The GDPR app

The GDPR App is an app that exists separately to Learning Record Store and allows you to easily comply with GDPR in regards to your Learning Record Store data. You will have been given access to your GDPR app by GS Learning when you first started using Learning Record Store.

If your organisation receives a request related to a learner's data in Learning Record Store, you can use the GDPR app to respond to this request.

 

Access requests

When a user contacts your organisation with a query relating to their data, go to the Access Request tab on the app menu: 

GPR_1.gif

From here you can view access requests that have been made and create new access requests. 

 

Create a new access request 

To create a new access request, click New Access Request:

GDPR_2.gif

Add personas Input the name of the person to whom the access request relates. You may have multiple personas for an individual if the identifiers and not linked. It is important to include each persona that is relevant to the access request to ensure you provide the user with the complete picture of their data. 
Preview Use this button to be absolutely certain that the data relates to the individual for whom you are making the request. 
Choose Access Request Name The name that will be displayed in the Actions Required log. This will be  useful for tracing the request for auditing purposes. 
Add an access pin Create a secure 10 digit PIN that the individual will need to input in order to access their data. You can click the   to automatically generate one.
Make request Click here when you're happy with your settings. 

 

Sending a user their access

Once you've created an access request, you can send it to the requestee. On the access reports screen, locate the relevant request and make note of the Pin and the Unique URL:

GDPR_3.gif

 

Send the PIN and unique url to the user. They can use it to access their information. 

 

What requestees see

When users go to their unique URL they'll be prompted to enter their PIN: 

mceclip1.png

 

They'll be taken to a screen where they can view and request changes to their information: 

mceclip2.png

Request changes  Users can request that changes are made to incorrect, out of date, or incomplete. 
Request to be forgotten Users can request to be forgotten and have all their data erased. 
Request download Users can request access to a report of all the data held in relation to them. 
Persona Data This section contains the user's identifying information, as seen in their Learning Record Store persona. Click here to read more about personas
Access Request Logs This section displays a summary of any access requests the user has previously made and their status. 
Preview Statements This window displays a list of the xAPI statements linked to the user and their activity. 

 

Actions required

Once an individual has initiated a request, the request will be displayed in your Actions Required tab:

GDPR_4.gif

 

In the Status column you will see several options: 

Resolve Marking the action as resolved removes it from the Actions Required tab and moves it into the Access Request Logs tab. It will also mark the item as resolved on the individual user's log.
Send Email This button will automatically send an email to learning Pool with all the information necessary for them to action the request. 
View Access Request