Data Access Request Procedures

Version1.0
Effective DateApril 2026
Review CycleAnnual
Document OwnerChief Information Security Officer (CISO)
ClassificationCONFIDENTIAL — Internal Use Only
Applicable StandardSOC 2 Type II

1. Purpose

This document defines the procedures by which data subjects (including portal users, consumers, and customer organisation contacts) may submit a Subject Access Request (SAR) to DCKAP to obtain access to their personal information held by DCKAP Integrator.

2. Scope

These procedures apply to requests for personal data held by DCKAP in connection with:

  • DCKAP portal user accounts (names, email addresses, login history, audit records of configuration actions).
  • Customer organisation contact data held for account management and support purposes.
  • Any personal data DCKAP holds in its own capacity as a Data Controller.

Note: For personal data that has transited through DCKAP Integrator as part of a customer’s integration flow (e.g., end-consumer order data), data subjects should direct requests to the customer organisation, which is the Data Controller for that data.

3. Access Request Process

StepActivityDescriptionTimeline
1SubmissionData subject submits a SAR via email to privacy@dckap.com or via the online SAR form at dckap.com/privacy/requestDay 0
2AcknowledgementDCKAP acknowledges receipt of the request and provides a reference numberWithin 3 business days
3Identity VerificationDCKAP verifies the identity of the requestor (see Section 4)Days 3–7
4Data IdentificationDCKAP identifies all personal data held about the data subjectDays 7–20
5ReviewLegal / Privacy team reviews data for any applicable exemptionsDays 20–25
6ResponseDCKAP provides the data subject with access to their data in a portable format (PDF/CSV)By Day 30
7RecordSAR logged in the privacy request register with outcome and dateOn completion

4. Identity Verification Requirements

Before providing access to personal data, DCKAP must verify the identity of the requestor to ensure data is not disclosed to an unauthorised party.

Requestor TypeVerification MethodEscalation if Unclear
Portal user (active account)Verify via authenticated portal session — user must be logged in to submit SAR in-portalRequire government ID if session cannot be established
Portal user (former account)Email verification to account email + last-4 of phone or account IDRequest government ID
Consumer (end user of customer)Not applicable — DCKAP is processor; redirect to Data ControllerProvide Data Controller contact details
Third-party representativeWritten letter of authority from data subject + their IDEscalate to Legal

5. Response Timelines and Extensions

  • Standard response time: 30 calendar days from receipt of a valid, verified request.
  • Extension: up to an additional 60 days for complex or high-volume requests — data subject notified within the initial 30 days with reason for extension.
  • No fee is charged for a SAR unless the request is manifestly unfounded or excessive.

6. Placement in Product

Product LocationScreen / PageAudience
Public Websitedckap.com/privacy/request (SAR form)All Data Subjects
Product PortalSettings → My Data → Request My DataPortal Users
Privacy Policydckap.com/privacy → Your Rights SectionAll Data Subjects
Internal WikiLegal → Privacy Ops → SAR ProcedurePrivacy Team, Support
Compliance FolderSOC 2 Evidence → Data Subject RightsExternal Auditors