Data Subject Rights (DSR) Procedure
Company: Abbara Sounds, Inc.Effective Date: January 1, 2026Owner: Abbara Sounds, Inc.Version: 1.0
1. Purpose
This document sets out Abbara Sounds, Inc.’s (“Abbara”) internal procedures for receiving, verifying, responding to, and documenting requests from individuals (“Data Subjects”) to exercise privacy rights under applicable data protection laws, including the GDPR and UK GDPR, and—where relevant—U.S. state privacy laws (e.g., CCPA/CPRA, Virginia, Colorado, Connecticut, Utah).
2. Scope
This procedure applies to:
all Data Subject Rights requests relating to personal data processed by Abbara in connection with abbarasounds.com and its subdomains, and related services; and
all Abbara personnel and contractors who may receive, route, or handle DSRs.
This procedure does not replace legal advice. If a request is complex, high risk, or involves sensitive issues, escalate per Section 12.
3. Definitions
DSR: Data Subject Rights request (access, deletion, rectification, portability, restriction, objection, etc.).
Requester: the individual submitting the DSR, or their authorized agent.
Personal Data: information relating to an identified or identifiable person.
Verification: steps to reasonably confirm the Requester’s identity.
4. Roles and Responsibilities
DSR Owner (Privacy Lead): Yusuf Demir AkcayResponsible for intake oversight, deadline tracking, approvals, and final responses.
Support Team: receives inbound requests, creates a ticket, and routes to DSR Owner.
Engineering/IT: executes data pulls/deletion/rectification, and provides system notes.
Legal Counsel: reviews escalations, denials, and high-risk requests.
Vendors/Subprocessors: provide assistance where Abbara is controller and vendor is processor.
5. Accepted Intake Channels
DSRs may be received through:
Email: notice@abbarasounds.com
Support portal: https://abbarasounds.com/pages/contact
Mail: 2093 Philadelphia Pike #8865 Claymont, DE 19703
Other channels (social media, general support inboxes): must be forwarded within 1 business day to the DSR Owner.
6. Initial Triage (Within 2 Business Days)
Upon receipt:
Create a DSR ticket.
Record: date/time received, channel, request type(s), jurisdiction (if known), and any identifiers (email, account ID, order ID).
Confirm whether request relates to Abbara (vs. third party).
Send acknowledgement (Template A).
Determine whether verification is required and appropriate (Section 7).
Start deadline tracking (Section 8).
7. Identity Verification Standard
7.1 General Rule Verify identity to a reasonable degree based on:
sensitivity of data requested;
risk of harm from unauthorized disclosure; and
whether the request is for access/portability (higher risk) vs. general inquiries.
7.2 Verification Methods (Preferred Order)
Logged-in account: Require request submission from the account email and confirm via authenticated session.
Email verification: Reply to the account email and require confirmation via a verification link or code.
Order verification: Confirm an order number plus billing email and last 4 digits of payment method (if available through processor metadata).
Additional verification (only if needed): request an additional piece of information already on file (do not request new sensitive data unless strictly necessary).
7.3 Authorized Agents If an agent submits a request:
require proof of authorization (signed permission or power of attorney); and
verify the Data Subject’s identity separately where required by law.
7.4 Insufficient Verification If identity cannot be verified, request additional information (Template B). If still unverifiable, deny (Template E) and document the basis.
8. Deadlines and Extensions
8.1 GDPR/UK GDPR
Respond within 1 month of receipt.
Extension: up to 2 additional months for complex or numerous requests, with notice within the original 1 month explaining reasons.
8.2 U.S. State Privacy (If Applicable)
Track state-specific deadlines (e.g., 45 days under CPRA, with extensions in some cases).
Where a user’s location is unclear, default to the stricter timeline.
8.3 Internal Targets
Acknowledge receipt: within 2 business days.
Complete verification: within 7 calendar days (target).
Fulfill simple requests: within 21 calendar days (target).
9. Request Types and Handling Steps
9.1 Right of Access (GDPR Art. 15)
Goal: Provide a copy of personal data and required disclosures.Steps:
Confirm scope (account data only vs. all systems).
Export data from systems (Section 10).
Review for third-party personal data and redact where required.
Provide required disclosures: purposes, categories, recipients, retention, source, transfers, and rights.
Deliver securely (Section 11).
9.2 Right to Rectification (GDPR Art. 16)
Steps:
Confirm what data is inaccurate.
Update in source systems (account profile, billing records where permitted).
Where data must be retained unchanged for legal reasons (e.g., invoices), record a note/correction rather than altering the record.
Confirm completion.
9.3 Right to Erasure / Deletion (GDPR Art. 17)
Steps:
Confirm whether an exception applies (e.g., legal obligation, establishment/defense of claims, fraud prevention).
If eligible, delete or irreversibly anonymize across systems where feasible.
Maintain a suppression list entry (e.g., hashed email) if needed to respect opt-outs and prevent re-collection, to the extent permitted by law.
Confirm completion and note any retained data categories and basis.
9.4 Right to Restriction (GDPR Art. 18)
Steps:
Flag account and limit processing (e.g., pause marketing, limit profiling/analytics where applicable).
Implement technical restriction where feasible.
Notify Requester when restriction is lifted (if applicable).
9.5 Right to Data Portability (GDPR Art. 20)
Steps:
Provide data the Data Subject provided to Abbara and data processed by automated means based on contract/consent.
Provide in a structured, commonly used, machine-readable format (e.g., JSON/CSV).
Deliver securely.
9.6 Right to Object (GDPR Art. 21)
Steps:
Direct marketing objection: honor promptly (unsubscribe/suppress).
Legitimate interests objection: assess and document balancing test; stop processing unless compelling legitimate grounds exist.
9.7 Withdraw Consent (GDPR)
Steps:
Identify processing based on consent (e.g., non-essential cookies; marketing where consent-based).
Apply withdrawal (cookie settings / email preference).
Record completion.
9.8 Automated Decision-Making (GDPR Art. 22)
If applicable, provide information and enable human review. If not used, confirm “not applicable.”
10. Data Map: Systems to Search (Template)
Minimum systems to review for most requests:
User Accounts/DB: [SYSTEM NAME]
Admin/CRM: [SYSTEM NAME]
Email marketing: [SYSTEM NAME]
Support platform: [SYSTEM NAME]
Payments processor: [SYSTEM NAME]
Analytics: [SYSTEM NAME]
File delivery/logs (downloads): [SYSTEM NAME]
Security logs: [SYSTEM NAME]
For each DSR, record:
systems searched,
data exported/deleted,
exceptions, and
the person completing each step.
11. Secure Delivery Standards
Provide access/portability exports via: encrypted file + separate password channel, secure portal, or time-limited link.
Do not include sensitive credentials.
Do not send personal data exports as unencrypted email attachments.
Keep a record of delivery method and date.
12. Exceptions, Refusals, and Escalations
Escalate to Legal Counsel and the DSR Owner before refusing or limiting a request when:
identity cannot be verified;
the request is manifestly unfounded or excessive;
requests involve suspected fraud or account takeover;
fulfilling would disclose third-party personal data or trade secrets; or
Abbara must retain data for legal obligations (tax/accounting, chargebacks, litigation hold).
Any refusal or partial refusal must include:
the reason (legal basis);
what was not provided/deleted and why; and
instructions on how to complain to a supervisory authority (GDPR/UK GDPR) where applicable.
13. Recordkeeping and Audit Log
Maintain a DSR log with:
ticket ID,
requester identifiers (minimized),
request type,
verification steps,
dates (received/verified/responded),
outcome (fulfilled/partial/denied),
systems involved,
any vendors contacted,
response template used, and
reviewer approvals (if applicable).
Retention of DSR logs: 3 YEARS (or as required by law).
14. Vendor/Subprocessor Coordination
If a vendor processes personal data as Abbara’s processor:
Send a vendor assistance request with the ticket ID and scope.
Track vendor SLA.
Collect vendor confirmation of completion (deletion/export) and attach to the DSR ticket.
15. Templates
Template A — Acknowledgement
Subject: We Received Your Privacy Request
Hello [NAME],We have received your privacy request on [DATE]. To protect your information, we may need to verify your identity before completing the request. We will respond within the time period required by applicable law.
If you have questions, contact us at notice@abbarasounds.com— Abbara Sounds, Inc.
Template B — Verification Needed
Subject: Verification Required for Your Privacy Request
Hello [NAME],To process your request, we need to verify your identity. Please reply from the email address associated with your account and confirm the following: [E.G., USERNAME AND MOST RECENT ORDER ID].
Once verified, we will proceed with your request.— Abbara Sounds, Inc.
Template C — Fulfilled (Access/Portability)
Subject: Response to Your Privacy Request
Hello [NAME],We have completed your request. Your personal data file is available here: [SECURE LINK] (expires [DATE]). The password will be provided via [CHANNEL].
If you have questions, contact us at contact@abbarasounds.com.— Abbara Sounds, Inc.
Template D — Fulfilled (Deletion)
Subject: Confirmation of Deletion Request
Hello [NAME],We have processed your deletion request. We deleted or anonymized personal data associated with your account to the extent required and permitted by law. We may retain certain information where necessary for legal obligations (e.g., accounting/tax records) or to protect against fraud.
— Abbara Sounds, Inc.
Template E — Denial or Partial Denial
Subject: Response to Your Privacy Request
Hello [NAME],We are unable to fully complete your request because: [REASON]. Where applicable, we have completed the portions of your request that we can.
If you are located in the EU/EEA or UK, you may lodge a complaint with your local supervisory authority (or the UK ICO). You may also contact us at notice@abbarasounds.com— Abbara Sounds, Inc.
16. Training and Review
Train relevant staff annually and upon material changes.
Review this procedure at least annually and after any material changes to data systems or applicable laws.
17. Appendices
Appendix 1 — DSR Intake Checklist
Ticket created and categorized
Jurisdiction assessed (EU/UK/US/Other)
Verification completed (or not required)
Systems identified
Vendor requests sent (if needed)
Response drafted and approved
Response delivered securely
Log updated and closed
Appendix 2 — Balancing Test Note (Legitimate Interests Objection)
Processing purpose: [PURPOSE]
Legitimate interest: [INTEREST]
Impact on individual: [IMPACT]
Safeguards: [SAFEGUARDS]
Outcome: [CONTINUE/STOP]