GDPR Article 15 Workflow
ZD: https://gitlab.zendesk.com/agent/tickets/102282 (internal only) is an article 15 request.
This isn't the first one, but it probably won't be the last.
As of right now, we currently don't have a good process in place for handling requests of the following nature:
-
Please confirm to me whether or not my personal data is being processed. If it is, please provide me with the categories of personal data you have about me in your files and databases.
a. In particular, please tell me what you know about me in your information systems, whether or not contained in databases, and including e-mail, documents on your networks, or voice or other media that you may store.
b. Additionally, please advise me in which countries my personal data is stored, or accessible from. In case you make use of cloud services to store or process my data, please include the countries in which the servers are located where my data are or were stored.c. Please provide me with a copy of, or access to, my personal data that you have or are processing.
-
Please provide me with a detailed accounting of the specific uses that you have made, are making, or will be making of my personal data.
-
Please provide a list of all third parties with whom you have (or may have) shared my personal data.
-
If you are additionally collecting personal data about me from any source other than me, please provide me with all information about their source, as referred to in Article 14 of the GDPR.
-
If you are making automated decisions about me, including profiling, whether or not on the basis of Article 22 of the GDPR, please provide me with information concerning the basis for the logic in making such automated decisions, and the significance and consequences of such processing.
-
I would like to know whether or not my personal data has been disclosed inadvertently by your company in the past, or as a result of a security or privacy breach.
Some of this may be a rehash of the GDPR account deletion workflow, but we need to be able to deliver a solid package for these types of requests.
/cc @jhurewitz @gitlab-com/support/managers @MFarber @jjcordz