We assist the Client in defining the internal procedures for handling data access and sharing requests, where appropriate in coordination with the access and portability rights provided for by the GDPR. In practice, we govern how the Client receives and manages users’ requests to access the data generated by connected products or to share them with third parties, defining roles, timescales, authorisation flows and controls, and ensuring, where necessary, alignment with personal data protection obligations.
We aim to create a clear, documented internal process that allows requests to be answered promptly and compliantly, reducing exposure to disputes and defaults.