CS-W18 — Privacy-verzoek (AVG / DSAR) · ISO 27001Privacy request (GDPR / DSAR) · ISO 27001

Versie:Version: 1.0-27001 Proceseigenaar:Process owner: [CS Manager] — Klant Gerelateerd:Related: CS-W17 Klik op een stap voor details + beveiligingsmappingClick a step for details + security mapping
Doel: inzage- en verwijderverzoeken (incl. account verwijderen) correct en binnen de wettelijke termijn afhandelen.  |  Termijn: 1 maand (AVG).
Goal: handle access and deletion requests (incl. account deletion) correctly and within the legal term.  |  Term: 1 month (GDPR).

🔒 ISO 27001-scan · dataveiligheid (+ AVG)ISO 27001 scan · data security (+ GDPR)

Privacyverzoek = maximaal datagevoelig proces. Elke stap verwerkt persoonsgegevens; de terugkoppel-stap (data-export) is het grootste lek-risico. De swimlane toont al de dataflow en de kernrisico's (identiteit streng, bewaarplicht). Van de 8 stappen is de beveiligingsmaatregel bij 3 al aanwezig, bij 5 uit systeem/beleid te halen — met als belangrijkste: een veilig, versleuteld exportkanaal (A.5.14). ISMS-fundament (risicobeoordeling + SoA) blijft op procesniveau een aparte to-do.
Privacy request = maximally data-sensitive process. Every step processes personal data; the report-back step (data export) is the biggest leak risk. The swimlane already shows the data flow and the core risks (strict identity, retention). Of the 8 steps, the security control is already present for 3 and light to gather for 5 — chief among them a secure, encrypted export channel (A.5.14). ISMS core (risk assessment + SoA) remains a separate process-level to-do.
3 Maatregel aanwezigControl in place
5 Uit systeem/beleidFrom system/policy
ISMS SoA + risico op procesniveauSoA + risk at process level
Document-IDCS-W18
VersieVersion1.0-27001
ProceseigenaarProcess ownerTeamlead / Supervisor
SoA-referentie (A.5–A.8)SoA reference (A.5–A.8)KoppelenTo link
DPO + risicobeoordelingDPO + risk assessmentVast te leggenTo be set
Datclassificatie (stip)Data classification (dot)
OpenbaarPublic
InternInternal
PersoonsgegevensPersonal data
Bijzondere pers.geg.Special category
🔒 = maatregel-status🔒 = control status
🔒AanwezigIn place
🔒Uit systeem/beleidFrom system/policy
KlantCustomer
1
Klant: privacyverzoekCustomer: privacy request
7
Afgehandeld binnen termijnHandled within term
AgentAgent
2
Identiteit verifiërenVerify identity
3
Registreren + termijn startenRegister + start term
6
Terugkoppelen (export / bevestiging)Report back (export / confirmation)
DPO / LegalDPO / Legal
4
Data verzamelen / verwijderenCollect / delete data
5
Juridische checkLegal check
R
Uitzondering: wettelijke bewaarplichtException: legal retention
← Terug naar overzicht← Back to overview