Data subject participation is one of the conditions for the lawful processing of PI. Remember, a data subject is anyone with PI.
The condition has two parts:
- Data subjects have the right to request access to their PI.
- Data subjects have the right to ask that you correct, reduce, or delete their records.
If you have a Promotion of Access to Information Act (PAIA) manual you would have addressed this issue already.
If you don’t have a PAIA manual yet, now is a great time to draft one – since you’re thinking about access to information anyway. Just check whether a PAIA manual is a requirement for your business.
Either way – you need a process in place for dealing with requests for PI.
Give your POPIA Pro a call if you need more information about PAIA manuals.
Remember to add to your Risk Master list if you don’t have a documented process or a PAIA manual.