The legal framework used by Protect My Privacy when processing requests is the data protection /consumer privacy law which is applicable in the country of residence of the Protect My Privacy customer unless they are selecting a specific organisation (i.e. data controller) that is located in or operating in another jurisdiction; we then use the relevant data protection/consumer privacy law of that jurisdiction, if appropriate.
Protect My Privacy’s services are offered to customers who want to exercise the rights that are afforded to them under the relevant law(s) e.g. CCPA (California Consumer Privacy Act) or GDPR (the EU General Data Protection Regulation) or other such equivalent laws.
Protect My Privacy will look to extend its services to customers in other jurisdictions where new data protection /consumer privacy laws come into force.
Protect My Privacy is currently available to businesses with a registered head office or physical presence within the European Economic Area (EEA), the United Kingdom and California (United States of America).
If your country is not currently included, please register your interest here and one of our customer support team will contact you.
Protect My Privacy’s authority to act for its users is derived from the contractual agreement between the customer and Protect My Privacy in the provision of its services to them. This contractual agreement is entered into when the customer downloads the app, selects a subscription plan (free or paid), and engages with Protect My Privacy when they look to exercise their data protection or consumer privacy rights.
Once the Protect My Privacy user completes our onboarding requirements, they digitally sign an “Authorisation Letter” as evidence of this same authority for the recipient organisation, when sending requests.
Protect My Privacy is also registered as an Authorised Agent in California to assist our users there.
Companies could receive one of three types of requests from Protect My Privacy users (or a combination of all three); either “Stop Marketing”, “Get Data” or “Delete Data”. The email request will clearly identify what type of request you have received; each request is prefixed by a 3-letter shortcode that corresponds to a specific type of request, for example, the prefix “STO” refers to Stop Marketing.
In addition, consumers and businesses which comply with CCPA can send “Stop Sharing” requests.
Under CCPA, “consumers” exercise their privacy rights by submitting requests to a company.
Under GDPR, “data subjects” exercise their data protection rights by submitting requests to a company e.g., referred to as a data subject access request (“DSAR”) or “subject access request” (“SAR”).
If your company is in our database, (our company database allows users to select which companies they want to send requests to). You may receive a subject access request (SAR) which you can manage using our secure Protect My Privacy business services and verification process.
You can reply to a request without creating an account if the information provided by users is sufficient for you to match them to your company’s records. If you need additional sensitive data, such as National ID or biometric data, you will need to create an account with Protect My Privacy so that you can use the secure, data encrypted services available to businesses users, using either our Essential or Plus plans; both are currently free of charge for organisations.
You will be asked to choose between our two current plans, “Essential” and “Plus”, both of which are free for organisations. Each plan connects to our DM portal and allows Data Controllers and their privacy teams to safely and securely action requests, (“Essential” offers limited features while “Plus” affords Data Controllers and their teams a greater range of functionality). The main difference between the two plans is that “Essential” offers basic tools to deal with a single request at a time. “Plus” gathers all the incoming requests into a dashboard table showing all key information and the status of each request. This is a practical feature for companies who receive a large number of Subject Access Requests. “Plus” also displays all processing statistics and allows other authorised members of your privacy team to use the DM portal.
All SARs sent by Protect My Privacy on behalf of its users include links to “Manage Request” and “Access DM Portal”.
Clicking on “Manage Request” will open a window where you will be able to view the data subject’s information and respond to their request by either:
To view the data subject’s information you will need to click the blue button, “View All” after which you will be prompted to enter a One-Time Code that will be sent to your DPO email inbox.
Clicking “Access DM Portal” will open a window prompting you to “create a unique password” which will allow you to access the portal once a unique key has been generated to encrypt your communications (which currently can take up to 24 ). If you have already created a unique password and your unique key has been generated, you can access the portal securely with your password.
Once in the portal, you can view the data subject’s verified information as well as request consent from the data subject to view their more sensitive identity document in order to complete your company’s validation checks. You can also request more information from the data subject such as account or customer number etc. if you need it to complete their SAR.
You can respond to their SAR, communicate with the data subject, and complete the entire SAR process in our secure portal. If you choose our “Plus” portal option, the SAR process is made faster by using the app’s QR code scanner feature which provides quick access into your secure portal account.
Protect My Privacy is a consumer mobile application -i.e., an app (iOS and Android), with a business Data Management portal service for organisations and is fully compatible with Macs and PCs.
The main purpose of the Protect My Privacy DM portal is to provide;
We have written a detailed DM guide where Data Controllers and their privacy teams can find a comprehensive explanation of all features. The DM guide is available via the following here.
Verified information available on the data subject/user through either of the email response links is listed below and can include any of the following which is classified as being either “Standard” or “Sensitive” data which is explained in more detail later on in this document.
We do not have any Terms & Conditions for our free services for businesses. Protect My Privacy expects all business users to abide by all relevant laws in your jurisdiction when engaging with, and using our Protect My Privacy DM portal. We offer access to our Service, including the Portal (DM Portal) for the purpose of facilitating your response to data subject access requests. Our DM Portal allows you to transfer the required information to the data subject in an encrypted and secure manner. Protect My Privacy can neither view nor modify any data transferred by you to the data subject using our platform.
You cannot charge a person (or their agent acting on their behalf) for obtaining their data under GDPR and CCPA, provided the request is not unreasonable or excessive. All requests made via Protect My Privacy are basic requests under the legislation mentioned above.
Under the California Consumer Privacy Act (CCPA) and the EU General Data Protection Regulation (GDPR), an individual may choose to exercise their rights to access information held by an organisation in any appropriate way they choose e.g., electronic or non-electronic communication methods, via email, letter, verbal request or via their third party agent. An organisation cannot insist on a particular process for consumers to follow. However, in certain cases, if your company has a straightforward data management process in place, we can set an autoresponder feature so our users will be redirected to your system to exercise their data rights.
Under Article 12 GDPR, a data controller must respond to a SAR “without undue delay and in any event within one month of receipt of the request.” This can be extended by a further two months if the request is complex or a number of requests have been made by the data subject.
However, you must inform that data subject within the one-month period, why it is necessary for you to seek an extension for the SAR.
If a company does not fulfil its obligations with respect to the GDPR request(s), the data subject has the right to make a complaint to the relevant data protection regulator (or Supervisory Authority of the data controller) and seek redress or compensation. They also have the ability to bring legal action to the relevant court to seek redress or compensation.
For the most severe type of breach or for repeated breaches of the GDPR Regulation, a company could face a fine of up to a maximum 20 million euros or 4% of global annual revenues, whichever is the highest. Regulatory bodies will consider several factors to determine the fine, including its nature, severity and the frequency of the infraction(s). The levels of damage or distress suffered by individuals is also taken into account and any action taken by the organisation to mitigate the damage suffered by individuals will be considered.
Organizations must confirm receipt of a request within 10 business days and respond to the request within 45 calendar days from the time the request is received, not from when the request is verified although an extension may be possible. Violations of the CCPA are subject to enforcement by the California attorney general’s office, which can seek civil penalties of $2,500 for each violation or $7,500 for each intentional violation after notice and a 30-day opportunity to cure have been provided.
Our software utilises the highest security standards in communication technology and data storage to protect both you, the contact organisation and the data subject’s personal data. When data is imported into and stored in the Protect My Privacy platform it allows organisations to meet the regulatory requirements in the provision of a secure system to allow an individual to access and store their personal data. Our services provide a robust process when verifying our user’s identity. Our systems capture the customer’s electronic signature and consent, (where appropriate) which evidences a contractual agreement between Protect My Privacy and the user required the most relevant data protection regulations around the world.
Our software utilises the highest security standards in communication technology, encryption and data storage to protect both you, the contact organisation and the data subject’s personal data.
Our services use independent experts, who are experienced in all types of ID verification methods, to provide Protect My Privacy, and your company, with a robust process for verifying each Protect My Privacy user identity.
Our systems also capture the customer’s electronic signature and consent, (where appropriate) which evidences a contractual agreement between Protect My Privacy and the user. This documentation is available to review by all Protect My Privacy SAR recipient organisations
When data is imported into and stored in the Protect My Privacy platform it allows organisations to meet the high standards envisaged by the GDPR regulation and CCPA law in the provision of a secure system to allow an individual to access and store their personal data.
We take security seriously which is why we’ve been assessed and certified for addressing cybersecurity effectively and mitigating the risk from Internet-based threats.