Case study - A company in the FinTech industry
Context
Following a data breach, a French cryptocurrency company faced an unexpected surge in data subject rights requests from customers who were informed through the media about the breach. In addition to the loss of customers, the company anticipated potential financial penalties in case of investigations by the data protection authority due to delays in responding to the requests and lack of compliance documents.
Objectives
To strengthen its GDPR compliance, the company chose to centralize all data processing activities within a single, online record of processing, hosted on the Dastra platform. It also engaged its data scientists and subject matter experts to actively contribute to enriching the documentation. In parallel, it streamlined the collection and classification of data subject requests by integrating Dastra’s widget directly into its website.
Results
In a few weeks:
- 228 data subject rights requests collected and managed
- 24 data processing activities documented
- 8 action plans defined (one per department) with detailed tasks and responsible parties
- 5 product enhancements implemented by Dastra at the client's request