Privacy safeguard 13—correction of CDR data
56EP Privacy safeguard 13—correction of CDR data
Obligation on data holders and action service providers
If:
a CDR consumer for CDR data gives a request to the following person (the CDR entity):
a data holder of the CDR data (including a request given through a designated gateway for the CDR data);
a person as an action service provider for a type of CDR action; and
the request is for the CDR entity to correct the CDR data, and is not given in response to advice from the CDR entity under subsection 56EN(3); and
the CDR entity was earlier required or authorised under the consumer data rules to disclose the CDR data;
the CDR entity must respond to the request to correct the CDR data by taking such steps as are specified in the consumer data rules to deal with each of the matters in subsection (3) of this section.
This subsection is a civil penalty provision (see section 56EU).
Subsection 56EN(4) applies instead of this subsection if the request is given in response to advice from the CDR entity under subsection 56EN(3).
Obligation on accredited data recipients
If:
a CDR consumer for CDR data gives a request to an accredited data recipient of the CDR data (including a request given through a designated gateway for the CDR data); and
the request is for the accredited data recipient to correct the CDR data, and is not given in response to advice from the accredited data recipient under subsection 56EN(3);
the accredited data recipient must respond to the request by taking such steps as are specified in the consumer data rules to deal with each of the matters in subsection (3) of this section.
This subsection is a civil penalty provision (see section 56EU).
Subsection 56EN(4) applies instead of this subsection if the request is given in response to advice from the accredited data recipient under subsection 56EN(3).
Relevant matters when responding to correction requests
The matters are as follows:
either:
to correct the CDR data; or
to include a statement with the CDR data, to ensure that, having regard to the purpose for which the CDR data is held, the CDR data is accurate, up to date, complete and not misleading;
to give notice of any correction or statement, or notice of why a correction or statement is unnecessary or inappropriate.
When working out the purpose for which the CDR data is held (see subparagraph (3)(a)(ii)), disregard the purpose of holding the CDR data so that it can be disclosed as required under the consumer data rules.
The statute text is free to read above. View subscription options to unlock the case-law research tools for each provision.