Data Subject Consent Forms Corrections
| Field | Value |
|---|---|
| Version | 1.0 |
| Effective Date | April 2026 |
| Review Cycle | Annual |
| Document Owner | Chief Information Security Officer (CISO) |
| Classification | CONFIDENTIAL — Internal Use Only |
| Applicable Standard | SOC 2 Type II — Security, Availability, Confidentiality |
1. Purpose and Scope
This document provides the templates and guidance for consent and confirmation forms used when a data subject provides written authorisation for corrections or amendments to their personal information held by QA Touch. It ensures correction actions are documented, authorised, and auditable. Supports SOC 2 Privacy criterion P7.1 and GDPR Article 16.
Note: most data correction requests at QA Touch do not require a separate consent form — correction is a legal right of the data subject. However, certain scenarios require written confirmation to protect both parties: corrections to verified identity data, corrections where QA Touch cannot verify accuracy independently, or corrections requested by authorised third parties.
2. Scenarios Requiring Written Confirmation
| Scenario | Why Confirmation Is Needed | Applicable Form |
|---|---|---|
| Correction to registered email when original is inaccessible | Prevents account takeover via fraudulent DSR claiming email change. | Form A — Email Change Confirmation |
| Correction affecting records visible to other workspace users | Data subject acknowledges the correction will affect records visible to colleagues. | Form B — Shared Record Correction Confirmation |
| Correction QA Touch cannot independently verify | Documents that correction was made on data subject’s attestation; limits QA Touch liability. | Form C — Unverifiable Correction Attestation |
| Correction requested by authorised third party on behalf of data subject | Confirms data subject has reviewed and authorised the specific correction. | Form D — Third-Party Authorised Correction |
3. Form A — Email Address Change Confirmation
Used when a data subject requests an email address correction and can no longer access the original registered email.
FORM A — QA TOUCH EMAIL CHANGE CONFIRMATION
DSR Reference: DSR-[____________________] Date: [YYYY-MM-DD]
I, [Full Name: ________________________________], confirm that:
- My current registered email address in QA Touch is: [current-email@domain.com]
- I am requesting this be updated to: [new-email@domain.com]
- I can no longer access the original registered email address.
- I have provided the following government-issued identity document: Document Type: [ ] Passport [ ] Driver’s Licence [ ] National ID [ ] Other: ________ (Redacted copy showing name and photo only; reference retained per Section 7.)
- I authorise QA Touch to update my registered email address to the new address provided.
- I understand QA Touch will send a verification link to the new email before the change takes effect.
[ ] I confirm I have read and understood QA Touch’s Privacy Policy.
Full Name (print): ________________________________ Signature: ________________________________ Date: ________________
ACTION REQUIRED: QA Touch staff: retain completed Form A in the DSR tracking system. Identity document copy must be deleted within 30 days of request closure.
4. Form B — Shared Record Correction Confirmation
Used when a correction to the data subject’s personal data will affect records visible to other authorised users within the same QA Touch workspace.
FORM B — SHARED RECORD CORRECTION CONFIRMATION
DSR Reference: DSR-[____________________] Date: [YYYY-MM-DD]
I, [Full Name: ________________________________], confirm that:
- I am requesting a correction to the following data: Data element / field: [] Record / context (e.g., project name, test run): []
- Current (incorrect) value: [________________________________]
- Correct value: [________________________________]
- Reason for correction: [________________________________]
- I acknowledge that this correction will update records visible to other authorised users in my workspace.
- I confirm this correction is factually accurate to the best of my knowledge.
- I authorise QA Touch to make this correction on my behalf.
Full Name (print): ________________________________ Signature: ________________________________ Date: ________________
5. Form C — Unverifiable Correction Attestation
Used when QA Touch cannot independently verify the accuracy of the requested correction. The data subject attests to the correct value on the basis of their own knowledge.
FORM C — UNVERIFIABLE CORRECTION ATTESTATION
DSR Reference: DSR-[____________________] Date: [YYYY-MM-DD]
I, [Full Name: ________________________________], confirm that:
- I am requesting a correction to: [data element: ________________]
- Current value on record: [________________________________]
- Value I believe to be correct: [________________________________]
- I understand that QA Touch has been unable to independently verify the accuracy of the corrected value.
- I attest that the corrected value is, to the best of my knowledge, accurate and complete.
- I understand QA Touch will make this correction in good faith based on my attestation and will note in the record that the correction was applied on data subject attestation.
- I accept responsibility for the accuracy of the information I have provided.
Full Name (print): ________________________________ Signature: ________________________________ Date: ________________
6. Form D — Third-Party Authorised Correction
Used when an authorised representative acts on behalf of the data subject for a correction request (e.g., legal guardian, solicitor, holder of power of attorney).
FORM D — THIRD-PARTY AUTHORISED CORRECTION CONFIRMATION
DSR Reference: DSR-[____________________] Date: [YYYY-MM-DD]
DATA SUBJECT DETAILS Full Name: ________________________________ Email on record: ________________________________
AUTHORISED REPRESENTATIVE DETAILS Full Name: ________________________________ Relationship to data subject: [ ] Legal Guardian [ ] Solicitor [ ] Power of Attorney [ ] Other: _______ Contact Email: ________________________________
CORRECTION REQUESTED Data element to correct: ________________________________ Current (incorrect) value: ________________________________ Correct value: ________________________________ Reason for correction: ________________________________
AUTHORISATION BY DATA SUBJECT I, [Data Subject Full Name], confirm I have reviewed this correction request and the corrected value is accurate. I authorise [Representative Name] to act on my behalf for this specific request.
Data Subject Signature: ________________________________ Date: ________________
AUTHORISATION BY REPRESENTATIVE Representative Signature: ________________________________ Date: ________________
Supporting authority document: [ ] Attached ([document type]: ________________) [ ] Not applicable (reason: ________________)
7. Form Retention and Security
- All completed confirmation forms stored securely in the DSR management system; access restricted to Privacy/Compliance team only.
- Forms and supporting documents retained for 3 years after request completion.
- Identity document copies (Form A) deleted within 30 days of request closure.
- Forms transmitted electronically must be sent over encrypted channels (TLS-secured email or secure file transfer).
- Completed forms are never stored in the main QA Touch application database; stored in the separate compliance document management system.