- Help centre
- Clients and intake
Task guide
Data subject requests
Log, verify, locate and answer a request under the Data Protection Act, 2012 (Act 843), within the firm's time, with every step on the record.
A person whose data the firm holds may ask to see it, correct it, take it elsewhere or have it erased. Each request is logged, answered within the firm's time, and kept for good.
Log the request
- Open Settings, Compliance, Data requests and choose New request.
- Record who asked, what kind of request it is, and the day it arrived. The due day follows from the firm's setting.

Verify, then locate
Nothing is searched until the requester's identity is verified. Then the system locates their data across every kind of record: the party, its KYC, conflict checks, matters, documents, mail, notifications and the audit trail.
Decide per kind of record
For each kind of record the system proposes what the law allows, with the reason:
- Erase what may go, such as notes about the person.
- Pseudonymise the party record where other records must still point at it.
- Retain what the Anti-Money Laundering Act, the audit trail or a matter file requires the firm to keep.
Answer and close
Draft the answer to the requester from the request, send it, and close the request. A closed request is permanent.
Was this helpful?
Read next
- The audit trailEvery change, and every view of confidential material, is written down with who, what and when, in a record no one can edit.
- Retention and legal holdsHow long the firm keeps each class of record, the nightly review list, two person destruction, and holds that stop it.
- Add a party and keep the register cleanAdd a person or an organisation once, see possible duplicates before saving, and merge two records that turn out to be the same.
