Skip to main content

GDPR rights requests (DSARs, deletion, correction)

How data subject requests are handled when personal data is processed in Konfir.

Jacob avatar
Written by Jacob
Updated over 2 weeks ago

Overview

Under UK GDPR, individuals can exercise rights over their personal data, including access requests (DSARs), deletion (erasure), and correction (rectification).

Konfir can support requests relating to personal data held in Konfir systems. In most verification workflows, however, your organisation is the data controller, so requests often need to be handled in coordination.

Disclaimer: This article explains how rights requests are managed in practice. For formal legal terms, refer to: https://www.konfir.com/client/security


Common request types

You can contact Konfir about requests relating to data held in Konfir systems, including:

  • Access (DSAR): request a copy of personal data processed by Konfir

  • Deletion (erasure): request deletion of personal data where applicable

  • Rectification: request correction of inaccurate personal data

  • Restriction or objection: depending on context

  • Portability: where applicable

Who can submit a request

Rights requests may be submitted by:

Applicants (data subjects)

If you are an applicant and your request relates to a verification completed for a client organisation, Konfir may need to involve that client (as controller) to confirm scope and instructions.

Client users

If you are a client user requesting action on verification data, Konfir may ask you to confirm that you are authorised to make the request on behalf of your organisation.

What to include

To help Konfir locate the relevant record, include the following minimum information:

  • The request type (Access, Deletion, Rectification, etc.)

  • The identity of the subject (use Verification ID)

  • Any relevant details


How to submit a request

Email Konfir Support at: [email protected]

How requests are handled

Konfir will assess whether the request relates to personal data held in Konfir systems.

Where the request relates to verification processing for a client:

  • Konfir may notify the client organisation (controller), and/or

  • Request confirmation of instructions before taking action

Identity and authority checks

To protect personal data, Konfir may need to verify:

  • The requester’s identity (if you are the data subject), and/or

  • The requester’s authority (if acting on behalf of an organisation)


Customer responsibilities for exported copies

If your organisation has exported or stored verification outputs outside Konfir, you remain responsible for those downstream copies. Konfir cannot delete or amend data held in your own systems.

Did this answer your question?