Handling Data Principal Rights Requests Under Rule 14
Rule 14 puts a publishing obligation on you before anyone asks for anything. Most organisations do not currently meet it.
The publishing obligation comes first
Rule 14(1) requires the Data Fiduciary, and a Consent Manager where applicable, to prominently publish on its website or app:
- the details of the means by which a Data Principal may make a request to exercise her rights; and
- the particulars, if any, such as a username or other identifier, that may be required to identify her under its terms of service.
This applies whether or not anyone has ever made a request. An organisation with a working internal process but nothing published does not satisfy Rule 14(1).
Grievance redressal has a published period
Rule 14(3) requires every Data Fiduciary and Consent Manager to prominently publish, within a reasonable period not exceeding ninety days, the period within which it will respond under its grievance redressal system. The commitment is yours to set, but publishing it is not optional.
Why this is harder than it reads
Answering a request means finding one individual across every system that holds her data, including the copies. That is the same capability the record of processing exists to support, and it is where most organisations discover their inventory is incomplete.
It also has to work for a person who is not logged in, or who has left, or who used a different email — which is why Rule 14(1)(b) matters.
A rights request is an unannounced audit of your data map, run by a member of the public, with a published deadline you set yourself.
Infosek Team
What to build
- A published route: a form or address, plus the identifier you require.
- A published grievance response period, within the ninety day outer limit Rule 14(3) sets.
- An internal process that reaches every system in the inventory, not only the primary database.
- An identity verification step proportionate to the request.
- A log of requests, what was done and when, since demonstrating compliance is the point.
Common questions
What must a Data Fiduciary publish under Rule 14?
Under Rule 14(1), the Data Fiduciary and, where applicable, the Consent Manager must prominently publish on its website or app the details of the means by which a Data Principal may make a request to exercise her rights, and the particulars such as a username or other identifier that may be required to identify her under its terms of service.
How does a Data Principal make a rights request?
Under Rule 14(2), she may make a request to the Data Fiduciary to whom she previously gave consent, using the means and furnishing the particulars that the Data Fiduciary requires for the exercise of those rights.
Building your rights request process?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment