Data Subject Rights Operations: GDPR, CCPA and HIPAA Access
Access and deletion requests have deadlines, and they arrive in bursts. Handle them across GDPR, CCPA and HIPAA from intake to evidence file.
What you'll be able to do
- Verify identity without asking for more data than you need
- Find a person's data across systems and vendors
- Apply exemptions correctly and meet each law's clock
- Keep a record that shows every request was handled properly
A data subject request runbook
What's in it. Intake, identity verification, datastore search, vendor sub-requests, exemptions, SLA clock, response pack and evidence file.
You build it lesson by lesson, using your own organization, and submit it for your certificate. It's yours to keep and adapt.
Who it's for
Privacy analysts, DPOs and customer support leads who handle data subject requests.
What's inside
- Part 1Where the requirement comes from 16 min
- Part 2How small teams and enterprises meet it 14 min
- Part 3The method, step by step 20 min
- Part 4Hands-on lab: small team choose one 90 min
- Part 5Hands-on lab: enterprise choose one 120 min
- Part 6Finish and submit your deliverable 20 min
Built for your size
The requirement is the same everywhere. How you meet it depends on who you have. You pick the lab that matches your organization.
How you earn the certificate
Submit your finished deliverable, which is scored against a published rubric, and pass a short scenario quiz. Your certificate goes to your wallet and can be checked by anyone on the public register.