LGPD: Why provide a form for Data Subject Requests?

Estimated reading time: 2 minutes

Summary

If you have a company, website, or platform that uses customer and user data, be aware that they have rights over this information. Data subjects, as they are called in the General Data Protection Law (LGPD), can request changes, portability, and deletion of their information from your business's databases.

What are the rights of data subjects?

To find out if there is a treatment: A person can contact your company to confirm whether or not they are being stored data. Following this request, the institution has 15 days to respond, stating whether or not the data is being processed, the origin of the data, the criteria used, and the purpose of storing the information.

Accessing data about themselves: This right is guaranteed by Article 18 of the LGPD (Brazilian General Data Protection Law). The law ensures the data subject the right to obtain a copy of their personal data that is processed by a company of which they are a client. 

Correction and modification of data: When the account holder wishes to maintain a relationship with the company, they may want to correct outdated information. This can happen with changes in phone number, address, employment, among others, and this right is guaranteed by law. 

Anonymization or deletion of information: Citizens have the right to request that their data be anonymized, or that the company block or delete their information. This can occur when the data is unnecessary for the purpose justifying its processing, when it is excessive in relation to what is necessary, or when the processing is not justifiable by any legal basis.

Data portability: The data subject has the right to request the portability of their personal data to another provider. This information must be transferred in a structured format, in common and widely used language. It is essential that this data is usable and well understood by the party receiving the information.

A form streamlines the service process.

Institutions that process personal data need to make it easier for the law to be enforced. Ideally, there should be a form that data subjects can use to make requests regarding their personal data, and this request should fall into the hands of qualified personnel, such as... Data Protection Officer/DPO.

Privacy Tools, a privacy management and data protection platform, developed a module specifically for this purpose, also called DSAR.The feature allows for deadline and order management, provides automated responses, and performs audits of past requests.

It is possible to view a control panel for managing policyholder requests, create customized forms in other languages, generate links for online support with captcha, and validate policyholder identity via email. The DSAR module can also be integrated with customer service automation, Salesforce, and other systems via API.

Start your adaptation today.

In addition to enabling the fulfillment of data subject requests, Privacy Tools offers various solutions for compliance with the LGPD (Brazilian General Data Protection Law). The platform offers Cookie Management for websites, the creation of Privacy Policies, Data Mapping, Blockchain Auditing, and Incident Management, when it is necessary to respond to the ANPD (Brazilian National Data Protection Authority).

By registeringYou can test the tool for free and invest even more in data protection within your company, avoiding penalties and improving your relationship with consumers.

About the Author

Meet the author of this article.

Want to see how Privacy Tools can help your company in practice?

Request a personalized demonstration and see how our solutions adapt to your needs.

Related articles section

Read also