Data Correction Request Procedures
| Field | Value |
|---|---|
| Version | 1.0 |
| Effective Date | April 2026 |
| Review Cycle | Annual |
| Document Owner | Chief Information Security Officer (CISO) |
| Classification | CONFIDENTIAL — Internal Use Only |
| Applicable Standard | SOC 2 Type II — Security, Availability, Confidentiality |
1. Purpose and Scope
This document defines the written procedures for processing Data Subject Correction Requests — requests from individuals to correct, amend, or update inaccurate or incomplete personal information held by QA Touch. It ensures corrections are processed accurately, timely, and with appropriate verification, in compliance with GDPR Article 16, CCPA, and PIPEDA. Supports SOC 2 Privacy criterion P7.1 (Correction of Personal Information).
2. Types of Correction Requests
- Factual correction: correction of objectively inaccurate data (e.g., misspelled name, incorrect email address).
- Update request: updating data that was accurate but has since changed (e.g., new email address, updated role).
- Completion request: adding missing information to an incomplete record.
- Annotation: where QA Touch contests the correction but cannot verify accuracy either way, a note of dispute may be added to the record rather than a direct correction.
3. Correction Request Process
| # | Activity | Responsible Party | Timeline |
|---|---|---|---|
| 1 | Data subject submits correction request via the online Data Request Form [VERIFY URL], selecting ‘Correct My Data’, or via email to privacy@qatouch.com [VERIFY]. Request must specify: (a) the data element to be corrected, (b) the current (incorrect) value, and (c) the correct value. | Data Subject | Anytime |
| 2 | Automated acknowledgement email sent with unique DSR tracking ID. | System (automated) | Within 24 hours of submission |
| 3 | Request logged in DSR tracking system: requestor details, request type = CORRECTION, data element, current value, requested corrected value, DSR ID. | Privacy / Compliance Team | Within 24 hours |
| 4 | Identity of requestor verified per Authentication and Verification Records (Document 22). No correction actioned before verified identity confirmed. | Privacy / Compliance Team | Within 5 business days |
| 5 | Request reviewed for reasonableness: Is the correction factually plausible? Is supporting evidence provided or needed? Does the data element exist in QA Touch’s systems? | Privacy / Compliance Team | Within 10 calendar days of verification |
| 6 | Correction actioned: Engineering / DBA updates the record in the relevant data system(s). Change is logged in the audit trail with actor = Privacy Team (DSAR action), previous value, new value, timestamp. | Privacy / Compliance Team + Engineering | Within 20 calendar days of verification |
| 7 | Third-party notification: if the corrected data was previously shared with sub-processors or integration partners, those systems are notified of the correction where technically feasible. | Privacy / Compliance Team | Within 25 calendar days of verification |
| 8 | Written confirmation sent to requestor: confirmation of data corrected, effective date, and (if applicable) which third parties were notified. | Privacy / Compliance Team | Within 30 calendar days of verification |
| 9 | DSR record updated: correction made, parties notified, confirmation sent, request closed. | Privacy / Compliance Team | On completion |
4. Self-Service Corrections Available in QA Touch
QA Touch provides self-service correction capabilities within the platform for certain personal data elements, reducing the need for a formal DSR process:
| Data Element | Self-Service Mechanism | Notes |
|---|---|---|
| Display Name (First / Last Name) | User Settings → Profile → Edit Name | Changes take effect immediately; reflected in all workspace views. |
| Email Address | User Settings → Account → Change Email | New email address verified via confirmation email before change takes effect. |
| Password | User Settings → Security → Change Password | Old password required for verification; new password must meet complexity policy. |
| Profile Photo | User Settings → Profile → Upload / Remove Photo | Previous photo deleted on upload of new photo. |
| Notification Preferences | User Settings → Notifications | Takes effect immediately. |
| MFA Method | User Settings → Security → Manage MFA | Existing MFA method removed and new method enrolled. |
ACTION REQUIRED: Encourage data subjects to use self-service corrections where available before submitting a formal DSR, as self-service changes are immediate.
5. Grounds for Declining a Correction Request
- The data element cited is not personal data held by QA Touch as a controller (e.g., customer test case content managed by the customer as controller).
- The requestor cannot provide sufficient evidence that the current value is inaccurate.
- The correction conflicts with a verified legal record (e.g., court order, verified identity document on file).
- The data in question is audit log data or compliance records where retrospective modification would undermine their integrity.
When a request is declined, the requestor is informed within 30 calendar days of the reason and their right to lodge a complaint with the relevant supervisory authority.
6. Record Retention
- All correction request records retained for 3 years after DSR completion.
- Audit log entry for the correction (original value, corrected value, actor, timestamp) retained per the standard audit log retention schedule (36 months).