Sign Up

What is 8 + 4?

Have an account? Sign In Now

Sign In

What is 8 + 4?

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

What is 8 + 4?

Have an account? Sign In Now

Please type your username.

Please type your E-Mail.

Please choose an appropriate title for the question so it can be answered easily.
Please choose the appropriate section so the question can be searched easily.

Type the description thoroughly and in details.

What is 8 + 4?

Sign InSign Up

Watercooler by DPOrganizer

Watercooler by DPOrganizer Logo Watercooler by DPOrganizer Logo

Watercooler by DPOrganizer Navigation

Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Categories
    • GDPR
    • Privacy Management
    • Professional Development
    • Software tips and tricks
    • Polls
  • Help
  • About Watercooler
Home/ Questions/Q 6529
Next
In Process
PGustavsson
PGustavsson

PGustavsson

  • 1 Question
  • 2 Answers
  • 0 Best Answers
  • 0 Points
View Profile
  • 0
Asked: April 26, 20212021-04-26T13:01:36+01:00 2021-04-26T13:01:36+01:00In: GDPR, Privacy Management

Deletion requests facilitated by a third party

  • 0

Hi,

Does anyone have any experience dealing with companies like https://saymine.co/? They send data deletion requests from individual’s private e-mail addresses, but the e-mails are labelled “powered by Mine” and there are some indications that their service includes getting access to the registered individual’s entire inbox and then sending request to any company they find. In short, how can we verify that the request has in fact been made by the person they claim to be representing? Replying to the e-mail won’t due if they have access to the inbox.

  • 7 7 Answers
  • 0 Followers
  • 0
Answer
Share
  • Facebook

    7 Answers

    • Voted
    • Oldest
    • Recent
    1. Ian G

      Ian G

      • 1 Question
      • 5 Answers
      • 0 Best Answers
      • 5 Points
      View Profile
      Ian G Rising star contributor
      2021-05-26T09:28:13+01:00Added an answer on May 26, 2021 at 9:28 am

      Just adding to this thread as we receive waves of these erasure requests from Saymine (generating probably around 95% of all our total erasure requests). We can get 40 one weekend and then 1 or 2 over the next few weeks. Given the random times day and night the requests come in I believe the emails are sent via saymine servers who seem to have peaks and lulls in activity.

      Our approach is we contact the individual directly as the email address is included in the request to get them to confirm they raised the request, around 80%+ do not come back to us to confirm this, so we don’t process their erasure request further.

      I think the ICOs approach on these would be if the request includes the individuals email address reach out to them, but your under no obligation to sign up to the third party portal as an earlier comment mentioned

      • 0
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
      • PGustavsson

        PGustavsson

        • 1 Question
        • 2 Answers
        • 0 Best Answers
        • 0 Points
        View Profile
        PGustavsson
        2021-06-03T07:51:09+01:00Replied to answer on June 3, 2021 at 7:51 am

        Thanks Ian, that’s the approach we’ve been taking as well.

        • 0
        • Reply
        • Share
          Share
          • Share on Facebook
          • Share on Twitter
          • Share on LinkedIn
    2. Stephen Lark

      Stephen Lark

      • 2 Questions
      • 29 Answers
      • 0 Best Answers
      • 26 Points
      View Profile
      Stephen Lark Bronze contributor
      2021-04-27T15:08:04+01:00Added an answer on April 27, 2021 at 3:08 pm

      As these are third party companies seeking to profit I always refuse requests based on automated collecting of data by controllers and processors – ie email scanning.

      I recommend that you wait for Mine, or whomever, to contact you and then explain you only accept requests from the individual directly and upon further verification such as letter to a physical address and/or phone call.

      Just keep a record of the refusals and the reason. If it’s important the data subject will contact you themselves.

      • 0
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
    3. Yorkie82

      Yorkie82

      • 0 Questions
      • 19 Answers
      • 0 Best Answers
      • 19 Points
      View Profile
      Yorkie82 Bronze contributor
      2021-04-27T12:23:21+01:00Added an answer on April 27, 2021 at 12:23 pm

      We normally deal with deletion request quite straight forward and use the data provided and the fact that it comes from the registered email address as sufficient proof to delete the account.
      For SARs we request further ID verification and just communicate with them through their registered email address, not through the portals of the provider.

      • 0
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
    4. Dean

      Dean

      • 0 Questions
      • 41 Answers
      • 0 Best Answers
      • 41 Points
      View Profile
      Dean Silver contributor
      2021-04-26T17:11:20+01:00Added an answer on April 26, 2021 at 5:11 pm

      So, to your point, you’re absolutely right in your understanding of how the platform works, and you’re very right to be concerned about having assurance over the legitimacy of the requests. From my understanding there are some disagreements on the identity verification technology/protocols that the Mine platform uses and of course, disclosing or deleting data without appropriate authorisation gets us into hot water.

      You may choose to take a punt and try and verify the legitimacy of the request, or you may choose to take a more risk-based approach and either contact Mine or Privacy Bee and others to try and verify the requests or ignore them and instead respond to an individual directly.
      My understanding is that these tools are free, well nothing is truly free, so how are they funded, makes you wonder, are we the product again.

      • 0
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
    5. Dean

      Dean

      • 0 Questions
      • 41 Answers
      • 0 Best Answers
      • 41 Points
      View Profile
      Dean Silver contributor
      2021-04-26T17:04:48+01:00Added an answer on April 26, 2021 at 5:04 pm

      There is a fair amount of controversy around the use of third-party SAR portals, like for example saymine. It works by an individual signing up on the Mine website, and granting access to their email account. The Mine tool then scans all of the contents and depending on the access level that someone grants to Mine, it will then send off requests to all the companies.

      In the UK, the ICO has issued guidance around subject access requests and they have advised that organisations are under no obligation to take proactive steps to determine if a SAR has been requested. This would indicate that there is no obligation to sign up to Mine to determine if a SAR has been logged. This link might help: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/right-of-access/how-do-we-recognise-a-subject-access-request-sar/#portal

      • 0
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
      • PGustavsson

        PGustavsson

        • 1 Question
        • 2 Answers
        • 0 Best Answers
        • 0 Points
        View Profile
        PGustavsson
        2021-04-27T08:03:37+01:00Replied to answer on April 27, 2021 at 8:03 am

        Great, thanks Dean!

        • 0
        • Reply
        • Share
          Share
          • Share on Facebook
          • Share on Twitter
          • Share on LinkedIn

    Leave an answer
    Cancel reply

    You must login to add an answer.

    What is 8 + 4?

    Forgot Password?

    Sidebar

    Ask A Question

    Trending contributors

    Smurf333

    Smurf333

    • 11 Answers
    Bronze contributor
    Dave_Wylie

    Dave_Wylie

    • 28 Answers
    Bronze contributor
    CRodica

    CRodica

    • 6 Answers
    Rising star contributor
    Atis

    Atis

    • 4 Answers
    Ian G

    Ian G

    • 5 Answers
    Rising star contributor

    Recent questions

    • Ian G

      Revoke.com - new third party portal for customer right requests

      • 0 Answers
    • Anonymous

      Instagram!!

      • 0 Answers
    • Olga

      DPO in EU and UK

      • 1 Answer
    • Smurf333

      DBS scenario with HR retaining excessive information for longer than ...

      • 0 Answers
    • CRodica

      Parties role towards employees data for administrative purposes

      • 0 Answers

    Explore

    • Home
    • Categories
      • GDPR
      • Privacy Management
      • Professional Development
      • Software tips and tricks
      • Polls
    • Help
    • About Watercooler

    Footer

    Your privacy

    • Cookie notice
    • Privacy notice

    Terms and policy

    • Acceptable Use Policy
    • Terms of Use

    © 2021 DPOrganizer. All Rights Reserved. With Love by DPOrganizer.