Infosek
INFOSEK

Handling Data Principal Rights Requests Under Rule 14

Rule 14 puts a publishing obligation on you before anyone asks for anything. Most organisations do not currently meet it.

Handling Data Principal Rights Requests Under Rule 14

The publishing obligation comes first

Rule 14(1) requires the Data Fiduciary, and a Consent Manager where applicable, to prominently publish on its website or app:

This applies whether or not anyone has ever made a request. An organisation with a working internal process but nothing published does not satisfy Rule 14(1).

Grievance redressal has a published period

Rule 14(3) requires every Data Fiduciary and Consent Manager to prominently publish, within a reasonable period not exceeding ninety days, the period within which it will respond under its grievance redressal system. The commitment is yours to set, but publishing it is not optional.

Why this is harder than it reads

Answering a request means finding one individual across every system that holds her data, including the copies. That is the same capability the record of processing exists to support, and it is where most organisations discover their inventory is incomplete.

It also has to work for a person who is not logged in, or who has left, or who used a different email — which is why Rule 14(1)(b) matters.

A rights request is an unannounced audit of your data map, run by a member of the public, with a published deadline you set yourself.

Infosek Team

What to build

Common questions

What must a Data Fiduciary publish under Rule 14?

Under Rule 14(1), the Data Fiduciary and, where applicable, the Consent Manager must prominently publish on its website or app the details of the means by which a Data Principal may make a request to exercise her rights, and the particulars such as a username or other identifier that may be required to identify her under its terms of service.

How does a Data Principal make a rights request?

Under Rule 14(2), she may make a request to the Data Fiduciary to whom she previously gave consent, using the means and furnishing the particulars that the Data Fiduciary requires for the exercise of those rights.

Building your rights request process?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment