Deep Dive: Data Subject Rights
A guide to controls and evidence related to data subjects
Written By Micah
What is meant by “Data Subject”?
Any individual that can be directly or indirectly identified by referencing information (data) about them, such as their name, personal numbers, or location data.
GDPR applies to all personal data, which is defined as "any information which is related to an identified or identifiable natural person."
Which frameworks does this concept apply to?
SOC 2 with Privacy
GDPR
ISO 27701
This also applies to any organization that handles, transmit, stores data of individuals
The following are controls related to data subject rights:
Data Collection: Only the minimum necessary data subject information is collected in order to provide the service.
Choice and Consent: The privacy notice describes the choices available to the data subject. Explicit consent is collected prior to an individual completing their registration and when personal information is to be used for a purpose not previously specified. The date and time that consent was collected are retained in the user's record. The privacy notice describes the impact of not providing personal information or withdrawing consent.
Marketing Consent: The organization obtains data subject consent to use PII processed under a contract for the purposes of marketing and advertising. Providing consent is not a condition for receiving the service.
Basis for Transfer of PII: The basis for the transfer of data has been documented and is available to data subjects.
Collection: Reliable Source: Contracts/statements of work and the Privacy Notice outline the lawful basis used to collect any necessary personal information. The source of data not collected directly from data subjects is retained.
Data Pseudonymization: Where required by law, data pseudonymization processes are used to protect data subject data.
Data Rectification Procedure: Procedures are in place to communicate any rectification or erasure of personal data or restriction of processing carried out to each recipient to whom the personal data have been disclosed unless this proves impossible or involves disproportionate effort. Procedures include informing the data subject about recipients if the data subject requests it.
Data Subject: Authenticate: Procedures are in place to authenticate the identity of data subjects who request access to their personal information before they are given access to their personal information. Individuals may access their data by providing valid credentials or information. The procedures include steps to notify the data subject when there is not enough data to identify them.
Erasure of PII: Procedures are in place to erase PII when requested by the data subject. The procedures include the timeline and delivery methods of said erasure, as well as the procedures to inform other controllers of the request for erasure. The organization's responsibilities with respect to exemptions to the data subject right to erasure are documented.
Joint Controller Notification: The Privacy Notice lists all joint controllers and outlines the relevant data subject rights with respect to the joint controllers.
Lawful Basis: The organization has documented which processing activities are necessary for normal operations and has made this available to data subjects. The organization limits the processing of PII to that which is adequate, relevant, and necessary for the identified purposes or to comply with legal obligations.
Data Subject Correction: Procedures are in place for individuals to correct, update, and/or erase their data. If access is denied, the user is informed in writing and provided with options to appeal.
Obligations to PII Principals: Policies, processes, and procedures, are in place to enable compliance with data subject rights requests.
PII Portability: Procedures are in place to transmit PII to another controller, upon data subject request. These procedures include scenarios where the right to erasure has been requested and consideration of the rights of others.
Privacy Notice Updates: The entity provides notice to data subjects before the entity changes its privacy notice or as soon as the privacy notice is changed. The privacy notice is reviewed by management and legal prior to being published.
Re-processing After Restriction: Data subject notification is sent prior to the re-processing of PII after a processing restriction.
Restriction of Processing: Procedures are in place to address data subjects' requests for restriction of processing. The procedures include any exemptions.
Why are these controls important?
Under the General Data Protection Regulation (GDPR) and most privacy regulations, data subject rights refer to the rights of individuals whose personal data is collected, used, or processed by an organization. It is important to have controls in place that address each of these rights:
The right to be informed: Individuals have the right to be informed about how their personal data is being used and what their rights are under GDPR.
Controls: Choice and Consent; Privacy Notice Updates
The right of access: Individuals have the right to request access to their personal data and to be provided with a copy of it.
Control: Data Subject: Authenticate
The right to rectification: Individuals have the right to request that any inaccurate or incomplete personal data be corrected.
Control: Data Subject Correction
The right to erasure: Also known as the "right to be forgotten," this allows individuals to request that their personal data be erased in certain circumstances.
Control: Erasure of PII
The right to restrict processing: Individuals have the right to request that their personal data not be processed in certain circumstances.
Control: Restriction of Processing
The right to data portability: This allows individuals to request a copy of their personal data in a commonly used format, so that it can be transferred to another organization.
Control: PII Portability
The right to object: Individuals have the right to object to the processing of their personal data in certain circumstances, such as for direct marketing purposes.
Control: Marketing Consent
The right to not be subject to automated decision-making: Individuals have the right to request that they not be subject to decisions based solely on automated processing, including profiling.
Control: Restriction of Processing
These rights are intended to give individuals more control over their personal data and to ensure that it is collected, used, and processed in a transparent and fair manner.
Who is involved with these controls?
Typical control owner: Data Privacy Officer
Typical parties involved: Marketing, Database admins, Website admins, IT managers
How often should I perform these controls?
Choice and Consent - Continuous
Others - As Needed
How do I demonstrate these controls?
Public facing Privacy Policy (or Notice) that outlines each of the data subject rights.
Internal policy that outlines the organization’s stance on data subject rights.
Procedures for how to address or handle data subject rights inquiries.
Procedures on how to pull data subject’s data and how to send it to them.
A data dictionary showing which data elements are collected from data subjects
A way to collect the data subject’s consent - this might look like a database field showing the date they accepted the Privacy Policy
A way to show that a data subject has not provided consent to use their data for marketing purposes - this might look like a database field showing the date they opted in or opted out of using their data for marketing.
Questions?
Reach out through our chat feature for real-time Customer Success support 8 am - 5 pm PT Monday through Friday.