An individual may ask what data BesluitBron holds about them, and may request that it be corrected or deleted. Since 1 March 2011, the management console has featured a screen for this purpose, entitled ‘Personal data requests’. This is the procedure.
Where a request is received
A request is sent to the address specified in the privacy statement. There is deliberately no form allowing individuals to submit a request themselves. On a service without user accounts, such a form would be a way of requesting data relating to an address chosen by the user, with verification of the requester’s identity taking place afterwards.
An administrator enters the request manually on the screen. The service then calculates the duration as one month and displays the number of days remaining on the dashboard.
The language of the reply
When creating a case file, the administrator selects the language: Dutch or English. This choice is fixed at the time of the request and determines the entire letter, from the header to the last field. If the case file is recreated at a later date, it will be in the same language, even if the administrator is now viewing the console in a different language.
There are two languages, not sixteen. Every sentence in a case file like this is handwritten. A machine-translated text could contain errors here that the reader cannot spot, and that is precisely why the legal pages of the website are available in four languages rather than sixteen.
First, establish who is making the request
No case file will be compiled until it has been established on what grounds it is assumed that the applicant is who he claims to be. There are three grounds:
- The reply will be sent to the email address already on file in the subscriber database, and nowhere else;
- The applicant is logged in on the console, so the account identifies the person;
- A practitioner writes, in a single sentence, why they believe the claim to be true. This forms the basis for a request relating to a network or a session, as these do not refer to a specific person.
A copy of an identity document is never stored. A service that collects passport scans to comply with the AVG has itself become the bigger problem.
What the service does, then
The screen searches every storage location used by the service: the log, the error table, the subscriber database, the accounts, the trace file, the temporary memory storage and the request log itself. For each storage location, the case file will specify its purpose, the legal basis for its retention, how long it will be retained, what has been found, and what happens in the event of a deletion request.
Searches are carried out only on whole values, never on parts of them. Searches are not carried out by name, nor are they carried out in the registers made available by BesluitBron: a name appearing in a council document or a ruling belongs to the administrative body or court that published it, and not to this service. See Openbaarheid en Persoonsgegevens.
What is not provided
If a request relates solely to an IP address, the number of records is counted and their nature described, but the content of those records is not disclosed. The recorded address has been truncated to a network, and that network is shared by many people. Disclosing the content would reveal the traffic of others.
If a storage device cannot be read, this is noted in the case file. A blank response that was in fact caused by a fault must not be interpreted as ‘nothing’.
What is stored
The case file is stored in the data folder, in a separate folder for each request, containing the response in JSON format and a draft letter. The case file is deleted ninety days after the request is closed. What remains is the entry in the register: what was requested, on what grounds, who processed it, and a hash of the case file that was sent. This makes it possible to demonstrate retrospectively that a response was provided, without having to retain the response itself.
The screen and the log require a database, and this has always been present from version 1.3.73 onwards, as the service will not start without it. Up to and including version 1.3.72, the screen reported that there was no database. A log of who has requested what should not be stored in a separate file. If there is still an old log file from before the switch, this is read alongside the request, so that the response remains complete.
What a removal request entails
For each storage location, a rating is given, along with the reason:
- the subscriber database: the address is deleted. It is there for the sole purpose of sending messages and nothing else;
- the log and the trace file: there is no entry that can be attributed to a single person, and the storage clears itself. The case file specifies the date on which the last entry was deleted;
- the error table: the same, except in the case of a report that has been classified as an attack. That remains on the table until its expiry date, and this is stated explicitly rather than being tacitly omitted;
- An account: this will not be deleted on request whilst it exists, as it is used to manage this system.