Upon receipt of Subject access request, the procedure says to ask for 2 forms of ID. How soon do we have to ask this? If we leave it for 29 days, then they pass the ID verification, does 30 day period begin again? Also it says data subject to submit DSAR in prescribed form – which is this?
Assign topic to the user
Expert
Andrei Hanganu
May 23, 2018
Answer:
Checking the identity of the data subject is one of the first steps when dealing with a DSAR so waiting till the last day to confirm the identity of the requester to get the 30 days period “reset” would most likely be considered abusive. So my advice is to check the identity of the requester as soon as possible in he process. Please consult the “Data Subject Access Request Flowchart” which is part of the “ DATA SUBJECT ACCESS REQUEST PROCEDURE” to see how a DSAR flow could look like.
As regards to the form is not a compulsory requirement to use a specific template although is advisable to do so as the requests would be handled much easier and in a consistent way.
To learn more about DSARs check out our webinar “Data Subject Rights under the EU GDPR” (https://advisera.com/eugdpracademy/webinar/data-subject-rights-under-the-eu-gdpr-free-webinar-on-demand/).
Comment as guest or Sign in
May 23, 2018
May 23, 2018
May 23, 2018