Skip to main content

privacyVersion 1SOC2GDPRCCPA

Data Subject Rights Policy

How Rex Black handles access, deletion, portability, and related rights.

Download PDFSHA-256 cbc0a6cc70d396d1…

Data Subject Rights Policy

1. Purpose

Defines how Rex Black receives, verifies, and responds to requests from data subjects (individuals whose personal data we process) to exercise their rights under GDPR, UK GDPR, CCPA/CPRA, and comparable laws.

2. Rights covered

Right GDPR CCPA/CPRA Rex Black action
Access / know Art.15 §1798.110 Provide copy + categories of data, sources, recipients.
Correction Art.16 §1798.106 Correct inaccuracies.
Deletion / erasure Art.17 §1798.105 Delete, subject to legal holds and retention obligations.
Portability Art.20 §1798.130 Export in a machine-readable format.
Restrict processing Art.18 , Pause processing pending resolution.
Object Art.21 , Stop processing absent overriding grounds.
Opt out of sale/share , §1798.120 N/A (Rex Black does not sell or share personal data).
Limit use of sensitive PI , §1798.121 Limit where requested.
Non-discrimination , §1798.125 Do not retaliate for exercising rights.

3. Intake channels

  1. privacy@rexblack.com: primary intake, acknowledged within 2 business days.
  2. A web form at /privacy/request (tracked in the same queue).
  3. Authorized agents may submit on behalf of a data subject with written authorization and identity verification.

4. Verification

  1. For clients (B2B): verified by matching the requester against the active org-user list and confirming via a sign-in challenge.
  2. For individuals: verified by matching known-good email and one additional attribute (most recent transaction, account identifier).
  3. Rex Black does not require more identity proof than necessary; we never require government ID for a standard request.
  4. Unverified requests are not fulfilled; the requester is asked for the minimum information to verify.

5. Timelines

Jurisdiction Initial acknowledgement Final response
GDPR / UK GDPR 2 business days 30 days (extendable to 60 with notice)
CCPA / CPRA 10 business days 45 days (extendable to 90 with notice)
Other 2 business days 30 days default

6. Processing steps

  1. Intake ticket created and classified.
  2. Verify requester.
  3. Determine Rex Black's role (controller vs. processor). If processor, forward to controller (the client) and assist as required by DPA.
  4. Discover data across Rex Black systems: DynamoDB by orgId, userId, email; S3 by object tag; SaaS by account.
  5. Prepare response; legal hold check; redact data about other data subjects.
  6. Deliver response through a secure channel.
  7. Record in the rights register (registers/rights-requests.md) with date, scope, verification, and outcome.

7. Exceptions to deletion

Rex Black retains data required for:

  • Legal obligation (tax / accounting / SOX / IRS: 7 years).
  • Ongoing contract performance.
  • Pending litigation or legal holds.
  • Security investigations.
  • Anonymized aggregate records.

Data subject is informed of any refusal with reasoning and how to appeal.

8. Appeals

Requesters may appeal a denial to privacy@rexblack.com. Appeals are reviewed by the Privacy Officer with escalation to the CEO. Responses are issued within 15 business days.

9. Children

Requests regarding data subjects under 13 (COPPA) or 16 (GDPR) are prioritized and, if the data exists, deletion is the default response.

10. Metrics

  • Request volume by type and jurisdiction.
  • Mean time to acknowledge and close.
  • Appeals rate.
  • Denials by reason.

11. Roles & responsibilities

Role Responsibility
Privacy Officer Owns intake, routing, and response.
Engineering Provides discovery and deletion tooling.
CEO Final escalation authority on appeals.

12. References

  • 019-privacy-policy-internal.md
  • 010-data-retention-and-disposal-policy.md
  • 009-data-classification-and-handling-policy.md

13. Revision history

Version Date Author Approver Change
1.0 2026-04-17 P.O. CEO Initial policy

Approval

This policy has been reviewed and is hereby approved for the named version and effective date above.

Approved by Myles Bai
Title Chief Executive Officer, Rex Black LLC
Email myles@rexblack.com
Approval date 2026-04-17
Effective date 2026-04-17
Next review due 2027-04-17

Digital signature of record: the CEO's electronic approval is captured in the platform audit log (event kind admin.policy.approved) with hash-chained integrity under the M-C1 control. The hash-chained audit log entry for this document is the canonical signature of record; this printed block exists for print/review convenience.

← Back to the trust center