[{"data":1,"prerenderedAt":549},["ShallowReactive",2],{"content-/contacts/gdpr-and-data-subject-requests":3,"docs-toc":321},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"type":10,"status":11,"applies_to":12,"last_reviewed":14,"related":15,"body":18,"_type":315,"_id":316,"_source":317,"_file":318,"_stem":319,"_extension":320},"/contacts/gdpr-and-data-subject-requests","contacts",false,"","GDPR and data subject requests","How PropLink supports your data protection duties under UK GDPR and the Data Protection Act 2018.","concept","live",[13],"shared","2026-05-10",[16,17],"/contacts/the-contact-directory","/core-concepts/the-audit-trail",{"type":19,"children":20,"toc":303},"root",[21,29,35,42,47,52,89,94,100,112,118,123,128,158,163,169,174,180,185,219,224,230,249,255,260,284,290],{"type":22,"tag":23,"props":24,"children":26},"element","h1",{"id":25},"gdpr-and-data-subject-requests",[27],{"type":28,"value":8},"text",{"type":22,"tag":30,"props":31,"children":32},"p",{},[33],{"type":28,"value":34},"Under UK GDPR and the Data Protection Act 2018, individuals whose personal data you hold have rights you must support. PropLink gives you the tools to do that. This page covers the workflows; consult your data protection officer or solicitor for legal interpretation.",{"type":22,"tag":36,"props":37,"children":39},"h2",{"id":38},"data-subject-access-requests",[40],{"type":28,"value":41},"Data-subject access requests",{"type":22,"tag":30,"props":43,"children":44},{},[45],{"type":28,"value":46},"A data subject can request a copy of all personal data your organisation holds about them. You have one calendar month to respond.",{"type":22,"tag":30,"props":48,"children":49},{},[50],{"type":28,"value":51},"To produce the export:",{"type":22,"tag":53,"props":54,"children":55},"steps",{},[56],{"type":22,"tag":57,"props":58,"children":59},"ol",{},[60,66,79,84],{"type":22,"tag":61,"props":62,"children":63},"li",{},[64],{"type":28,"value":65},"Open the contact.",{"type":22,"tag":61,"props":67,"children":68},{},[69,71,77],{"type":28,"value":70},"Click ",{"type":22,"tag":72,"props":73,"children":74},"strong",{},[75],{"type":28,"value":76},"Actions → Export data subject record",{"type":28,"value":78},".",{"type":22,"tag":61,"props":80,"children":81},{},[82],{"type":28,"value":83},"PropLink compiles a ZIP containing every record relating to the contact: profile, communications, invoices, payments, tickets, audit log entries.",{"type":22,"tag":61,"props":85,"children":86},{},[87],{"type":28,"value":88},"Download or email the ZIP to the contact within the statutory timeframe.",{"type":22,"tag":30,"props":90,"children":91},{},[92],{"type":28,"value":93},"The export is generated in a portable format (PDF for documents, CSV for tabular data, JSON for the machine-readable record).",{"type":22,"tag":36,"props":95,"children":97},{"id":96},"right-to-rectification",[98],{"type":28,"value":99},"Right to rectification",{"type":22,"tag":30,"props":101,"children":102},{},[103,105,110],{"type":28,"value":104},"If a contact tells you their data is wrong, fix it under ",{"type":22,"tag":72,"props":106,"children":107},{},[108],{"type":28,"value":109},"Contact → Edit",{"type":28,"value":111},". PropLink records the change in the audit log.",{"type":22,"tag":36,"props":113,"children":115},{"id":114},"right-to-erasure",[116],{"type":28,"value":117},"Right to erasure",{"type":22,"tag":30,"props":119,"children":120},{},[121],{"type":28,"value":122},"If a contact asks for their data to be deleted, you must consider whether you have a lawful basis to retain it. For most contacts you will: legal obligations on financial records, the firm's legitimate interest in retaining audit history for tribunal exposure, contractual obligations under leases.",{"type":22,"tag":30,"props":124,"children":125},{},[126],{"type":28,"value":127},"If erasure is appropriate:",{"type":22,"tag":53,"props":129,"children":130},{},[131],{"type":22,"tag":57,"props":132,"children":133},{},[134,138,148,153],{"type":22,"tag":61,"props":135,"children":136},{},[137],{"type":28,"value":65},{"type":22,"tag":61,"props":139,"children":140},{},[141,142,147],{"type":28,"value":70},{"type":22,"tag":72,"props":143,"children":144},{},[145],{"type":28,"value":146},"Actions → Erase",{"type":28,"value":78},{"type":22,"tag":61,"props":149,"children":150},{},[151],{"type":28,"value":152},"PropLink shows you what will be erased and what will be retained for legal reasons (with the basis cited).",{"type":22,"tag":61,"props":154,"children":155},{},[156],{"type":28,"value":157},"Enter a reason and confirm.",{"type":22,"tag":30,"props":159,"children":160},{},[161],{"type":28,"value":162},"PropLink replaces the contact's name, email, phone and address with placeholder values. Audit history is preserved for legal reasons but stripped of any personal data not required for that legal basis.",{"type":22,"tag":36,"props":164,"children":166},{"id":165},"right-to-data-portability",[167],{"type":28,"value":168},"Right to data portability",{"type":22,"tag":30,"props":170,"children":171},{},[172],{"type":28,"value":173},"The data subject access export is in machine-readable formats so the data can be transferred to another controller if requested.",{"type":22,"tag":36,"props":175,"children":177},{"id":176},"right-to-object",[178],{"type":28,"value":179},"Right to object",{"type":22,"tag":30,"props":181,"children":182},{},[183],{"type":28,"value":184},"If a contact objects to direct marketing or to specific uses of their data, set the corresponding preference on their profile:",{"type":22,"tag":186,"props":187,"children":188},"ul",{},[189,199,209],{"type":22,"tag":61,"props":190,"children":191},{},[192,197],{"type":22,"tag":72,"props":193,"children":194},{},[195],{"type":28,"value":196},"Marketing.",{"type":28,"value":198}," Toggles whether they receive any non-transactional emails.",{"type":22,"tag":61,"props":200,"children":201},{},[202,207],{"type":22,"tag":72,"props":203,"children":204},{},[205],{"type":28,"value":206},"Surveys.",{"type":28,"value":208}," Toggles whether they receive feedback requests.",{"type":22,"tag":61,"props":210,"children":211},{},[212,217],{"type":22,"tag":72,"props":213,"children":214},{},[215],{"type":28,"value":216},"Building updates.",{"type":28,"value":218}," Toggles whether they receive non-statutory updates.",{"type":22,"tag":30,"props":220,"children":221},{},[222],{"type":28,"value":223},"Statutory communications (Section 20 notices, Section 166 notices, demand letters) cannot be opted out of and are sent regardless.",{"type":22,"tag":36,"props":225,"children":227},{"id":226},"records-of-processing-activity",[228],{"type":28,"value":229},"Records of processing activity",{"type":22,"tag":30,"props":231,"children":232},{},[233,235,241,243,248],{"type":28,"value":234},"The audit trail (see ",{"type":22,"tag":236,"props":237,"children":238},"a",{"href":17},[239],{"type":28,"value":240},"The audit trail",{"type":28,"value":242},") records every meaningful interaction with personal data. This is part of your records of processing activity under Article 30. Export the relevant log under ",{"type":22,"tag":72,"props":244,"children":245},{},[246],{"type":28,"value":247},"Settings → Audit logs → Export",{"type":28,"value":78},{"type":22,"tag":36,"props":250,"children":252},{"id":251},"breach-response",[253],{"type":28,"value":254},"Breach response",{"type":22,"tag":30,"props":256,"children":257},{},[258],{"type":28,"value":259},"If a personal data breach occurs, you have 72 hours to notify the ICO. PropLink gives you:",{"type":22,"tag":186,"props":261,"children":262},{},[263,268,273],{"type":22,"tag":61,"props":264,"children":265},{},[266],{"type":28,"value":267},"The audit log to identify the scope of access during the breach window.",{"type":22,"tag":61,"props":269,"children":270},{},[271],{"type":28,"value":272},"Communications history to identify what was sent to whom.",{"type":22,"tag":61,"props":274,"children":275},{},[276,278,283],{"type":28,"value":277},"The ability to expire all active sessions immediately under ",{"type":22,"tag":72,"props":279,"children":280},{},[281],{"type":28,"value":282},"Settings → Users and access → Sign all users out",{"type":28,"value":78},{"type":22,"tag":36,"props":285,"children":287},{"id":286},"retention",[288],{"type":28,"value":289},"Retention",{"type":22,"tag":30,"props":291,"children":292},{},[293,295,301],{"type":28,"value":294},"Data is retained as long as the organisation exists, unless an individual exercises their right to erasure and that erasure is granted. See ",{"type":22,"tag":236,"props":296,"children":298},{"href":297},"/core-concepts/organisations-and-multi-tenancy",[299],{"type":28,"value":300},"Organisations and multi-tenancy",{"type":28,"value":302}," for what happens to data if an organisation closes.",{"title":7,"searchDepth":304,"depth":304,"links":305},3,[306,308,309,310,311,312,313,314],{"id":38,"depth":307,"text":41},2,{"id":96,"depth":307,"text":99},{"id":114,"depth":307,"text":117},{"id":165,"depth":307,"text":168},{"id":176,"depth":307,"text":179},{"id":226,"depth":307,"text":229},{"id":251,"depth":307,"text":254},{"id":286,"depth":307,"text":289},"markdown","content:04.contacts:gdpr-and-data-subject-requests.md","content","04.contacts/gdpr-and-data-subject-requests.md","04.contacts/gdpr-and-data-subject-requests","md",{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"type":10,"status":11,"applies_to":322,"last_reviewed":14,"related":323,"body":324,"_type":315,"_id":316,"_source":317,"_file":318,"_stem":319,"_extension":320},[13],[16,17],{"type":19,"children":325,"toc":539},[326,330,334,338,342,346,373,377,381,390,394,398,402,429,433,437,441,445,449,476,480,484,498,502,506,526,530],{"type":22,"tag":23,"props":327,"children":328},{"id":25},[329],{"type":28,"value":8},{"type":22,"tag":30,"props":331,"children":332},{},[333],{"type":28,"value":34},{"type":22,"tag":36,"props":335,"children":336},{"id":38},[337],{"type":28,"value":41},{"type":22,"tag":30,"props":339,"children":340},{},[341],{"type":28,"value":46},{"type":22,"tag":30,"props":343,"children":344},{},[345],{"type":28,"value":51},{"type":22,"tag":53,"props":347,"children":348},{},[349],{"type":22,"tag":57,"props":350,"children":351},{},[352,356,365,369],{"type":22,"tag":61,"props":353,"children":354},{},[355],{"type":28,"value":65},{"type":22,"tag":61,"props":357,"children":358},{},[359,360,364],{"type":28,"value":70},{"type":22,"tag":72,"props":361,"children":362},{},[363],{"type":28,"value":76},{"type":28,"value":78},{"type":22,"tag":61,"props":366,"children":367},{},[368],{"type":28,"value":83},{"type":22,"tag":61,"props":370,"children":371},{},[372],{"type":28,"value":88},{"type":22,"tag":30,"props":374,"children":375},{},[376],{"type":28,"value":93},{"type":22,"tag":36,"props":378,"children":379},{"id":96},[380],{"type":28,"value":99},{"type":22,"tag":30,"props":382,"children":383},{},[384,385,389],{"type":28,"value":104},{"type":22,"tag":72,"props":386,"children":387},{},[388],{"type":28,"value":109},{"type":28,"value":111},{"type":22,"tag":36,"props":391,"children":392},{"id":114},[393],{"type":28,"value":117},{"type":22,"tag":30,"props":395,"children":396},{},[397],{"type":28,"value":122},{"type":22,"tag":30,"props":399,"children":400},{},[401],{"type":28,"value":127},{"type":22,"tag":53,"props":403,"children":404},{},[405],{"type":22,"tag":57,"props":406,"children":407},{},[408,412,421,425],{"type":22,"tag":61,"props":409,"children":410},{},[411],{"type":28,"value":65},{"type":22,"tag":61,"props":413,"children":414},{},[415,416,420],{"type":28,"value":70},{"type":22,"tag":72,"props":417,"children":418},{},[419],{"type":28,"value":146},{"type":28,"value":78},{"type":22,"tag":61,"props":422,"children":423},{},[424],{"type":28,"value":152},{"type":22,"tag":61,"props":426,"children":427},{},[428],{"type":28,"value":157},{"type":22,"tag":30,"props":430,"children":431},{},[432],{"type":28,"value":162},{"type":22,"tag":36,"props":434,"children":435},{"id":165},[436],{"type":28,"value":168},{"type":22,"tag":30,"props":438,"children":439},{},[440],{"type":28,"value":173},{"type":22,"tag":36,"props":442,"children":443},{"id":176},[444],{"type":28,"value":179},{"type":22,"tag":30,"props":446,"children":447},{},[448],{"type":28,"value":184},{"type":22,"tag":186,"props":450,"children":451},{},[452,460,468],{"type":22,"tag":61,"props":453,"children":454},{},[455,459],{"type":22,"tag":72,"props":456,"children":457},{},[458],{"type":28,"value":196},{"type":28,"value":198},{"type":22,"tag":61,"props":461,"children":462},{},[463,467],{"type":22,"tag":72,"props":464,"children":465},{},[466],{"type":28,"value":206},{"type":28,"value":208},{"type":22,"tag":61,"props":469,"children":470},{},[471,475],{"type":22,"tag":72,"props":472,"children":473},{},[474],{"type":28,"value":216},{"type":28,"value":218},{"type":22,"tag":30,"props":477,"children":478},{},[479],{"type":28,"value":223},{"type":22,"tag":36,"props":481,"children":482},{"id":226},[483],{"type":28,"value":229},{"type":22,"tag":30,"props":485,"children":486},{},[487,488,492,493,497],{"type":28,"value":234},{"type":22,"tag":236,"props":489,"children":490},{"href":17},[491],{"type":28,"value":240},{"type":28,"value":242},{"type":22,"tag":72,"props":494,"children":495},{},[496],{"type":28,"value":247},{"type":28,"value":78},{"type":22,"tag":36,"props":499,"children":500},{"id":251},[501],{"type":28,"value":254},{"type":22,"tag":30,"props":503,"children":504},{},[505],{"type":28,"value":259},{"type":22,"tag":186,"props":507,"children":508},{},[509,513,517],{"type":22,"tag":61,"props":510,"children":511},{},[512],{"type":28,"value":267},{"type":22,"tag":61,"props":514,"children":515},{},[516],{"type":28,"value":272},{"type":22,"tag":61,"props":518,"children":519},{},[520,521,525],{"type":28,"value":277},{"type":22,"tag":72,"props":522,"children":523},{},[524],{"type":28,"value":282},{"type":28,"value":78},{"type":22,"tag":36,"props":527,"children":528},{"id":286},[529],{"type":28,"value":289},{"type":22,"tag":30,"props":531,"children":532},{},[533,534,538],{"type":28,"value":294},{"type":22,"tag":236,"props":535,"children":536},{"href":297},[537],{"type":28,"value":300},{"type":28,"value":302},{"title":7,"searchDepth":304,"depth":304,"links":540},[541,542,543,544,545,546,547,548],{"id":38,"depth":307,"text":41},{"id":96,"depth":307,"text":99},{"id":114,"depth":307,"text":117},{"id":165,"depth":307,"text":168},{"id":176,"depth":307,"text":179},{"id":226,"depth":307,"text":229},{"id":251,"depth":307,"text":254},{"id":286,"depth":307,"text":289},1778601701170]