Data Access Request Procedures
| Version | 1.0 |
| Effective Date | April 2026 |
| Review Cycle | Annual |
| Document Owner | Chief Information Security Officer (CISO) |
| Classification | CONFIDENTIAL — Internal Use Only |
| Applicable Standard | SOC 2 Type II |
1. Purpose
This document defines the procedures by which data subjects (including portal users, consumers, and customer organisation contacts) may submit a Subject Access Request (SAR) to DCKAP to obtain access to their personal information held by DCKAP Integrator.
2. Scope
These procedures apply to requests for personal data held by DCKAP in connection with:
- DCKAP portal user accounts (names, email addresses, login history, audit records of configuration actions).
- Customer organisation contact data held for account management and support purposes.
- Any personal data DCKAP holds in its own capacity as a Data Controller.
Note: For personal data that has transited through DCKAP Integrator as part of a customer’s integration flow (e.g., end-consumer order data), data subjects should direct requests to the customer organisation, which is the Data Controller for that data.
3. Access Request Process
| Step | Activity | Description | Timeline |
|---|---|---|---|
| 1 | Submission | Data subject submits a SAR via email to privacy@dckap.com or via the online SAR form at dckap.com/privacy/request | Day 0 |
| 2 | Acknowledgement | DCKAP acknowledges receipt of the request and provides a reference number | Within 3 business days |
| 3 | Identity Verification | DCKAP verifies the identity of the requestor (see Section 4) | Days 3–7 |
| 4 | Data Identification | DCKAP identifies all personal data held about the data subject | Days 7–20 |
| 5 | Review | Legal / Privacy team reviews data for any applicable exemptions | Days 20–25 |
| 6 | Response | DCKAP provides the data subject with access to their data in a portable format (PDF/CSV) | By Day 30 |
| 7 | Record | SAR logged in the privacy request register with outcome and date | On completion |
4. Identity Verification Requirements
Before providing access to personal data, DCKAP must verify the identity of the requestor to ensure data is not disclosed to an unauthorised party.
| Requestor Type | Verification Method | Escalation if Unclear |
|---|---|---|
| Portal user (active account) | Verify via authenticated portal session — user must be logged in to submit SAR in-portal | Require government ID if session cannot be established |
| Portal user (former account) | Email verification to account email + last-4 of phone or account ID | Request government ID |
| Consumer (end user of customer) | Not applicable — DCKAP is processor; redirect to Data Controller | Provide Data Controller contact details |
| Third-party representative | Written letter of authority from data subject + their ID | Escalate to Legal |
5. Response Timelines and Extensions
- Standard response time: 30 calendar days from receipt of a valid, verified request.
- Extension: up to an additional 60 days for complex or high-volume requests — data subject notified within the initial 30 days with reason for extension.
- No fee is charged for a SAR unless the request is manifestly unfounded or excessive.
6. Placement in Product
| Product Location | Screen / Page | Audience |
|---|---|---|
| Public Website | dckap.com/privacy/request (SAR form) | All Data Subjects |
| Product Portal | Settings → My Data → Request My Data | Portal Users |
| Privacy Policy | dckap.com/privacy → Your Rights Section | All Data Subjects |
| Internal Wiki | Legal → Privacy Ops → SAR Procedure | Privacy Team, Support |
| Compliance Folder | SOC 2 Evidence → Data Subject Rights | External Auditors |