Forum Discussion

Tho-Mas's avatar
Tho-Mas
Active Contributor
21 days ago

user friendly way raising GDPR subject-access/deletion requests

as a Company running Webinars many times during a month I understand our role as Company
as "Data Controller" according to GDPR definitions.
GoTo as Vendor that offers the platform, covers the role of the "Data Processor".
As a conclusion to that, we have to handle GDPR requests related to GoTo events we manage,
and GoTo has the responsibility to execute them in a timely manner.

Q1
What does GoTo Offer that makes it a straight forward process, raising GDPR related (bulk) requests 
for data: access/deletion I get from my Webinar Attendees (typically external Customers)? *
Q2
is it still the case that data from my events reside for 2 years at GoTo's servers, then kept but anonymised?
If yes, why does the reporting feature in the Admin Portal limit the range to 12 months maximum rather 24 months?
Q3
in case there are technical reasons 


* ZOOM has this Data Privacy management "feature" very well integrated into their Admin Portal;
 so whenever I get GDPR requests, I enter those and submit; latest half a day, max. a day later, I get the confirmation/information sent by e mail, about the result of my request.

 

5 Replies

  • tjst's avatar
    tjst
    New Contributor
    16 days ago

    typically we get between 30 and 40 requests, from all EU countries, per month; 
    but again: your IRM does not even allow the attendee requesting deletion or data access request raised.
    That is far away from being GDPR compliant! And your privacy team, that I contacted couple of days ago, plays the sound of silence ... i.e., no reaction at all to my request

  • KateG's avatar
    KateG
    GoTo Manager
    19 days ago

    Tho-Mas​ there was an issues with the moderation approval on your post, I've included it here. 

    I appreciate the additional context; it helps to understand this process. The process doesn't seem ideal. 

    A portal directly in the admin to delete attendee information is not currently planned. To help make a strong case for a dedicated feature, could you please let me know how many GDPR-related data deletion requests you typically receive from your attendees each month? Understanding the volume and impact will help us prioritize this need with our product team.

     

    @Tho-mas wrote: 

    indeed Kate, so far we contacted GoTo Support, they than sent us a mail asking for some additional information about the Customer who asked us to take GDPR related action; we sent this Information back to GoTo and got a confirmation, that within couple of weeks, this will get done, in case the record exists. Very clumsy, outdated and and no way to have some confirmation anything really happened.
    I was not aware about a new GoTo Admin .... will try asap....

  • KateG's avatar
    KateG
    GoTo Manager
    20 days ago

    Hi Tho-Mas​

    It does appear the IRM portal is for requests to delete your own data, not your attendees, apologies for the confusion. I'm following up with the team on the process for this. Previously, did you send an email to customer support with this request? 

    Are you currently using the GoTo Admin Center classic version to pull reports? I'm verifying with the team if you are able to pull 2 years worth of data in the new GoTo Admin

     

  • Tho-Mas's avatar
    Tho-Mas
    Active Contributor
    20 days ago

    thank you very much Kate!
    I was not aware about the IRM; what is surprising to me is
    that anybody can request a deletion also from others attending a Webinar, as long as the e mail is known.
    2 points here:
    1) from Test Webinars I did in the past, I have a report showing 2 of my private e mail addresses as Attendee
    so I used both, to request deletion, and a Access Request (which I believe is a request getting the data that has been collected about me as attendee)
    at the IRM; submitted, and quickly later, received in those mailboxes a notification saying: 

    Your request cannot be completed at this time.

    Hello,

    Thank you for your request. Please contact the organization that you attended a webinar for.

    Best,

    privacy@goto.com

    2) in the Admin Portal -> Reports-Webinar, I can only choose "Past 12 months" , and not, Past 24 months
    so nothing to report on last 2 years

  • KateG's avatar
    KateG
    GoTo Manager
    21 days ago

    Hi Tho-Mas​ 

    Nice to see you. Hope you are doing well. 

    • As you may know, if you would like to request data deletion, you can do this through the Individual Rights Management (IRM) Portal. Once submitted, you should receive a confirmation email upon completion. 
    • I'm checking with the team on a bulk management system and will get back to you shortly. 
    • For GTW reporting, 12 months used to be the stated limit, it was increased to 24 months a few years ago.