Data Correction Request Procedures

Version1.0
Effective DateApril 2026
Review CycleAnnual
Document OwnerChief Information Security Officer (CISO)
ClassificationCONFIDENTIAL — Internal Use Only
Applicable StandardSOC 2 Type II

1. Purpose

This document defines the procedures by which data subjects can request corrections, amendments, or updates to their personal information held by DCKAP Integrator, including the verification process, timelines, and communication methods.

2. Scope of Correction Requests

Data subjects may request correction of personal information that DCKAP holds in its capacity as Data Controller, including:

  • DCKAP portal account details (name, email, contact information).
  • Billing and invoicing contact information.
  • Marketing preference records.

For personal data that has transited through DCKAP Integrator as part of a customer integration flow, data subjects should contact the customer organisation (Data Controller) to request corrections. DCKAP will relay correction requests to customers where DCKAP holds a copy.

3. Correction Request Process

StepActivityDescriptionTimeline
1SubmissionData subject submits correction request via portal self-service, email to privacy@dckap.com, or the online SAR/correction formDay 0
2AcknowledgementDCKAP acknowledges receipt with a reference number and outlines next stepsWithin 3 business days
3Identity VerificationIdentity verified per Document 22 (Authentication and Verification Records)Days 3–7
4AssessmentDCKAP assesses whether the correction request is valid and what data needs to be changedDays 7–15
5CorrectionCorrection applied to relevant records and systemsDays 15–25
6Notification to Third PartiesWhere data has been shared with third parties, DCKAP notifies them of the correction where feasibleDays 20–30
7ConfirmationData subject receives written confirmation that the correction has been madeBy Day 30
8RecordCorrection request and outcome logged in the privacy request registerOn completion

4. Self-Service Corrections (Portal)

Portal users can update many of their own account details without submitting a formal correction request:

Data ElementSelf-Service Available?Portal Location
Display nameYesSettings → My Profile → Name
Contact email addressYes (requires email verification)Settings → My Profile → Email
Phone numberYesSettings → My Profile → Phone
Notification preferencesYesSettings → Notifications
Marketing consentYesSettings → Privacy → Marketing Preferences
Billing contact detailsYes (admin only)Account → Billing → Contact

5. Grounds for Declining a Correction

  • DCKAP may decline a correction request if the data is accurate as held — in this case, we will explain our reasons and the data subject may request that we note their disagreement alongside the record.
  • Corrections cannot be applied to immutable audit trail records (by design for SOC 2 integrity) — instead, an annotation can be added.

6. Placement in Product

Product LocationScreen / PageAudience
Product PortalSettings → My Profile (self-service corrections)All Portal Users
Public Websitedckap.com/privacy/request (formal correction form)All Data Subjects
Privacy Policydckap.com/privacy → Rectification Rights SectionAll Data Subjects
Internal WikiLegal → Privacy Ops → Correction ProcedurePrivacy Team
Compliance FolderSOC 2 Evidence → Data Subject RightsExternal Auditors