People Also Ask
What must be redacted in a DSAR response?
Third-party personal data. A subject access request gives the requester their own data, so other people's names, contact details, and identifiers must be redacted first, along with any exempt material such as legally privileged content.
How long do we have to respond to a DSAR under GDPR?
One month from receipt. The deadline can be extended by up to two further months for complex or numerous requests, provided you tell the requester within the first month and explain why.
Can we keep the requester's data visible while redacting everyone else?
Yes. Selective redaction keeps the requester's personal data intact while masking third-party individuals across the response, including faces in CCTV footage and voices in call recordings.
Does GDPR redaction apply to CCTV and call recordings, not just documents?
Yes. Personal data is personal data in any format. CCTV footage, call audio, emails, and documents in a response all fall under GDPR and must have third-party data redacted before disclosure.
What happens if we disclose third-party data by mistake?
It is a personal data breach. Unauthorized disclosure of someone's personal data can trigger reporting obligations and regulatory penalties, which is why third-party redaction has to be verified before a response goes out.
Can it handle high DSAR volumes?
Yes. Bulk processing lets you upload an entire request set and apply detection rules once across every file, so large or numerous requests are handled in one pass instead of file by file.
Where is subject access data processed?
VIDIZMO Redactor deploys on-premises, in a private cloud, or as SaaS, so you can process subject access data within your own environment and data-residency requirements.