Skip to Content
CKonnect
  • Home
  • CourseKonnect
    • e-learning
    • Udemy
    • learning (Old LMS)
  • Career
    • Life @CKonnect
    • All Jobs
  • Knowledge Base
    • PrivacyReads
    • Community
    • Newsletters
    • Priv ToolKit
  • Stay Tuned
    • ComplyKonnect
    • E-PrivJournals
    • Priv-Books
  • Connects
    • 1:1
  • Contact Us
CKonnect
    • Home
    • CourseKonnect
      • e-learning
      • Udemy
      • learning (Old LMS)
    • Career
      • Life @CKonnect
      • All Jobs
    • Knowledge Base
      • PrivacyReads
      • Community
      • Newsletters
      • Priv ToolKit
    • Stay Tuned
      • ComplyKonnect
      • E-PrivJournals
      • Priv-Books
    • Connects
      • 1:1
  • Contact Us

Welcome!

Share and discuss the best content and new marketing ideas, build your professional profile and become a better marketer together.

Sign up

You need to be registered to interact with the community.
All Posts People Badges
Tags (View all)
Data Privacy IDT Tech Privacy DSR Data Mapping
About this forum
You need to be registered to interact with the community.
All Posts People Badges
Tags (View all)
Data Privacy IDT Tech Privacy DSR Data Mapping
About this forum
CKonnect Community

Can You Deny a DSR if the Request is Weaponized?

Subscribe

Get notified when there's activity on this post

This question has been flagged
DSR
1 Reply
387 Views
Avatar
CKonnect

You work for a fintech company. A known troublemaker — someone who has previously harassed your support staff and left multiple fake reviews — suddenly raises a Right to Access and Right to Rectification request under the DPDPA. You suspect the intent is to burden your team and gather internal data to fuel more public complaints.

You’re tempted to push back or delay. After all, the person’s clearly acting in bad faith. But can you?

How would you respond?

  • Can intent or motive be used to deny or delay a data subject request under GDPR or DPDPA?
  • What safeguards or red flags should you document internally before making a decision?
  • If you do respond, how would you protect your team from further harassment while still staying compliant?

Use this case to explore the fine line between lawful refusal and lawful obligation.

0
Avatar
Discard
Avatar
aftab.naukhaiz1997@gmail.com

No, we cannot deny the DSR even if it has bad faith. The Digital Personal Data Protection Act and General Data Protection Regulation grants data principle certain rights, and our company has a legal obligation to fulfil them.

Despite the user’s history of poor intention, our company must treat their DSR with the same due diligence as any other good faith request. Failure to respond could invite heavy penalties. Hence, bad intention is not enough to deny the data subject request.

Safeguards or red flags 

·      Document everything, such as past harassment, fake reviews, and repeated requests. Log all previous requests from them, with dates and details.

·      Estimate the workload or data volume involved in the processing request.

·      Update the DPO or another senior legal person to get the document attested.

Protect your team from further harassment.

·      Pick one person to handle all communication with the user.

·      Make sure you document everything, through mail or any other mode of communication. Make it clear that abusive or harassing language is not acceptable.

·      If the user gets really aggressive or threatening, involve your legal team. This is about keeping your employees safe.

In rare cases, understand the ground for refusal. DPDPA and GDPR provide some grounds for refusal, but they are typically limited and need justification for refusal. Engage with the legal team for the same.

For deep understanding follow the


linkhttps://www.ckonnect.co.in/blog/privacy-team-pulse-7/data-subject-request-dsr-85

0
Avatar
Discard
Enjoying the discussion? Don't just read, join in!

Create an account today to enjoy exclusive features and engage with our awesome community!

Sign up
Related Posts Replies Views Activity
You’ve Received a Vague Data Access Request — What Now?
DSR
Avatar
Avatar
1
Dec 25
417
How Would You Respond to a "Right to Be Forgotten" Request from an Ex-Employee?
DSR
Avatar
0
May 25
394
Follow us

Privacy Notice ​​Refund Policy

 Terms & Conditions

    ​    connect@ckonnect.co.in

How can we help?

konnect with us

Website Logo

Respecting your privacy is our priority.

Allow the use of cookies from this website on this browser?

We use cookies to provide improved experience on this website. You can learn more about our cookies and how we use them in our Cookie Policy.

Allow all cookiesOnly allow essential cookies