Find and sort the privacy requests in your inboxes
Reads emails, chats and tickets for a request to see, delete, correct or stop using data, which right and whose. Code starts the clock; a person acts.
Try it on this example
Channel (email, chat, help centre form, social message, letter): chat
The whole message or conversation
- Does the person getting in touch ask to exercise a right over personal data, such as seeing, correcting or deleting it, or stopping marketing?Yes99%
- What does the sender mainly ask for about personal data?Access100%
- Does the sender ask for more than one right over their personal data, such as a copy and then deletion?Yes97%
- What is the relationship to us of the person whose data the message is about?Our customer or user100%
- Is the person getting in touch acting for someone else, such as a relative, carer, parent, lawyer or claims firm?No94%
- Does the message concern the personal data of someone under 18?No95%
- Does the sender mention a lawyer, legal action, or a complaint to a data protection authority or other regulator?Yes96%
- Does the sender complain about us, or raise a claim or a dispute, in the same message as the request?Yes92%
- Does the message give details that would let staff find the records of the person it is about?Yes99%
- Is it clear enough what the sender wants for staff to start the request without writing back?Yes83%
These are real answers stored from one run on this example.
The prism behind it
Find and sort the privacy requests in your inboxes
Fields
- Channel (email, chat, help centre form, social message, letter)
- The whole message or conversation
Context
We are Fernway, a company that sells home fitness equipment online in the EU and the UK, and runs Fernway Classes, a class-booking app that gyms license for their members. People write to us by email, chat, the help centre form and social messages. Each message is read here on arrival, whatever inbox it lands in, so that privacy requests inside ordinary support contacts reach the privacy team on the day they arrive. Whose request it is: - Customers and app users who signed up with us directly: we decide how their data is used, and we answer their requests. - Members who use Fernway Classes through their gym: the gym decides how their data is used, and we act for the gym. We forward their requests to the gym and do not answer them ourselves. - Current and former staff and job applicants: their requests go to privacy counsel. Rule sets: - EU GDPR and UK GDPR: a person may ask for access to their data, deletion, correction, restriction or portability, may object to a use of their data, and may withdraw consent. A request counts in any words and through any channel; it does not have to name a law or a right. An objection to direct marketing must always be honoured. - US state privacy laws, such as California's, also give a right to opt out of the sale or sharing of personal data. These answers only sort the message. They do not check identity, find the data, apply exemptions or decide the reply. Code opens the privacy case with the time the message arrived and sets the deadline for the region; a person handles the request.
Questions
Does the person getting in touch ask to exercise a right over personal data, such as seeing, correcting or deleting it, or stopping marketing? Yes / No
Count a request to see or get a copy of personal data, to be told what is held or who it was shared with, to delete, correct, move or restrict it, to object to a use of it, to stop marketing, to opt out of its sale or sharing, or to withdraw consent. Count it in any words, such as "everything you have on me" or "the notes about me", whether or not a law or right is named, and when it sits inside a message about something else. A request for a routine document, such as a payslip, an invoice or an employment letter, is not a data request. Read only what the person getting in touch says, not the agent. Yes: They make at least one such request about their own data or the data of someone they act for. No: They make no such request. A general question about the privacy policy is No.
What does the sender mainly ask for about personal data? Choice
When the sender asks for more than one right, pick the one they ask to be done first.
Does the sender ask for more than one right over their personal data, such as a copy and then deletion? Yes / No
Count these rights: access, deletion, correction, portability, objection or restriction, stopping marketing, opting out of sale or sharing, and withdrawing consent. Yes: The sender asks for two or more different rights. No: The sender asks for one right, or none.
What is the relationship to us of the person whose data the message is about? Choice
Judge the person whose data it is. When someone writes for another person, judge that person. Use the context to tell our own customers from members who use the app through a gym.
Is the person getting in touch acting for someone else, such as a relative, carer, parent, lawyer or claims firm? Yes / No
Count anyone who says they are getting in touch for the person whose account or data it is. Someone who writes for themselves and copies in a lawyer is acting for themselves. Yes: The person says they act for someone else. No: The person acts for themselves, or makes no request.
Does the message concern the personal data of someone under 18? Yes / No
Count it when the message says or clearly shows the person is a child, such as "my son's account" or a stated age under 18. Do not guess an age from writing style. Yes: The data is about a person the message shows to be under 18. No: Nothing in the message shows the person is under 18.
Does the sender mention a lawyer, legal action, or a complaint to a data protection authority or other regulator? Yes / No
Count a threat, or a statement that it has already been done. Do not count a plain question about how to complain. Yes: The sender says they have gone, or will go, to a lawyer, a court, a data protection authority or another regulator. No: No such step is mentioned.
Does the sender complain about us, or raise a claim or a dispute, in the same message as the request? Yes / No
Count dissatisfaction about any matter in the same message, such as a late order, a charge, unwanted contact or how they were treated, and an employment dispute. Yes: The message contains a complaint, a claim or a dispute as well as, or instead of, a request. No: The sender raises no complaint, claim or dispute.
Does the message give details that would let staff find the records of the person it is about? Yes / No
Count an account email, a customer or member number, an order number, a phone number or a gym membership given in the message, or a sender address in email headers. Yes: At least one such detail appears. No: No such detail appears, so staff would have to ask for one.
Is it clear enough what the sender wants for staff to start the request without writing back? Yes / No
Judge only what the sender asks for, not whether their identity is proven; code and the privacy team handle identity. Yes: The message is a privacy request, and it is clear which data and which right it concerns. No: The request is too vague to start, or the message makes no privacy request.
Lens columns
data_request, data_request_probability, primary_right, primary_right_probability, multiple_rights, multiple_rights_probability, requester_relationship, requester_relationship_probability, on_behalf_of_other, on_behalf_of_other_probability, concerns_child, concerns_child_probability, legal_or_regulator_threat, legal_or_regulator_threat_probability, complaint_alongside, complaint_alongside_probability, locating_details_given, locating_details_given_probability, enough_to_act, enough_to_act_probability
Run it on your own text
Add this prism in the app, change any question, and test it on a file of your own.