This guide describes how certain features and functionality in Zendesk Sunshine can assist with your obligations under privacy law. Zendesk Sunshine includes profiles, events, custom objects, and the Sunshine UI.
To learn more about meeting your obligations in other Zendesk products, see遵守隐私和数据保护法律Zendesk products.
In this guide, users can be End-Users or Agents as the terms are defined in theMaster Subscription Agreement.
Meeting an access obligation
Individuals from certain regions have aright of access. On request, you may have an obligation to inform an end user or agent where their personal data is being held and for what purposes.
Sunshine profiles, events, and custom objects authenticates callers to its API using either basic authentication with your email address and password, with your email address and an API token, or with an OAuth access token.
Access to Sunshine profiles and events data using APIs can be limited to access to a single business account.
With respect to audits and logs, all generated logs are transferred and stored in a secured and encrypted location. In the event of suspected or confirmed unauthorized data access, Sunshine profiles, events, and custom objects can provide audit logs to help you investigate, respond to, and remediate the issue.
To export the data from profiles and events, please follow the steps described inMeeting a data portability obligation.
Meeting a correction obligation
个人从某些地区有权rectification, or the right to have inaccuracies in their personal data corrected. On request, you may have an obligation to provide the individual with their personal data and fix inaccuracies or add missing information.
To meet a correction obligation:
Sunshine profiles allows you to delete the existing information and re-create the personal data with the necessary fixes, orupdate or partially update an existing profile
Custom objects allows you to delete the existing information and re-create the personal data with the necessary fixes,update an existing object type, orupdate an existing object record
The Sunshine UI in the Admin Center allows you todelete an existing object type or relationship type. You can then re-create the object type or relationship type.
SeeMeeting an erasure obligationfor more detail.
Meeting an erasure obligation
Individuals from certain regions have a right to erasure, or the right to be forgotten or deleted. On request, you may have an obligation to delete the personal data of an individual.
Using the Sunshine Profiles API, you candelete a profileto delete a customer’s details and all events associated with the profile.
Using Custom Objects API, you candelete an object type,delete an object record,delete a relationship type,delete a relationship record. You can also runcustom object jobsto batch delete object records and relationship records.
Meeting a data portability obligation
Individuals from certain regions have a right to data portability. On request, you may have an obligation to provide an individual with their personal data or to transmit the data to another organization.
Businesses can export data about users including metadata to another system as required by privacy and data protection law. The feature exports data in a commonly used machine readable format (JSON), which can then be imported into another system. TheGet profile by identifier APIandGet profile by profile ID APIallows you to retrieve all of the personal data stored on a user.
TheGet events by Sunshine profile APIandGet events by Sunshine profile ID APIretrieves all the events associated with a user.
Meeting an objection obligation
Individuals from certain regions have a right of objection, or the right to object to direct marketing. You may have an obligation to stop processing personal data for direct marketing purposes when you receive an objection from an individual.
Since Sunshine profiles, events, custom objects, and the Sunshine UI do not actively offer direct marketing as a feature, it's up to the business to be aware of how the end user information is being used. With that, if the business wishes to meet this objection obligation within the platform, Sunshine profiles, events, and custom objects allows you to delete the existing information and re-create the personal data with the necessary fixes. SeeMeeting an erasure obligationfor more detail.
Disclaimer
This document is for informational purposes only and does not constitute legal advice. Readers should always seek legal advice before taking any action with respect to the matters discussed herein.
0 Comments
Pleasesign into leave a comment.