JustRelate CRM includes a “Privacy request” process for documenting any requests made by data subjects as defined in the GDPR. The administration form can be accessed from the Sales/Contacts/... main menu.
Request and information about stored data

Create privacy request from an e-mail
Managing a request as a case
Usually, requests are received via the usual communication channels (email, phone, fax, letter) and should first be recorded as an activity.
For emails, the email connector already offers the Create case/Privacy request function when synchronizing from the Groupware. This creates a data protection case and stores it in the data protection relationship with the person (sender of the email) under Additional data/Data protection/Cases.
If the email or the activity already exists in the system (phone call, letter) without a data protection case having been generated, open the person (sender, talk with...) and generate the data protection case of the Privacy request type using the GDPR Privacy request (new)... function.

Creating a privacy request at the person
Identity verification
Before answering a privacy request, the identity of the inquiring person must always be verified beyond doubt. Only then can a clear decision be made as to whether data has been stored and processed in the CRM system. Depending on this, the corresponding answer is then formulated, which in most cases is also stored as an activity in the CRM.
In order to support the request, it makes sense to store the corresponding response templates in PisaSales. The JustRelate CRM standard already includes the template for customizing, “E-Mail: GDPR information pursuant to Section 15 (German, BIRT)”.
Creating information
If a person exercises his/her right to information, the stored data must be communicated to the person immediately after detailed identity verification, but at the latest within one month.

Information on privacy request
The report is stored as a document with the person and can be attached when replying to the privacy request.
Report on the external person’s form
The JustRelate CRM standard provides a report, “Information according to Article 15 GDPR”, that compiles all stored personal data in a PDF document:
- Personal details such as names and titles,
- all communication data such as addresses, phone numbers and email addresses,
- if available, bank details and telephone log,
- purpose of the processing and the respective applicable legal basis,
- all active purposes of use with the web option set, each with the applicable legal basis,
- the corresponding protocol for each purpose of use.
Note: Activities, documents, service notifications, cases and contracts linked to the person are also to be seen as data with personal reference. In this case, the processor should decide for him/herself whether these are to be output or not. Activities can be output with or without content.
Under data protection law, the latter is not necessarily required according to Section 15 of the GDPR, and should only be considered at the specific request of the data subject. You can deselect the corresponding entries in the Report Manager. For cases and contracts, only the absolute header data is output, grouped by role.
Report on the internal person's form
The GDPR also applies to internal employees and their personal data in a company.
On the Internal staff members form (Administration/Contacts/Internal staff members), the "Disclosure according to article 15 GDPR" report has been provided. It provides information about the stored data of the internal employee.