Data Processing Basis
As a Data Controller, to be GDPR compliant you need to process data based on one of the lawful bases. Based on your business requirement and discretion you can choose a processing basis from the list of bases: legitimate interests, contract, legal obligation, vital interests, public interests, and consent. If consent is the lawful basis used to process data, the CRM provides an option to allow portal users to access the details you store about them, and provide consent to process their personal data.
You must consider the below points when setting data privacy for the portal users:
- The data privacy tab will be displayed for a record only if the compliance settings are turned on.
- The portal user can view the data processing basis in their account only if the data processing basis is Consent.
- The portal user can also update the consent details of the leads or contacts that they have added.
- The portal user can update their consent details from within the portal.
Data Subject Rights
Under GDPR, the portal users have certain rights regarding their personal information. They can manually add a request from the data privacy section in the portal for the following rights:
- Right to delete
- Right to stop processing
- Right to export
- Right to rectify
They can also add requests in the portal on behalf of the contacts or leads that they add to the portal.