Skip to content

Task guide

Data subject requests

Log, verify, locate and answer a request under the Data Protection Act, 2012 (Act 843), within the firm's time, with every step on the record.

A person whose data the firm holds may ask to see it, correct it, take it elsewhere or have it erased. Each request is logged, answered within the firm's time, and kept for good.

Log the request

  1. Open Settings, Compliance, Data requests and choose New request.
  2. Record who asked, what kind of request it is, and the day it arrived. The due day follows from the firm's setting.
The register of data subject requests with each one's due day.
The register of data subject requests with each one's due day.

Verify, then locate

Nothing is searched until the requester's identity is verified. Then the system locates their data across every kind of record: the party, its KYC, conflict checks, matters, documents, mail, notifications and the audit trail.

Decide per kind of record

For each kind of record the system proposes what the law allows, with the reason:

  • Erase what may go, such as notes about the person.
  • Pseudonymise the party record where other records must still point at it.
  • Retain what the Anti-Money Laundering Act, the audit trail or a matter file requires the firm to keep.

Answer and close

Draft the answer to the requester from the request, send it, and close the request. A closed request is permanent.

Was this helpful?