Skip to main content

On-demand webinar coming soon...

Press Release

OneTrust Launches First-to-Market Data Subject Access Request (DSAR) Portal

Comprehensive software solution to aid organisations in complying with right to be forgotten (erasure), access, and portability requirements in GDPR

May 07, 2018

OneTrust, a global leader in enterprise privacy management software that supports compliance with data privacy regulations like the EU General Data Protection Regulation (GDPR), today announces the launch of the OneTrust Data Subject Access Request (DSAR) Portal.

Data subjects include customers, employees, or third parties whose personal data can be used, stored, or processed by organisations.

OneTrust’s DSAR Portal is the first to market, allowing data subjects to submit requests directly to organisations that process their data, and allowing organisations to demonstrate compliance and automate record keeping by operationalising the fulfilment of data subject requests.

The enterprise-grade portal is highly scalable, tailorable, multi-lingual, and can be deployed either in the cloud or on-premise to meet global data residency requirements.

The OneTrust DSAR Portal is fully integrated into the comprehensive OneTrust privacy management platform, one of the world’s most prevalent technologies used to support and implement a GDPR-based privacy program.

“The addition of the DSAR Portal to OneTrust’s privacy management platform emphasises OneTrust’s unique position in the market and capability to deliver the most comprehensive, easy-to-use, and well-researched platform,” said OneTrust CEO and Fellow of Information Privacy (FIP), Kabir Barday, CIPP US/E, CIPM, CIPT.

The GDPR goes into effect on 25 May 2018, and outlines distinct data subject rights for EU customers and employees:

  • Article 12: Exercise of the Rights of the Data Subject
  • Article 13 & 14: Right to Be Informed
  • Article 15: Right to Access
  • Article 16: Right to Rectification
  • Article 17: Right to Erasure (“Right to be Forgotten”)
  • Article 18: Right to Restriction of Processing
  • Article 19: Notification Obligation
  • Article 20: Right to Data Portability
  • Article 21: Right to Object to Processing
  • Article 22: Right to Object to Automated Individual Decision Making
  • Article 7(3): Right to Withdraw Consent

These GDPR Articles have also created new operational requirements for organisations to “facilitate” the requests (Art 12(2); Rec 59) both “electronically” (Art 12(1), (3); Rec 59), and within a specified time-period (Art 12(3); Rec 59), through demonstrable record keeping (Art 5; Rec 39) and clear communication (Art 12(1); Rec 58). Thus, international organisations, across size and sector, are significantly transforming their business processes to comply with the new data subject rights obligations.

Non-compliance and infringements of data subject rights triggers the highest tier of administrative fines in the GDPR – up to 4% global revenue, or €20M. Perhaps more concerning is that data subjects are granted the right to seek compensation for damages suffered (Art 82; Rec 146), which is why many regulators and industry experts expect the new regulations to lead to an increased risk of class action law suits and brand/reputation damage if companies fail to properly meet the rights of data subjects.

“As consumers become more aware of data privacy rights around the world, especially under the GDPR, organisations are highly anticipating an increase in the number of data requests,” said Jason Sabourin, OneTrust DSAR Product Management Lead. “The OneTrust DSAR Portal has been developed to meet these new demands based on input from EU regulator-based sources and trusted industry and legal professionals.”

OneTrust’s DSAR Portal gives privacy teams the ability to tailor a branded web form (linked from their privacy policy web page), receive notification of a submitted request, validate the subject’s identity, and file an extension if the one-month deadline is approaching.

The organisation can also access the underlying data inventory and map to fulfil the request, transmit the data to the individual through a secure portal, and generate the proper documentation for evidence in the event of a regulator inquiry.

“OneTrust’s commitment to innovations like the DSAR Portal is backed by our global size and scale, significant investments in R&D, and access to leading sources of insight into how regulators may enforce the GDPR,” Barday continued. “Our ability to execute in the emerging privacy management market is distinctly unique, and we look forward to working in partnership with the industry of privacy professionals to continue delivering practical solutions for complex regulatory requirements.”

Click here to watch a 5 minute video demo of OneTrust’s Data Subject Access Rights Portal.

Register to attend a free local GDPR implementation workshop to learn more about Data Subject Rights in GDPR.

For more information, OneTrust will be hosting an Exclusive Data Subject Access Rights (DSAR) Portal webinar on Thursday, October 26, 11:00am ET / 4:00pm UTC.  Registration is available online

For additional information, or to request a live demo, visit OneTrust.com or email Info@OneTrust.com.

 

About OneTrust

OneTrust’s privacy management software is used by more than 1,500 organisations to comply with data privacy regulations across sectors and jurisdictions, including the EU GDPR and ePrivacy (Cookie Law).

The multi-lingual software is deployed in an EU cloud or on-premise, and is based on a combination of intelligent scanning, regulator guidance-based questionnaires, and automated workflows used together to automatically generate the record keeping required for an organization to demonstrate compliance to regulators and auditors.

OneTrust helps organisations implement GDPR requirements, including: Data Protection by Design, Data Protection Impact Assessments (PIA / DPIA), Vendor Management, Incident and Breach Management, Records of Processing (Data Mapping), Consent Management, ePrivacy Cookie Compliance, Data Subject Access, Portability, and Right to Be Forgotten.

Backed by the founders of Manhattan Associates (NASDAQ: MANH) and AirWatch ($1.54B acq. by VMware), OneTrust is co-headquartered in London, UK and Atlanta, GA with a fast-growing global team of privacy and technology experts surpassing 200 employees.


You may also like

eBook

Privacy Management

Understanding data transfers under the GDPR ebook

In the ebook, we delve into the fallout from Schrems II and explore how organizations based in Europe can best navigate international data transfers under the GDPR.

June 05, 2024

Learn more

Webinar

Privacy Management

Navigating data privacy in 2024: Global regulatory updates & compliance strategies

Join our webinar for a comprehensive overview of the latest global data privacy regulations and updates impacting businesses in 2024 and how to prepare.

March 20, 2024

Learn more

Infographic

Privacy Management

OneTrust announces partnership with Europrivacy

Learn how OneTrust and Europrivacy's partnership can help your organization achieve GDPR compliance and build trust with your customers.

December 06, 2023

Learn more

Webinar

Technology Risk & Compliance

Demonstrating GDPR compliance with Europrivacy criteria: The European Data Protection Seal

Join our webinar to learn more about the European Data Protection Seal and to find out what the key advantages of getting certified.

November 30, 2023

Learn more

Webinar

Privacy Management

Revisiting the ICO Data Protection Practitioner's Conference: Addressing your top challenges

Join OneTrust and KPMG UK to discuss the challenges of employee SARs, managing your breach response with third parties, and incident management.

October 25, 2023

Learn more

Infographic

Privacy & Data Governance

Understanding the EU Data Boundary

Download our free infographic and get the information you need to understand the EU Data Boundary and how to properly handle data in the European Union.

September 22, 2023

Learn more

Webinar

Privacy Management

Privacy in practice: PIA & DPIA with PA Consulting

Join OneTrust and PA Consulting as we discuss what makes an effective PIA, best practices, and the benefits of automation.

September 21, 2023

Learn more

Webinar

Privacy & Data Governance

Privacy in practice for data mapping: With PA Consulting and Syngenta

Join OneTrust and panelists from PA Consulting and Syngenta as we explore practical ways to build an effective data mapping program, best practices, and the need for automation.

September 14, 2023

Learn more

Webinar

Governance & Policy Management

EU-US DPF: What next for UK businesses?

Join our expert webinar as we discuss the upcoming UK-US DPF Extension and what UK businesses need to prepare to become DPF-certified.

September 06, 2023

Learn more

Webinar

Privacy Management

Unpacking the EU-US DPF

In this webinar, we cover the new EU-US Data Privacy Framework (EU-US DPF) and what privacy program managers need to know for post-Schrems II data transfers.

June 28, 2023

Learn more

Infographic

Privacy & Data Governance

The 3 priorities of the French DPO: Gain visibility, take action, automate

Download our infographic and learn about the 3 priorities of the French DPO.

May 30, 2023

Learn more

Webinar

Privacy Management

GDPR turns 5: Celebrating data protection

Northern Europe panel - Join our panel of experts as they recap the GDPR, its key concepts, and what it means for organizations and compliance. 

May 25, 2023

Learn more

Webinar

Privacy Management

Global Panel — GDPR & Tech: Key considerations of Privacy by Design and AI in tech

Join our panel of experts as we discuss the impact GDPR had on the tech industry during the past five years, the importance of privacy by design, and what to expect with AI and regulation.

May 25, 2023

Learn more

Webinar

Privacy Management

5 years of GDPR: Milestones, challenges, and opportunities

Eastern European panel - Watch our webinar as we look back on 5 years of the GDPR, AI, and their impact on Europe, the world, and your organization.

May 24, 2023

Learn more

Webinar

Privacy & Data Governance

Global Panel — GDPR & Healthcare: current regulatory guidance and enforcement

In this live webinar, our expert panel examines the first five years of the GDPR, how it changed the healthcare industry, and the changing global regulatory landscape.

May 24, 2023

Learn more

Webinar

Privacy Management

Global Panel — GDPR & Retail: building customer loyalty and trust with consent and privacy

Join us for a live panel as we discuss GDPR's impact on the retail and eCommerce industry and how companies evolved to meet the global regulatory landscape.

May 23, 2023

Learn more

eBook

Privacy Management

Getting started with GDPR compliance

This eBook covers the fundamental information you need to know in order to get your GDPR compliance program started and how OneTrust helps. 

May 23, 2023

Learn more

Infographic

Privacy Management

Comparing the FADP, Revised FADP, and the GDPR

Download our infographic to see how the Revised FADP compares with its original version and the GDPR.

May 23, 2023

Learn more

Webinar

Privacy Management

Global Panel — GDPR & Finance: Staying ahead of the regulatory and cyber landscape

How has the GDPR affected the financial industry? Join our live panel as we examine how it companies evolved to meet the regulatory challenges and what can be done to stay ahead of the curve.

May 22, 2023

Learn more

Webinar

Privacy Automation

OneTrust and Deloitte UK - Data transfers: Assessments & safeguards

OneTrust's Center of Excellence and Deloitte UK will discuss data transfers and GDPR compliance, covering the UK stance, ICO/EDBP guidance, and more.

April 04, 2023 1 min read

Learn more

eBook

Privacy Management

The 3 Priorities for DPOs in France: Gain Visibility, Take Action, Automate eBook | Resources | OneTrust

French DPOs should take three priorities into account when building their data protection and compliance programs and processes in 2023.

February 21, 2023

Learn more

Webinar

Privacy & Data Governance

Data Protection in Financial Services Week: Government keynote and international transfers

This session will examine some key issues and recent developments on international data transfers with contributions from key EU, UK, and US regulators.

February 07, 2023

Learn more

Webinar

Consent & Preferences

Belgian DPA approves TCF action plan: Where we go from here

Belgian DPA approves IAB Europe’s action plan to correct its Transparency & Consent Framework (TCF) violations of the GDPR.

January 12, 2023

Learn more

Webinar

Privacy & Data Governance

Keeping pace with the changing regulatory landscape: UK And EU updates webinar

Learn more about the privacy updates for the UK and the EU, what to expect in the coming year, and how to manage regulatory change.

August 15, 2022

Learn more

Webinar

Ethics & Compliance

GDPR and the EU Whistleblower Protection Directive webinar

Join this webinar to learn how to review your whistleblowing processes to comply with the EU Whistleblower Protection Directive, the GDPR and others.

July 06, 2022

Learn more

Webinar

Privacy & Data Governance

4 years of GDPR

Watch our webinar on the last 4 years of GDPR compliance and trends for the future.

May 05, 2022

Learn more

Webinar

Privacy Management

Privacy rights poland: Enhance Your DSAR process with automation, discovery & redaction

As part of our Privacy Automation webinar series, we discuss why it's important to automate DSAR fulfillment and the latest regulatory trends. 

April 03, 2022

Learn more

Webinar

Privacy & Data Governance

Know your laws: Comparing CCPA & CPRA vs. GDPR

Watch this free webinar and see how the CCPA and CPRA compare with the GDPR.

January 04, 2022

Learn more

Checklist

Privacy & Data Governance

Transfer Impact Assessment (TIA) checklist

This Transfer Impact Assessment checklist provides an overview of the key steps you can take as you perform a TIA.

December 01, 2021

Learn more

Infographic

GDPR's 8 fundamental data subject rights

Download our GDPR's 8 Fundamental Data Subject Rights infographic and learn more about the individual rights guaranteed under the EU's major privacy law. 

August 27, 2021

Learn more

eBook

Privacy & Data Governance

The ultimate guide to GDPR compliance

Download this eBook to get an ultimate guide to understanding the GDPR and implementing steps towards compliance.

August 26, 2021

Learn more

eBook

Privacy & Data Governance

The Ultimate PIA and DPIA eBook

Download The Ultimate PIA and DPIA eBook to understand, develop, and implement an efficient PIA and DPIA process for your privacy program.

July 22, 2021

Learn more

eBook

Privacy & Data Governance

10 steps to meeting the GDPR Article 30 requirement

Download this eBook and learn how to leverage data mapping for your GDPR Article 30 compliance program. 

July 22, 2021

Learn more

Checklist

Privacy & Data Governance

GDPR compliance checklist

Download our GDPR compliance checklist for recommendations on improving your organization's privacy program. 

June 11, 2021

Learn more