Q. What regulations/jurisdictions are supported by the DSR module?
The Securiti DSR module supports global regulatory requirements around handling subject rights requests including, but not limited to, EU GDPR, LGPD, Thailand’s PDPA, South Africa’s POPIA, US state (California (CPRA), Maine, Nevada and Virginia) privacy laws etc.
Q. Do you send automatic reminders when a DSR is due?
Yes, automatic reminders are sent to task owners when a DSR is due. The system also auto extends overdue DSR requests, to the extent allowed by law and automatically notified the data subject of the delay using configurable notification templates.
Q. Where is your SaaS service hosted?
Securiti is hosted in AWS and customer tenants can be hosted in our US or EU cloud infrastructure.
Q. Can you have different response workflows for each request type?
Securiti DSR workbench automatically adjusts response workflows based on the request type.
Q. Which data repositories do you support?
Securiti supports 200+ predefined connectors to a variety of data repositories. This includes:
Custom connectors can also be enabled using standards based webhooks interfaces or using our workflow module which offers standards based API interfaces to any compatible application.
Q. Do you support scanning of tape backups?
No, Securiti cannot directly scan tape backups. This data has to be restored into a compatible environment before the data can be scanned to build People Data Graphs to support DSR fulfillment.
Q. Which languages are supported by the DSR module? Can consumers/data subjects interact with the system in different languages?
Securiti currently supports 8 languages – English, Portuguese (Brazil), French, Italian, Spanish, German, Japanese and Arabic with more on the roadmap. Consumers can choose to interact with the system using the language of their choice.
Q. Can I embed the DSR form on my website?
Yes, the DSR form can be embedded within your website to follow your brand guidelines using a special, embeddable form link, available once a form has been published.
Q. How do you perform identity verification?
Email based identity verification is included by default. External identity service providers such as ID.me and Accesso Digital can also be enabled to verify user identities using government identifiers such as drivers license, CPF and passport, augmented with selfie/liveliness checks.
Q. How are the reports secured? Where is it stored?
All DSR reports are encrypted at rest using tenant specific encryption keys within the Securiti platform. These reports cannot be downloaded from the DSR workbench by tenant admins. If required, all this information can be stored at rest in customer controlled cloud storage (AWS/Azure/GCP). When ready, reports are published to the authorized end user through the secure portal in encrypted format using a key accessible only to the end user.
Q. Can you redact/obfuscate data before handing it back to the data subject?
No, Securiti does not support redaction. This feature is on the near term roadmap
Q. How does data deletion work?
For applications that support deletion of users through APIs, Securiti’s DSR workflow can automatically delete user data for verified erasure requests. In other cases, custom workflows can be enabled to handle data deletion. For apps that don’t support standard deletion workflows, the DSR workbench displays all the data discovered for the user, along with standard data deletion steps/scripts, so that task owners can intelligently initiate application specific data deletion tasks.
Q. Can we hand back only the personal data attributes and not the actual data?
Yes, in most cases, organizations can choose to withhold actual data and only hand over personal data attributes through process records
Q. Is the DSR form customizable?
Yes, The DSR form can be customized to add/remove form fields and to add conditional logic and customization such as:
Q. Do you provide legal research data?
Yes, regulation specific research data is available within the workbench. Only relevant research data is shown in context so users don’t have to sift through research data to find information they need.
Q. How is the end user experience?
End users submit a DSR request using a form on your website. Users then get access to a secure portal where they can message/communicate with your internal privacy team and receive their final DSR report when it is ready in encrypted format. This report is only accessible to the data subject ensuring full confidentiality of the information and preventing unwanted data sprawls within your environment.
Q. Can I restrict/control the number of DSR requests a consumer can initiate?
Yes, the DSR module allows administrators to enforce restrictions on a per-DSR form basis. The following restrictions can be enforced
[email protected]
Securiti, Inc.
3155 Olsen Drive
Suite 350
San Jose, CA 95117