Data Subject Access Requests (DSARs): What You Need to Know
When it comes to cookie consent and data privacy laws, Data Subject Access Requests (DSARs) play a big part in keeping your business compliant.
Any individual can submit a DSAR to see where their information is going, has gone, where it was stored, and why. Where the user is located definitely counts. For instance, an end user in Virginia will have lawful rights to receive that information whereas someone in Ohio would not. Whew!
Laws like the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) and the Virginia Consumer Data Protection Act (VCDPA) all give residents of those regions the right to get that information in a timely fashion – typically about thirty to forty days.
If a business does not comply with this, they could be fined or risk their reputation. Many small businesses think they are immune to these laws simply because they do not get many DSARs. That could not be further from the truth. Even one DSAR that gets lost in the shuffle could cost $7,500 at the least.
Reasons for a DSAR
You probably don’t know why someone is submitting a DSAR. It could be because their name changed due to marriage, and they want to ensure all the information is accurate. It could be that they are getting targeted ads on social media. Or, it could be that they are simply curious about what information has been submitted and where it’s gone.
In your response, you can ask questions like:
Why did you submit this DSAR?
Would you like to correct information?
Would you like to delete information?
Have you seen ads you don’t like on social media?
Has your information changed since the last time you filled out a form here?
Did a shop or store ask you a question about something you don’t feel comfortable answering?
This will help you narrow down exactly what you need to provide. It will also help you in the future if your business is audited. Creating a digital trail of exactly what your end users asked for, why, and when you submitted it is key.
Things to Know About Cookie Consent
A cookie consent banner sets the stage for a DSAR. Good consent banners will give end users three options. Accept all cookies, decline all cookies, and manage preferences for cookies. This is where the DSAR comes in. If users want to manage their cookies, they will also be able to request information from you.
A DSAR solution is the second step in becoming globally compliant with data privacy laws worldwide. That’s right – worldwide! Many of these laws are very similar, so they have the same requirements. You need to ask for user consent, then be able to deliver the information to the user if they request it.
DSARs: The Lowdown
A user requests information
You verify what and why the user is requesting – so you can deliver the answer as efficiently as possible
Record the request and the response in case a lawmaker asks you about it later
Only keep the records for the minimum amount of time needed
Have a disposal method for the information you can no longer store
One of the most important parts of these steps is that you take DSARs seriously, respond to them, and do not keep customer information for longer than you absolutely need to. Remember that even end user request as they fill out the form counts as information.
Anything that an end user enters on your website has to be carefully guarded and managed according to the law.
Adzapier is on the way!
Adzapier has a number of different tools. Cookie Consent Management is the first thing, of course! However, even if you have a different cookie consent tool set up, you can use our DSAR Management tool. This will help you keep track of when requests are submitted and how you need to respond, when, and why.
Many businesses are getting fined for non-compliance. It’s not just big businesses, either. In any case, the loss of your good reputation can be a big hit when someone complains that they didn’t receive a DSAR response within a timely fashion.
Our data privacy experts understand the ins and outs. They can get you set up within a few minutes! You won’t have to worry about fines, damaging claims on your reputation, or data that got lost. It happens… we’ve all been there! Plus, we’ll also give you a cookie banner for 14 days. That’s right – you don’t have to pay a dime for this! Figure out if it’s right for your business and go from there. We’re always available to help.

Comments
Post a Comment