protection - it also presents one of the largest challenges to just about all businesses. Using our unique features to track and trace Data Subjects from the moment you develop the strategy to gather them, such as trade shows, web subscriptions, etc. right through to the eventual disposal based on record management principles. The GDPMS will tell you where they are and what their data has been used for - essential information to effectively manage Data Subject Requests.
Singularly one of the most complex achievements of any business will be knowing where it's Data Subjects have come from, what processes they are part of and how each data subject is classified. Not withstanding the fact that Data Protection Laws mostly operate retrospectively, that is, you must be able to demonstrate when a Data Subject gave you consent, or what the legitimacy of processing is, but you must also provide evidence of such consent, for all Data Subjects regardless of when they became Data Subjects.
Couple this, with the various "Rights of Data Subjects". There are more regions than the EU that have extra-territorial reach. So running foul of a regulator regarding a Data Subjects rights is in most cases deemed one of the more serious "harms" that a Data Subject may suffer.
You must know exactly what process you obtained the Personal Data of a Data Subject, when and where you came about the Personal Data and what you have done with that Personal Data since you acquired it.
Thankfully, the GDPMS provides all the tools to allow you to perform the initial audit to identify these locations and pockets of Personal Data, it allows you to identify the applications and processes in play on the Personal Data, and allows you to create the appropriate flows with checks and balances to ensure that the collection, process and use are all legitimate, legal and recorded.
Once that operation is complete, the tools include the generation of appropriate "Collection Notices" both at the time of Personal Data collection and retrospectively (seeking consent again) if there is no clear evidence of original consent discovered.
Form this point you will be able to simply and effectively interest with your Data Subjects and allow them to exercise their rights appropriately based on the means and method of acquisition and the processes and purposes for Personal Data use - in a controlled manner.
Each Data Subject that makes a Data Subject Request (DSR) will also launch a workflow process to ensure that the information or request is managed within the time frame allocated by the appropriate laws relevant to the Data Subject and their region. This includes the business involvement in locating or providing the appropriate personal data in response. There are rules for automatically seeking to confirm the identity of the data subject, and a timer to ensure that any delays caused by the data subject waiting on responses, is recorded and becomes part of the process and sequence of recorded events associated with the request.
With more than 20 automated templates ready to spring into action and a fully automated process that addresses each data subject concern in a systematic manner, ensures that you will be able to effectively manage your data subject requests as and when they make them in a timely and professional manner, regardless of the volume.
To top this superb functionality off, there is a fee register and Data Subject Request History register, that ensures that multiple Data Subject Requests are billable to compensate for administrative overhead in dealing with each request.
Our pool of qualified vDPOs are ready to assist you deal with and manage large volumes of Data Subject Requests if you require assistance. We can also provide advise and support regarding new laws that are enacted in regions that your business operates.