Data Correction Request Procedures


FieldValue
Version1.0
Effective DateApril 2026
Review CycleAnnual
Document OwnerChief Information Security Officer (CISO)
ClassificationCONFIDENTIAL — Internal Use Only
Applicable StandardSOC 2 Type II — Security, Availability, Confidentiality

1. Purpose and Scope

This document defines the written procedures for processing Data Subject Correction Requests — requests from individuals to correct, amend, or update inaccurate or incomplete personal information held by QA Touch. It ensures corrections are processed accurately, timely, and with appropriate verification, in compliance with GDPR Article 16, CCPA, and PIPEDA. Supports SOC 2 Privacy criterion P7.1 (Correction of Personal Information).

2. Types of Correction Requests

  • Factual correction: correction of objectively inaccurate data (e.g., misspelled name, incorrect email address).
  • Update request: updating data that was accurate but has since changed (e.g., new email address, updated role).
  • Completion request: adding missing information to an incomplete record.
  • Annotation: where QA Touch contests the correction but cannot verify accuracy either way, a note of dispute may be added to the record rather than a direct correction.

3. Correction Request Process

#ActivityResponsible PartyTimeline
1Data subject submits correction request via the online Data Request Form [VERIFY URL], selecting ‘Correct My Data’, or via email to privacy@qatouch.com [VERIFY]. Request must specify: (a) the data element to be corrected, (b) the current (incorrect) value, and (c) the correct value.Data SubjectAnytime
2Automated acknowledgement email sent with unique DSR tracking ID.System (automated)Within 24 hours of submission
3Request logged in DSR tracking system: requestor details, request type = CORRECTION, data element, current value, requested corrected value, DSR ID.Privacy / Compliance TeamWithin 24 hours
4Identity of requestor verified per Authentication and Verification Records (Document 22). No correction actioned before verified identity confirmed.Privacy / Compliance TeamWithin 5 business days
5Request reviewed for reasonableness: Is the correction factually plausible? Is supporting evidence provided or needed? Does the data element exist in QA Touch’s systems?Privacy / Compliance TeamWithin 10 calendar days of verification
6Correction actioned: Engineering / DBA updates the record in the relevant data system(s). Change is logged in the audit trail with actor = Privacy Team (DSAR action), previous value, new value, timestamp.Privacy / Compliance Team + EngineeringWithin 20 calendar days of verification
7Third-party notification: if the corrected data was previously shared with sub-processors or integration partners, those systems are notified of the correction where technically feasible.Privacy / Compliance TeamWithin 25 calendar days of verification
8Written confirmation sent to requestor: confirmation of data corrected, effective date, and (if applicable) which third parties were notified.Privacy / Compliance TeamWithin 30 calendar days of verification
9DSR record updated: correction made, parties notified, confirmation sent, request closed.Privacy / Compliance TeamOn completion

4. Self-Service Corrections Available in QA Touch

QA Touch provides self-service correction capabilities within the platform for certain personal data elements, reducing the need for a formal DSR process:

Data ElementSelf-Service MechanismNotes
Display Name (First / Last Name)User Settings → Profile → Edit NameChanges take effect immediately; reflected in all workspace views.
Email AddressUser Settings → Account → Change EmailNew email address verified via confirmation email before change takes effect.
PasswordUser Settings → Security → Change PasswordOld password required for verification; new password must meet complexity policy.
Profile PhotoUser Settings → Profile → Upload / Remove PhotoPrevious photo deleted on upload of new photo.
Notification PreferencesUser Settings → NotificationsTakes effect immediately.
MFA MethodUser Settings → Security → Manage MFAExisting MFA method removed and new method enrolled.

ACTION REQUIRED: Encourage data subjects to use self-service corrections where available before submitting a formal DSR, as self-service changes are immediate.

5. Grounds for Declining a Correction Request

  • The data element cited is not personal data held by QA Touch as a controller (e.g., customer test case content managed by the customer as controller).
  • The requestor cannot provide sufficient evidence that the current value is inaccurate.
  • The correction conflicts with a verified legal record (e.g., court order, verified identity document on file).
  • The data in question is audit log data or compliance records where retrospective modification would undermine their integrity.

When a request is declined, the requestor is informed within 30 calendar days of the reason and their right to lodge a complaint with the relevant supervisory authority.

6. Record Retention

  • All correction request records retained for 3 years after DSR completion.
  • Audit log entry for the correction (original value, corrected value, actor, timestamp) retained per the standard audit log retention schedule (36 months).