- Requests should identify the requester, account, group, right exercised, records sought, preferred response channel, and authority where a representative acts for someone else.
- FelbaCare should verify identity proportionately before disclosing or changing data and should avoid exposing another member's data in response to a request.
- Deletion and objection requests may be limited where FelbaCare or a group must preserve finance, audit, claim, dispute, security, tax, or legal records.
- Each request should have an audit record, deadline, decision, reviewer, response, withheld-data reason where applicable, and escalation route including ODPC complaint information.
Data Subject Rights Procedure
Access, correction, deletion, objection, portability, consent withdrawal, ODPC complaints, and identity checks.