Data Correction Request Procedures
| Version | 1.0 |
| Effective Date | April 2026 |
| Review Cycle | Annual |
| Document Owner | Chief Information Security Officer (CISO) |
| Classification | CONFIDENTIAL — Internal Use Only |
| Applicable Standard | SOC 2 Type II |
1. Purpose
This document defines the procedures by which data subjects can request corrections, amendments, or updates to their personal information held by DCKAP Integrator, including the verification process, timelines, and communication methods.
2. Scope of Correction Requests
Data subjects may request correction of personal information that DCKAP holds in its capacity as Data Controller, including:
- DCKAP portal account details (name, email, contact information).
- Billing and invoicing contact information.
- Marketing preference records.
For personal data that has transited through DCKAP Integrator as part of a customer integration flow, data subjects should contact the customer organisation (Data Controller) to request corrections. DCKAP will relay correction requests to customers where DCKAP holds a copy.
3. Correction Request Process
| Step | Activity | Description | Timeline |
|---|---|---|---|
| 1 | Submission | Data subject submits correction request via portal self-service, email to privacy@dckap.com, or the online SAR/correction form | Day 0 |
| 2 | Acknowledgement | DCKAP acknowledges receipt with a reference number and outlines next steps | Within 3 business days |
| 3 | Identity Verification | Identity verified per Document 22 (Authentication and Verification Records) | Days 3–7 |
| 4 | Assessment | DCKAP assesses whether the correction request is valid and what data needs to be changed | Days 7–15 |
| 5 | Correction | Correction applied to relevant records and systems | Days 15–25 |
| 6 | Notification to Third Parties | Where data has been shared with third parties, DCKAP notifies them of the correction where feasible | Days 20–30 |
| 7 | Confirmation | Data subject receives written confirmation that the correction has been made | By Day 30 |
| 8 | Record | Correction request and outcome logged in the privacy request register | On completion |
4. Self-Service Corrections (Portal)
Portal users can update many of their own account details without submitting a formal correction request:
| Data Element | Self-Service Available? | Portal Location |
|---|---|---|
| Display name | Yes | Settings → My Profile → Name |
| Contact email address | Yes (requires email verification) | Settings → My Profile → Email |
| Phone number | Yes | Settings → My Profile → Phone |
| Notification preferences | Yes | Settings → Notifications |
| Marketing consent | Yes | Settings → Privacy → Marketing Preferences |
| Billing contact details | Yes (admin only) | Account → Billing → Contact |
5. Grounds for Declining a Correction
- DCKAP may decline a correction request if the data is accurate as held — in this case, we will explain our reasons and the data subject may request that we note their disagreement alongside the record.
- Corrections cannot be applied to immutable audit trail records (by design for SOC 2 integrity) — instead, an annotation can be added.
6. Placement in Product
| Product Location | Screen / Page | Audience |
|---|---|---|
| Product Portal | Settings → My Profile (self-service corrections) | All Portal Users |
| Public Website | dckap.com/privacy/request (formal correction form) | All Data Subjects |
| Privacy Policy | dckap.com/privacy → Rectification Rights Section | All Data Subjects |
| Internal Wiki | Legal → Privacy Ops → Correction Procedure | Privacy Team |
| Compliance Folder | SOC 2 Evidence → Data Subject Rights | External Auditors |