<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Electronic Data Subject Access Requests in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/Electronic-Data-Subject-Access-Requests/m-p/5027#M179</link>
    <description>&lt;P&gt;We've implemented a Customer Portal that covers many of the things people ask us for (hundreds - welcome to local government!), and the SAR is one of them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If we've verified their identity - it's called an "Enhanced Account" we can process a SAR electronically, although I am still debating with the devs the level of security on the site as it's still password authentication only &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yours&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jan 2018 16:36:33 GMT</pubDate>
    <dc:creator>Steve_D</dc:creator>
    <dc:date>2018-01-08T16:36:33Z</dc:date>
    <item>
      <title>Electronic Data Subject Access Requests</title>
      <link>https://community.isc2.org/t5/Privacy/Electronic-Data-Subject-Access-Requests/m-p/4515#M165</link>
      <description>&lt;DIV&gt;&lt;FONT face="Arial" size="3"&gt;Hello All&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Arial" size="3"&gt;I recently watched the recording of the&amp;nbsp;excellent GDPR session from the Secure Summit held recently in London and it got me thinking again about subject access requests (DSAR).&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Arial" size="3"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Arial" size="3"&gt;I would be interested to learn what companies&amp;nbsp;are doing&amp;nbsp;about&amp;nbsp;DSAR, especially in regard to those submitted electronically. If submitted by email, for example, how would the response be sent securely?&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Arial" size="3"&gt;I'd also interested to learn how are people interpreting the ‘where possible’ element of the following two sections of the regulation please?&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;FONT face="times new roman,times" size="3"&gt;Where the data subject makes the request by electronic form means, the information shall be provided by electronic means where possible, unless otherwise requested by the data subject.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="times new roman,times" size="3"&gt;Article 12.3 (part)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;FONT face="times new roman,times" size="3"&gt;Where possible, the controller should be able to provide remote access to a secure system which would provide the data subject with direct access to his or her personal data.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="times new roman,times" size="3"&gt;Recital 63 (part)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have plans to provide a secure portal to allow data subjects to query their own information?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Arial" size="3"&gt;Your thoughts welcomed!&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Arial" size="3"&gt;Thanks for your help&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Arial" size="3"&gt;Andy H&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 21 Dec 2017 16:36:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Electronic-Data-Subject-Access-Requests/m-p/4515#M165</guid>
      <dc:creator>AndrewH</dc:creator>
      <dc:date>2017-12-21T16:36:31Z</dc:date>
    </item>
    <item>
      <title>Re: Electronic Data Subject Access Requests</title>
      <link>https://community.isc2.org/t5/Privacy/Electronic-Data-Subject-Access-Requests/m-p/4525#M166</link>
      <description>&lt;P&gt;Few thoughts, Caveat Emptor IANAL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;UK ICO has a decent at a glance:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-of-access/" target="_self"&gt;https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-of-access/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My opinion you&amp;nbsp;first should&amp;nbsp;contact the submitter to identify them(Government ID please would be best option, enshrined in policy and regularly reviews by the DPO). I'd probably be inclined to do that via a person - Otherwise, well your portal could be used for deep data slurps on subjects without their consent - queue lot's of complications. If&amp;nbsp;the natural person is unwilling/unable to identify themselves and allow you to confirm that then&amp;nbsp;I think it's reasonable to not continue with the SAR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another reason to use People there might be a certain amount of recursion with a portal:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Automated Privacy Notice:&lt;EM&gt; "Please consent to my processing your Personal Data for me to fulfill your SAR, including name, DOB, Age, Adress, Phone number, and a jpeg of your passport "&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Agitated person: &lt;EM&gt;"Grrr, I don't consent to your processing any of my data, because I've heard you are bad people, that's why I'm submitting the SAR!"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If your system already allows you to identify subjects, then I think you're on firmer ground with automation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A strong magnet for submission is good thing I think. Let's say you send me a questionnaire and I fill it in, and I include a SAR in one of the free text boxes and you don't respond to it, the timeline might well elapse and it may well be deemed a breach unless you can prove that the SAR/DPO/Privacy notice was unmissable with every communication. A&amp;nbsp;secure web portal or even App to do this might is&amp;nbsp;a good idea, fulfill the electronic bits but I don't think it can be your only option and you have to have a good fall back plan to use people.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We certainly have plans, but I've not seen that we've implemented anything as yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 11:26:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Electronic-Data-Subject-Access-Requests/m-p/4525#M166</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2017-12-22T11:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: Electronic Data Subject Access Requests</title>
      <link>https://community.isc2.org/t5/Privacy/Electronic-Data-Subject-Access-Requests/m-p/4592#M171</link>
      <description>&lt;P&gt;Thanks for your response Early_Adopter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Think data subject access requests (DSAR) could give rise to some interesting situations come May next year. Especially if some of the speculation I have heard of them being the 'next thing' to follow on from no win no fee PPI claims,&amp;nbsp;with companies offering to carry out DSARs for people, comes true.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Happy New Year to all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andy H&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2017 16:13:58 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Electronic-Data-Subject-Access-Requests/m-p/4592#M171</guid>
      <dc:creator>AndrewH</dc:creator>
      <dc:date>2017-12-27T16:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: Electronic Data Subject Access Requests</title>
      <link>https://community.isc2.org/t5/Privacy/Electronic-Data-Subject-Access-Requests/m-p/4965#M177</link>
      <description>&lt;P&gt;in terms of providing a secure portal to manage SARs I think this is unworkable as being able to provide sufficient confidence on their identification is not always straight forward. In addition to this where the information may not be provided ( a in the case of certain medical information which might cause or lead to further harm) cannot be automated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in supplying the information securely there are a number of secure mail / file share systems such as Egress would meet the requirements additionally the use of MS Onedrive can also provide a similar solution&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2018 09:48:09 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Electronic-Data-Subject-Access-Requests/m-p/4965#M177</guid>
      <dc:creator>Tonydan</dc:creator>
      <dc:date>2018-01-08T09:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: Electronic Data Subject Access Requests</title>
      <link>https://community.isc2.org/t5/Privacy/Electronic-Data-Subject-Access-Requests/m-p/5011#M178</link>
      <description>&lt;P&gt;Thanks Tonydan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would agree with your suggestion that it is not necessarily easy to identify and verify (ID&amp;amp;V) a portal user but wonder if that is sufficient in terms of the regulation for it not to be possible? Certainly the whole ID&amp;amp;V piece is a developing area in private companies and Government with examples such as the GOV.UK Verify. It will be interesting to see how high the ‘where possible’ threshold is set!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the pointer about Egress, I’ll look into it a bit more. However, do you think that email requests could still present the same ID&amp;amp;V challenges as those raised by the use of a portal?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2018 14:42:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Electronic-Data-Subject-Access-Requests/m-p/5011#M178</guid>
      <dc:creator>AndrewH</dc:creator>
      <dc:date>2018-01-08T14:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: Electronic Data Subject Access Requests</title>
      <link>https://community.isc2.org/t5/Privacy/Electronic-Data-Subject-Access-Requests/m-p/5027#M179</link>
      <description>&lt;P&gt;We've implemented a Customer Portal that covers many of the things people ask us for (hundreds - welcome to local government!), and the SAR is one of them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If we've verified their identity - it's called an "Enhanced Account" we can process a SAR electronically, although I am still debating with the devs the level of security on the site as it's still password authentication only &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yours&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2018 16:36:33 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Electronic-Data-Subject-Access-Requests/m-p/5027#M179</guid>
      <dc:creator>Steve_D</dc:creator>
      <dc:date>2018-01-08T16:36:33Z</dc:date>
    </item>
  </channel>
</rss>

