GDPR - Personal Information Request Functionality

Paul Hanlon
Paul Hanlon
  • Updated

General Data Protection Regulations - Personal Information Requests (PIR’s)                        

The content of this document is not legal advice. You should consult a legal advisor on your GDPR responsibilities.

Changes are being made to Jupix to ensure that you (the controller of the data) can meet your obligations under the General Data Protection Regulations requirements.

                                        

SAR (Subject Access Request) and PDR (Portable Data Request)

Two new buttons have been added to allow the user to respond to requests for personal data known as Subject Access Requests and Portable Data Requests.

Both are available from the contact record under Special Actions and access to them is controlled by a User Permission.

Subject Access Request

The Subject Access Request button will extract personal data into a text file, which will be downloaded onto the users local PC.

The Subject Access Request data file is in .txt format and will contain the following data:

  • Basic Contact Data (for each person on contact)

  • And additional personal information for Landlord’s, Vendors, Applicants, Tenants and Suppliers.

  • Anti Money Laundering information held

  • Notes tab notes, this includes:

    • all Notes added for the contact in any person role (Contact, Vendor, Landlord, Tenant, Applicant)

    • calls, notes, sms, viewing feedback etc, plus email and docs (see below)

    • all Notes related to a person but added to an associated record

      • eg Property, Appraisal, Tenancy, Viewing, Sale

    • Inline notes

      • viewing feedback for any viewing where person was the applicant

  • Documents

    • all Docs created for the contact, in any role.

      • (metadata only) i.e. just name and date etc of doc - not doc itself

  • Emails

    • all emails related to the contact, in any role

      • include date/time/subject and body text (not HTML)

  • Audit

    • All audit logs that contain a person's PID, including consent history

 

Portable Data Request

The Portable Data Request button will extract portable data into a JSON file, which will be downloaded onto the users local PC..

The Portable Data file is in machine readable format (JSON) and will contain the following data:

  • Basic Contact Data (for each person on contact)

  • And additional personal information for Landlord’s, Vendors, Applicants, Tenants and Suppliers.

  • Anti Money Laundering information held

 

User Permissions

Download Personal Information Requests

A new User Permissions has been added for Download Personal Information Requests and will allow the user to download both an SAR and PIR file. It is set in Admin/Manage Users/User/Permissions and will be off for all users, by default.

View Bank Account Details

A new User Permissions has been added for View Bank Account Details, this is in addition to the existing Edit Contact Bank Accounts.

This will allow a user to view Bank account details. If Edit Contact Bank Accounts is enabled they will also have the ability to edit them. It is set in Admin/Manage Users/User/Lettings Permissions. If Edit Contact Bank Accounts is enabled, View Bank Account Details has been automatically activated.

If the user does not have  Edit Contact Bank Accounts permissions,  View Bank Account Details will be off, by default.

A user without permission to View Bank Account Details will only see ******** instead of the account details, on any screen where account details are displayed. If the field is blank then these details are missing from the Payment Details section of the record.

Where a user has permission to Download Personal Information Requests, but does not have permission to view bank account details, they will be prevented from downloading a PIR or SAR file where bank details are included. They will receive a message advising them that View Bank Account Permission is required.