Skip to content
Docavra

Task guide

Data subject requests

Log, verify, locate and answer a request under the Data Protection Act, 2012 (Act 843), within the firm's time, with every step on the record.

A person whose data the firm holds may ask to see it, correct it, take it elsewhere or have it erased. Each request is logged, answered within the firm's time, and kept for good.

Log the request

  1. Open Compliance, Data requests and choose Record request.
  2. Choose the Request, give the Requester and their Contact, and where they are already a party, who they are On the register as.
  3. Give the day it was Received on and any Notes, and record it. The due day follows from the firm's setting.

Recording it also sets a task, Answer data subject request with its reference, due on that day. It goes to the person named under Settings, General, Compliance, Data subject requests go to; with nobody named, it goes to the firm's only person who handles requests, or stays unassigned for a partner to hand out where several do. Answering the request completes the task and refusing it cancels it. The Task line in the request's Standing opens it.

The register of data subject requests with each one's due day.
The register of data subject requests with each one's due day.

Verify, then locate

Nothing is searched until the requester's identity is verified. Choose Verify identity, say how under Verified by, and choose Record verification. Then Locate records finds their data across every kind of record: the party, its KYC, conflict checks, notifications and the audit trail, and also:

  • every matter they stand on, in any role;
  • the documents filed on their party record or on the matters they are a client of;
  • the emails filed that were sent from, to or copied to any of their email addresses, and the calls, meetings and letters on any matter they took part in;
  • the bills made out to them.

Each is counted with what may happen to it and why. Matters, documents, correspondence and bills are kept, because the matter file and the firm's financial records have their own retention periods.

Decide per kind of record

Under Records located, each class of record carries the system's determination of what the law allows, with the reason:

  • Erasable: what may go, such as notes about the person.
  • Pseudonymise: the party record where other records must still point at it.
  • Retained: what the Anti-Money Laundering Act, the audit trail or a matter file requires the firm to keep.

On an erasure request, Apply erasure names the classes that will go and asks before it acts; Erase and pseudonymise carries it out. Actions taken lists each step done.

Answer and close

Choose Draft response. The Answer is drafted from what was located and determined; edit it before it goes. Choose the Outcome, Responded or Refused with the reason in the answer, then Send and close. A closed request is permanent.

Was this helpful?