Prachi Khandekar, Sam Alexander, and Suejung Shin, Ketch
In order to fulfill data subject requests (DSRs), a structure of the rights request must be created and maintained from the time of intake, to the propagation to all data systems where Personal Information (PI) resides. What should this structure contain to perform effectively and efficiently? What exchanges are required to fulfill Delete and Access obligations?
The aim of this talk is to share how we developed and implemented a protocol based on the Data Rights Protocol, outlining standardized request and response data flows by which Data Subjects can exercise Personal Data Rights. The protocol is incorporated into our broader product's internal handshakes and specifies the payload structures for externally registered webhooks. I'll explain the decisions that drove the structures of these exchanges and lessons learned from implementation in practice. Lastly I'll share some areas of flexibility (e.g., "data subject variables") and discuss future applications for this build.
Prachi Khandekar, Ketch
Prachi Khandekar is a Software Engineer at Ketch. After graduating from UC Berkeley with a degree in Computer Science, Prachi worked at Nextdoor and then at Affirm, a Fintech company, where she was first exposed to the challenges of working with PI data at scale. Prachi now builds the scalable data privacy automation platform at Ketch.
Sam Alexander, Ketch
Sam Alexander is a Data Privacy Engineer at Ketch. He previously worked as an engineer for Zendesk and KVH and has a degree in Computer Science and Math from Brown University.
Suejung Shin, Ketch
Suejung Shin is a Senior Software Engineer at Ketch where she has spent the last 4 years building privacy solutions for a span of organizations from budding businesses to multinational corporations.
author = {Prachi Khandekar and Sam Alexander and Suejung Shin},
title = {Building a Protocol to Improve {DSR} Flexibility and Integration},
year = {2024},
address = {Santa Clara, CA},
publisher = {USENIX Association},
month = jun
}