Data, privacy and trust

Privacy requests

Receive, fulfil and evidence a data request end to end.

About 6 minutes

If someone in your data asks what you hold, or asks you to delete it, Foreman runs that as a tracked process rather than leaving you to remember the steps.

The lifecycle

  1. Request — recorded, with who and what.
  2. Review — confirm the requester is who they say they are. This is your judgement, not the system's.
  3. Fulfil — export what you hold, or purge it.
  4. Evidence — the process is recorded, which is what you need if you are ever asked to demonstrate compliance.

Purges extend to device storage where a desktop host holds data, with acknowledgement recorded rather than assumed.

Steps

  1. Open Settings → Privacy.
  2. Record the request.
  3. Verify identity before fulfilling. Fulfilling for an unverified requester is itself a breach.
  4. Fulfil, and keep the evidence.

You're done when the request shows fulfilled with its record intact.

Also here

Global Privacy Control signals and per-person privacy preferences are honoured, and appeals against a decision can be recorded and resolved.

Gotchas

  • Verify first. The most common privacy failure is disclosing to the wrong person while trying to be responsive.
  • A purge is a purge. Once fulfilled, the data is gone from your workspace.

Checked against

  • endpoints/privacy/