Skip to Main Content
D&D Portfolio Ideas Portal
Workspace D&D Portfolio
Created by Guest
Created on May 1, 2025

Osano Access Request Tool

Under CCPA/CPRA and GDPR, it is legal requirement to allow consumers to self-serve their DSARs

Example:

  • The right to know what personal information businesses have collected, used, and shared about them

  • The right to delete personal information businesses have collected from them (subject to some exceptions)

  • The right to correct inaccurate personal information businesses have about them

  • The right to limit use and disclosure of sensitive personal data

  • The right to opt out of the sale or sharing of personal information

  • The right to access personal information in a portable and usable format

These requests need to be actioned upon, tracked and reported. Currently, we use a ServiceNow workflow that was created by Julio and Mike Todd in 2018 when GDPR first became law which worked at that time when there was no off the self-tools to leverage. Now, there are many and with the frequency of new State Privacy laws coming into effect we needed get a tool that can scale with the Company growth and help automate this process that is currently highly manual to remain compliant. We already use Osano for Cookie Compliance Banner on the Brand websites and last week we renewed and added their DSAR/Data Mapping functionality that is embedded in the existing Brand websites Cookie Compliance Banners. So, turning on the functionality will be fairly easy, where we would need help is connecting Osano via APIs (where available) to the various Third Party Apps that collect customer information (e.g., Gladly, Power Reviews, Dynamic Yield, Amperity, Cordial, Merkle, Medallia, Salesforce Commerce Cloud, Adyen, Forter, DOMS, LoyaltyPlus Content Square, etc.) or leverage other options if API does not exist for some of the aforementioned systems.

Outcome Remain compliant with Regional and State Privacy Laws. Having a dedicated PM would help expedite the implementation and help coordinate with various global cross functional teams (e.g, eComm, Legal, GRC, Customer Service, System Owners, DSAR Task Owners)
Objective Alignment Other
Region GLOBAL
Regulatory Compliance Yes
Is a PM Required Yes
  • Attach files