Policies and Procedures: GDPR Data Removal Request Policy

Prev Next

GDPR Data Removal Request Policy

The purpose of this policy is to outline the process for communicating with a data subject and controller regarding a request for the removal of data for EU citizens from various internal Ripple Treasury systems. 

Ripple Treasury Data Protection Officer

Requests for personal data to be removed from the Ripple Treasury application should be directed to the Data Protection Officer mailbox at privacy@ripple.com.  This mailbox is managed by the Ripple Treasury Security & Compliance Team. 

Removal Request

If a Data Subject reaches out to Ripple Treasury (Processor) directly regarding a request that their data be removed from the Ripple Treasury application, Ripple Treasury must contact the Customer (Controller) directly regarding this matter. Ripple Treasury will forward the request to the Controller for them to communicate directly with the data subject. It is the responsibility of the Customer to discuss with the Data Subject and provide direction to Ripple Treasury regarding the data which should be removed. 

Application Requests

Most requests for the removal of data can be accomplished via the Ripple Treasury application by the Customer (Controller). A Support team member will aid the customer in removing data via the application and if this option is not viable, an internal ticket will be created to request the data removal process be executed. In instances where data cannot be removed by the Controller directly, the DevOps team will properly remove data according to the internal ticket request. 

Marketing Requests

Requests should be routed to treasury-sales@ripple.com for the proper removal from applicable sales/marketing related tools.

Confirmation

Upon completion of the removal of a Data Subject’s personal data from the Ripple Treasury application, Ripple Treasury must advise Controller that the data has been removed. In addition to removing the data itself, evidence will be provided of the removal of data upon request if feasible. The internal ticket will be re-assigned to the Ripple Treasury resource who received the request from the Controller so that they can provide adequate documentation/communication to the Controller.