'Most Innovative Startup 2020' by RSA - Watch the pitch video

View More

A Data Subject Access Request (DSAR) is the means by which individuals request that your enterprise discloses what personal data it holds on them and how you use or intend to use it. Submitting DSARs is one of the Data Subject Rights granted to consumers under data privacy laws such as the California Consumer Privacy Act (CCPA) and the European General Data Protection Regulation (GDPR). These laws not only give consumers awareness about their rights over their personal data but also provide the tools necessary to exercise them.

An enterprise served with a DSAR is legally obligated to fulfill these requests within a limited timeframe to avoid non-compliance. This is why automating the processing of DSARs is necessary to respond within the aforementioned timeframe. So, let’s discuss the importance of DSARs, how they differ under CCPA and GDPR, and how your business can cost-effectively prepare for and automatically respond to DSARs, which are likely to increase substantially in a post-CCPA world.

Who Are the Beneficiaries of DSARs?

DSARs give consumers unprecedented control over their personal information stored by organizations, from access to data and requesting information on stored data to requesting information on the data safeguards the organization provides. With CCPA, consumers can request DSARs twice a year at no cost whatsoever.

For businesses, speedy and accurate fulfillment of DSARs substantially boosts their brand image while also ensuring compliance with CCPA regulations. However, some estimates put the cost of the fulfillment of each DSAR could be in the thousands, since it requires data gathering across a multitude of systems, putting them in one place, going through data records and compiling it all in a comprehensive report. Moreover, fulfilling each DSAR can take weeks. This is where a solution based on automation can be a potent weapon.

 

Example of a Data Subject Access Request

DSARs under CCPA vs. GDPR

While both CCPA and GDPR provide consumers with mechanisms to exercise greater control over their data, there are some fundamental differences between how much power a consumer has under each law. Let’s have a look:

 

How to Prepare for DSARs

Many expect that the number of receiving DSARs have increased significantly after CCPA. So let’s explore what is required and how to prepare:

  • Responding to a Data Subject Request

Organizations have 45 days to respond and fulfill a customer’s data subject request, in a transferable electronic format. These obligations may vary depending on the customer’s request and how their information is handled.

  • Manage Deletion Requests

Deletion requests involve not only team members from within the organization, but also all third-party vendors and partners with whom the personal information has been shared.

  • Communicating with the Consumer

CCPA requires the disclosure of rights and communication about DSARs, as does the GDPR. The rights given to consumers under CCPA and GDPR are similar but not identical. This means that organizations will need to change their communication accordingly.

 

Responding to Data Subject Access Requests

The following are the steps required to process and fulfill a DSAR:

  1. Register, log and authenticate DSAR
    Organizations must register data requests, log them in a system of record, and authenticate the user before starting work on their fulfillment, either manually or automatically.
  2. Collect personal information
    For organizations to prepare for DSARs, they will need to discover and categorize the personal data they process and store. This data is often stored on an array of systems within an organization and externally as well. The personal data must also be mapped to the individual owner of that data to facilitate the processing of DSARs. Leveraging a People Data Graph can help streamline this process. The collection of this data must also be done in a safe manner to avoid additional data sprawl which could translate to greater liability.
  3. Review and approve the information
    After gathering the necessary information, organizations need to review the data and make sure it meets the DSAR requirements without disclosing proprietary information or the personal data of any other data subject.
  4. Safely deliver customer information
    The final response must then be delivered to the consumer securely. If a data breach or leakage occurs, it can cost as much as $750 per leaked record.

Here are several risks associated with fulfilling a data subject request you must watch out for:

  • Requesters cannot be trusted without authentication.
  • Managing deadlines is crucial to fulfilling DSARs.
  • Data scanning should be automated, and done in a way that does not replicate copies of the data
  • Data processing should be centralized in a safe workplace to avoid personal data sprawl
  • Consumer responses should be encrypted to avoid data breaches.
  • The activity must be tracked to keep a record for validating compliance
  • Data delivered to the wrong person can be catastrophic.

One important factor to consider is that using traditional means will do more harm than good. For example, using emails to deal with DSARs can be dangerous as the risk of data sprawl increases when sending and receiving data over a system that is not secure. Moving personal information in an unencrypted system increases the risk of data breaches. It takes an average of 196 days for an organization to pick up on a data breach, making it essential for enterprises to fortify and automate their systems to protect themselves from any data breach.

What needs to be included in a DSAR?

When responding to a DSAR, organizations are required to have the following heading in their response:

  • A confirmation that the data subject’s personal data is processed.
  • Access to the data subject’s personal information.
  • State all the lawful basis for processing data.
  • Mention the period, or criteria for which data will be stored.
  • Any relevant information  about how this data has been obtained.
  • Any relevant information about automated decision-making and profiling.
  • The names of any third parties information is shared with.

Key Takeaways

Here are some highlights:

  • DSARs are a mechanism by which consumers request access to their personal information held by organizations such as yours.
  • Responding to these requests presents several operational challenges.
  • Fulfilling DSARs will prove to be especially costly (average cost of $1,400 per each request when fulfilled manually)
  • A comprehensive DSR robotic automation solution can reduce cost and complexity and limit legal liability

Large organizations may have hundreds of millions of records about their consumers, often spread across an array of systems. Sorting this data and creating a data inventory to cope with DSARs is a challenging task that requires organizations to automate their current practices.

At SECURITI.ai, we have solutions that offer robotic automation, machine learning and secure cross-channel collaboration to help your business stay prepared for CCPA.

Next Steps

To learn more about automation and orchestration of data subject requests and how much time you can save, check out the video below or schedule a demo to see it live, in action!

 

Share this

Our Videos

data mapping video thumbnail View More
3:00

Data Mapping Automation

Simplify gathering information, dynamically update your data catalog, and automate assessments and reports

Learn More
View More
02:40

An IT Leader’s Perspective on CCPA

Meet Brian Lillie, Former CPO at Equinix as he discusses the potential challenges of CCPA and how the PrivacyOps framework can be the key to unlocking compliance.

Learn More
Most Innovative Startup 2020 SECURITI.ai View More
03:42

RSA Innovation Sandbox 2020: SECURITI.ai

Watch the 3-minute pitch presented by Rehan Jalil on SECURITI.ai in the RSAC Sandbox Competition

Learn More
CCPA View More
07:10

CCPA Compliance

CCPA protects consumers from mismanagement of their personal data and gives the consumer control over what data is collected, processed, shared or sold.

Learn More
Assessment Automation View More
2:25

Internal Assessment Automation

Audit once and comply with many regulations. Collaborate and track all internal assessments in one place.

Learn More
quinstreet privaci View More
02:44

QuinStreet Case Study

Learn how Quinstreet uses our product to simplify data mapping and automate their workflow to process and respond to CCPA requests.

Learn More

Schrems II Ruling & Resources
Get started for FREE

View