Data Subject Self-Service Portal

November 4, 2021

Architecture

Data Subject Self-Service Portal

Features

The eStealth Data Subject Self-Service Portal lets the data source view all the data stored in the data vault and correct wrong data. The data subject may add and delete data according to the business rules stored in the profile.

Additionally the portal allows the data subject to edit the consents given for certain purposes (add and delete).

  • If the data subject adds a consent then the portal is aware of the required data for the consent of this purpose and prompts the data subject to input the minimum required data.
  • If the data subject withdraws a consent then the eStealth Core deletes all the data no longer required by any other consent.

The data subject may also request to delete all the data about her. This request is asynchronous; the eStealth Code deletes the data as soon as all running activities that need some data for processing (for example the postal address needed by an order that is currently delivered). Additionally, the portal allows the data subject to export her data in a machine-readable form.

Private Information Data Attribute Management

Data Attribute Management

  • Show all datasets
  • Forked datasets are indented underneath origin dataset
  • Datasets are grouped by purpose
  • Color is only for demo, not to be implemented

Consent Management

  • Simple toggles
  • Friedly descriptions

Processing Log

Request Log

  • Single timeline (like a chat)
  • Possibility to select/reference data sets
  • Used for deletion, modification, and locking requests
  • Currently only limited “self-service”
  • Full self-service would require specifying which changes are possible and support powerful validation. (Out of scope for MVP)

Export

Request Log

  • Export your private information managed by eStealth for transparency, documentation, and transfer to other data processors