Manage a personal-data request
Use this workflow to locate and handle information for an access, correction, portability, restriction, or erasure request. Finsaku helps locate and change supported information, but it does not determine the person's identity, the legal outcome, applicable exemptions, or statutory retention period.
- For
- Privacy, compliance, operations, and authorised administrators handling an approved personal-data request.
- Requires
- Approved request scope, verified identity, access to the relevant records and history, and an organisation procedure for disclosure or deletion.
- Available when
- The organisation has identified the person and the applicable Finsaku tenant, affiliations, products, and connected providers.
- Before you begin
- Record the request date, legal deadline, request type, decision owner, required retention, and systems included in the search.
- Expected result
- The request decision and actions are complete across Finsaku and connected systems, with evidence of review and any retained exceptions.
Define the scope
Confirm the person, legal capacity of the requester, tenant, date range, request type, and the information that must be included. Establish whether the organisation must preserve lending, accounting, fraud-prevention, AML/CFT, complaint, or legal-claim information before changing anything.
One Finsaku export is not a complete response. Information can also exist in documents, messages, enrichment providers, identity services, payment providers, logs, backups, support systems, and customer-controlled integrations.
Locate the Finsaku information
- Use global search and the configured person lists to find the person. Check alternative identifiers and duplicate person entries.
- Open the person and review related applications, loans, payments, documents, messages, notes, labels, enrichment results, and history.
- Review affiliations and intermediary access where the person used a partner channel.
- Use saved queries and controlled exports for the record types and date ranges included in the request.
- Identify connected providers from the integration and event-action history.
- Record systems and copies that need a separate search.
See Person records, Lists, search, and export, and Audit trail.
Apply the approved outcome
| Request outcome | Work in Finsaku | Work outside Finsaku |
|---|---|---|
| Access | Gather relevant views, exports, documents, messages, and history, then review the package before disclosure. | Add provider-held and support-held information, apply exemptions and redactions, approve the recipient and format, and deliver securely. |
| Rectification | Correct supported current fields and verify the resulting application, loan, document, calculation, query, or integration output. | Notify recipients when required and decide how historical evidence or issued documents must be preserved. |
| Portability | Export the supported information in the approved scope and verify identifiers, columns, dates, amounts, and completeness. | Select the required machine-readable format and secure transfer method; include other systems where applicable. |
| Restriction | Apply the organisation's approved access, status, workflow, or operational controls without destroying required evidence. | Prevent unintended processing in connected systems and record the restriction, exceptions, review date, and release authority. |
| Erasure | Remove supported data only after dependency and retention review. Finsaku has no single action that erases every related copy. | Coordinate documents, exports, integrations, provider copies, logs, backups, and legally retained evidence according to the approved plan. |
Deleting a person, lookup, document, payment, or configuration item can affect linked lending information and later reconciliation. Do not use individual delete controls as a substitute for an approved erasure plan.
Check connected providers
Use Integration data flows to identify information sent outside Finsaku. For each provider, establish:
- whether Finserio or the customer owns the account;
- the provider's legal role and request procedure;
- copies, derived results, and generated documents it retains;
- deletion or restriction confirmation;
- transfers to the provider's own subprocessors.
Verify and close the request
Before closing:
- compare the completed work with the approved scope;
- check related records and downstream outputs after any correction or deletion;
- confirm external-provider actions or record why an exception remains;
- record the decision, searches, approvals, disclosures, retained information, and completion date in the organisation's request register;
- schedule any later deletion or restriction review required by backups or statutory retention.
The request register should not be replaced by a free-text note on the person's record. Access to privacy-case evidence can differ from ordinary lending access.