Sign Up

What is 8 + 4?

Have an account? Sign In Now

Sign In

What is 8 + 4?

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

What is 8 + 4?

Have an account? Sign In Now

Please type your username.

Please type your E-Mail.

Please choose an appropriate title for the question so it can be answered easily.
Please choose the appropriate section so the question can be searched easily.

Type the description thoroughly and in details.

What is 8 + 4?

Sign InSign Up

Watercooler by DPOrganizer

Watercooler by DPOrganizer Logo Watercooler by DPOrganizer Logo

Watercooler by DPOrganizer Navigation

Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Categories
    • GDPR
    • Privacy Management
    • Professional Development
    • Software tips and tricks
    • Polls
  • Help
  • About Watercooler
Home/ Questions/Q 6976
Next
In Process
Anonymous
  • 0
Asked: May 21, 20212021-05-21T13:58:27+01:00 2021-05-21T13:58:27+01:00In: GDPR

Rightly.co.uk

  • 0

Hi ,Does anybody have experience with receiving DSARs via their party platforms like rightly.co.uk ?
We are starting to see a significant increase in requests this way.
We are not 100% comfortable sharing the documents via this format. Can we refuse due to the sensitivity of some of the personal data we hold?

  • 6 6 Answers
  • 0 Followers
  • 0
Answer
Share
  • Facebook

    6 Answers

    • Voted
    • Oldest
    • Recent
    1. Stephen Lark

      Stephen Lark

      • 2 Questions
      • 29 Answers
      • 0 Best Answers
      • 26 Points
      View Profile
      Stephen Lark Bronze contributor
      2021-05-25T09:10:16+01:00Added an answer on May 25, 2021 at 9:10 am

      I am DPO for several small/mid size companies and this situation has arisen a few times. I’ve also commented on other questions relating to this issue.

      We have a policy as part of the formal DSAR response process that prohibits the release of personal data to a business entity except in the case of legal representation.

      We simply contact the data subject directly, ask if they requested the DSAR, why they are doing so, any info they are specifically looking for….and then release their data using the contact details we hold on file.

      So far this has proved to be acceptable and has not been challenged.

      • 1
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
    2. Sue3003

      Sue3003

      • 0 Questions
      • 4 Answers
      • 0 Best Answers
      • 4 Points
      View Profile
      Sue3003
      2021-05-26T10:15:54+01:00Added an answer on May 26, 2021 at 10:15 am

      We deal with a significant number of third party requests. We are fortunate in most of the business to use our own secure log in area so we require them to use ours rather than theirs. Where we cannot use this we try to check first with the individual that they have provided a valid LOA but if we are concerned about the recipient/their repository we will always send to the address we hold on file for the individual. Ultimately as the DC we remain responsible for the data until it reaches its destination.

      • 0
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
    3. Simon

      Simon

      • 1 Question
      • 18 Answers
      • 0 Best Answers
      • 19 Points
      View Profile
      Simon Bronze contributor
      2021-05-24T08:34:03+01:00Added an answer on May 24, 2021 at 8:34 am

      As a general rule of thumb if a requestor would like the response via rightly.co.uk, and you’ve informed them of the risks having offered a more secure method (eg. encrypted file share) then that it their reasoned and informed choice.

      I don’t think there would be a legal reason for failing to respond by the method the requester has chosen.

      • 0
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
    4. Dominga Leone

      Dominga Leone

      • 0 Questions
      • 20 Answers
      • 0 Best Answers
      • 21 Points
      View Profile
      Dominga Leone Bronze contributor
      2021-05-23T11:08:21+01:00Added an answer on May 23, 2021 at 11:08 am

      Yes I have dealt with a few requests and send the information to the registered email address that we have on record, rather than through the Rightly platform itself.

      • 0
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
      • Dominga Leone

        Dominga Leone

        • 0 Questions
        • 20 Answers
        • 0 Best Answers
        • 21 Points
        View Profile
        Dominga Leone Bronze contributor
        2021-05-24T11:22:22+01:00Replied to answer on May 24, 2021 at 11:22 am

        To add to Simon’s point, I agree that that there is no legal reason not respond via this service. However I have avoided using this service for various reasons:

        – I am not sure their Privacy notice truly reflects their processing. They say the don’t process special categories but what if the SAR data includes special categories?

        – I don’t want to sign into and utilise a tool that our own security teams have not validated as a secure method to transmit data and with whom our organisation has not done any due diligence and has no contractual agreement. I cannot be sure that interacting with their systems will not impact our wider security.

        – I do not know enough about their diligence on identity verification to ensure it is the right data subject.

        All of the above could be solved with some time and investigation, but whilst these requests remain low volume, it is not my priority to investigate and address my concerns. In time that may change, but for now, I will be responding using our current process.

        • 2
        • Reply
        • Share
          Share
          • Share on Facebook
          • Share on Twitter
          • Share on LinkedIn
        • Chris Roberts

          Chris Roberts

          • 0 Questions
          • 42 Answers
          • 0 Best Answers
          • 42 Points
          View Profile
          Chris Roberts Silver contributor
          2021-05-27T10:48:30+01:00Replied to answer on May 27, 2021 at 10:48 am

          Dominga, Like you until I am convinced any system for sharing the data is suitable for the data being shared then I will always defer to the system I know is secure.

          Great list.

          • 1
          • Reply
          • Share
            Share
            • Share on Facebook
            • Share on Twitter
            • Share on LinkedIn

    Leave an answer
    Cancel reply

    You must login to add an answer.

    What is 8 + 4?

    Forgot Password?

    Sidebar

    Ask A Question

    Trending contributors

    Smurf333

    Smurf333

    • 11 Answers
    Bronze contributor
    Dave_Wylie

    Dave_Wylie

    • 28 Answers
    Bronze contributor
    CRodica

    CRodica

    • 6 Answers
    Rising star contributor
    Atis

    Atis

    • 4 Answers
    Ian G

    Ian G

    • 5 Answers
    Rising star contributor

    Recent questions

    • Ian G

      Revoke.com - new third party portal for customer right requests

      • 0 Answers
    • Anonymous

      Instagram!!

      • 0 Answers
    • Olga

      DPO in EU and UK

      • 1 Answer
    • Smurf333

      DBS scenario with HR retaining excessive information for longer than ...

      • 0 Answers
    • CRodica

      Parties role towards employees data for administrative purposes

      • 0 Answers

    Explore

    • Home
    • Categories
      • GDPR
      • Privacy Management
      • Professional Development
      • Software tips and tricks
      • Polls
    • Help
    • About Watercooler

    Footer

    Your privacy

    • Cookie notice
    • Privacy notice

    Terms and policy

    • Acceptable Use Policy
    • Terms of Use

    © 2021 DPOrganizer. All Rights Reserved. With Love by DPOrganizer.