{"id":2902,"date":"2019-12-04T11:56:00","date_gmt":"2019-12-04T17:56:00","guid":{"rendered":"https:\/\/trustarc.com\/?post_type=resource&#038;p=2902"},"modified":"2024-12-17T09:07:43","modified_gmt":"2024-12-17T15:07:43","slug":"automated-dsr-fulfillment-dos-attacks","status":"publish","type":"resource","link":"https:\/\/trustarc.com\/resource\/automated-dsr-fulfillment-dos-attacks\/","title":{"rendered":"Automated DSR Fulfillment to Avoid Denial of Service Attacks"},"content":{"rendered":"\t\t<section id=\"block_9c919ef9260a396f5472c013da22aae1\" class=\"resource-intro intro-simple\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<strong class=\"sub-title block uppercase\">Articles<\/strong>\n\t\t\t\t\t\t\t\t\t\t<h1>Automated DSR Fulfillment to Avoid Denial of Service Attacks<\/h1>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t<section id=\"block_b6b2ff530b76f0ff0d00f02d218486de\" class=\"columns-content\">\n\t\t<div class=\"container\">\n\t\t\t<div class=\"left\">\n\t\t\t\t\t\t<div class=\"person-wrap\">\n\t\t\t<span>\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"110\" height=\"110\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/people-placeholder-lt-blue.png\" class=\"attachment-full size-full wp-post-image\" alt=\"\" \/>\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t<strong class=\"block name\">Annie Greenley-Giudici<\/strong>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/span>\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t<div class=\"middle\">\n\t\t\t\t<div class=\"content\">\n\t\t\t\t\t<p>In the wake of GDPR, law firm Squire Patton Boggs\u00a0<a href=\"https:\/\/www.squirepattonboggs.com\/~\/media\/files\/insights\/publications\/2019\/05\/the-rise-and-challenge-of-dsars-one-year-on-from-the-gdpr-and-the-dpa-2018\/dsar_survey_alert.pdf\">reported a \u201csharp increase\u201d<\/a>\u00a0in the number of UK residents who initiated <a href=\"https:\/\/trustarc.com\/solutions\/data-subject-request-automation\/\">data subject access requests (DSARs)<\/a>, fulfilling the same number of DSARs in the first five months of 2019 as they\u2019d handled during the\u00a0<i>entire year<\/i>\u00a0of 2018.<\/p>\n<p>CCPA data subject requests (DSRs) will likely have the same effect on California-based organizations. With a 45-day deadline for fulfillment, companies that don\u2019t implement automated DSR fulfillment are at an increased risk of Denial of Service (DoS) attacks.<\/p>\n<h2>How are denial of service attacks performed?<\/h2>\n<p>DoS attacks happen when legitimate users are unable to access information systems, devices, or other network resources due to cyber criminal activity that floods a host or network with traffic until it cannot respond or simply crashes, preventing access to email, online accounts, and websites.<\/p>\n<p>These attacks disrupt a company\u2019s online presence by keeping its web servers so busy with network requests that they cannot load web pages or Internet resources, costing organizations time and money. In contrast, their resources and services are inaccessible.<\/p>\n<h3>A DoS attack can happen when a company is inundated with DSRs<\/h3>\n<p>It overwhelms the CSR and IT staff, who are forced to respond to requests manually and eventually reach a breaking point in which the company can\u2019t safely respond to requests within the required timeline.<\/p>\n<p>With CCPA right around the corner, there\u2019s no time like the present to start thinking about your company\u2019s plans to circumvent DoS attacks and streamline DSR processes.<\/p>\n<p>According to the new regulations the process must now include identity verification prior to fulfilling each request. Technology can help teams automate\u00a0manual processes, which helps save time and promote consistency.<\/p>\n<p>But it\u2019s important for businesses to be aware of potential DSR threats like DoS attacks that can jeopardize fulfillment and result in both frustration and noncompliance.<\/p>\n<h2>Lessons learned from GDPR<\/h2>\n<p>Many companies started preparing for <a href=\"https:\/\/trustarc.com\/regulations\/gdpr\/\">GDPR<\/a> by hiring lawyers and consultants to conduct <a href=\"https:\/\/trustarc.com\/resource\/compliance-privacy-assessments\/\">privacy impact assessments (PIAs)<\/a>, data mapping, understanding workflows, manually surveying data sets, and introducing internal guidelines.<\/p>\n<p>These steps were certainly helpful and necessary, but because the work had to be applied to multiple sets of data repositories, companies found they were duplicating efforts over and over.<\/p>\n<p>Operationalizing <a href=\"https:\/\/trustarc.com\/regulations\/ccpa-cpra\/\">CCPA<\/a> with automation requires companies to leverage existing IT security tools and systems (e.g., SIEM, ticketing, data governance).<\/p>\n<p>Thus, it\u2019s critical to get buy-in from CTOs, CISOs, CPOs, and\u00a0data governance\u00a0teams from the beginning in order to\u00a0<strong>execute processes correctly the first time<\/strong>.<\/p>\n<p>Taking the time to prepare and automate DSR fulfillment processes can help mitigate the onslaught of DSRs, which result in DoS attacks.<\/p>\n<h3>GDPR rights of the data subject<\/h3>\n<p>GDPR Chapter III,\u00a0<em>Rights of the Data Subject<\/em>\u00a0outlines the requirements. Article 12 through Article 23 cover areas such as Article 17 \u2013 Right to erasure (\u2018right to be forgotten\u2019), which has been the hot topic of discussion.<\/p>\n<p>Questions such as\u00a0<em>What if my company doesn\u2019t have the technology to read that data anymore?<\/em>\u00a0have left privacy teams stumped.<\/p>\n<p><strong>You can get started in answering this question by following these steps:<\/strong><\/p>\n<ul>\n<li>Ensure fundamental understanding of what data you process.<\/li>\n<li>Establish a process to intake requests (one that is easy on the individual and ensure this process is well-communicated throughout the organization.\n<ul>\n<li>A request may come in from many routes and the person receiving that request needs to understand that a request is being made. Individuals typically won\u2019t understand or use the exact verbiage in the law).<\/li>\n<\/ul>\n<\/li>\n<li>Once the request is received, have a process to review it, evaluate the data referenced, the reasons for processing the data, and evaluate any exceptions.<\/li>\n<li>Have a response process.<\/li>\n<li>Have an appeals process that goes beyond the individual whose request was denied.<\/li>\n<li>Retain documentation throughout the process.<\/li>\n<\/ul>\n<h2>Coordinated data subject requests<\/h2>\n<p>Through the use of social media, online networking platforms, and other less obvious sources, many data subjects can quickly and easily coordinate to submit DSRs on behalf of people who may or may not exist, all at the same time.<\/p>\n<p>The most recent example of this was executed under GDPR law, when Blizzard Entertainment stripped the World of Warcraft Tournament Champion of his title after publicly claiming support for Hong Kong protesters, which triggered the gaming community.<\/p>\n<p>Multiple gaming sites, and even\u00a0<a href=\"https:\/\/www.reddit.com\/r\/hearthstone\/comments\/df0zx5\/upset_about_blizzards_hk_ruling_heres_what_to_do\/\">Reddit posts like this<\/a>, instructed angry gamers who were upset with Blizzard how to exercise their rights under\u00a0<a href=\"https:\/\/www.privacy-regulation.eu\/en\/article-15-right-of-access-by-the-data-subject-GDPR.htm\">GDPR Article 15<\/a>.<\/p>\n<p>The\u00a0<a href=\"https:\/\/www.secureworldexpo.com\/industry-news\/using-gdpr-as-a-weapon\">weaponization of DSRs<\/a>\u00a0quickly caught on, and led to an influx of requests that was very difficult for Blizzard to manage.<\/p>\n<p><strong>Even for large organizations with robust processes and automated systems for managing DSRs, such a large number of coordinated requests are likely to have a lasting impact.<\/strong><\/p>\n<p>Attacks tend to cause an excessive and manual workload by clogging automated systems with complicated requests.<\/p>\n<p>Not limited to large corporations, the coordinated DSR attacks will actually do more harm to smaller businesses that don\u2019t have the resources to deal with the\u00a0tidal wave of requests.<\/p>\n<p>But it\u2019s important to note that even moderate levels of DSR traffic can overwhelm organizations if they\u2019re not properly prepared.<\/p>\n<h2>Automated DSR fulfillment recommendations<\/h2>\n<p>The\u00a0<strong>first step<\/strong>\u00a0is to build an effective intake form for DSRs that are visible, have predefined requests that the data subject can select from, and can be automated to fulfill requests quickly.<\/p>\n<p>Automation tools also exist that can help businesses centralize requests in a single dashboard, automate notifications, track deadlines, and establish processes for individuals who are involved in each step of the workflow.<\/p>\n<p>The\u00a0<strong>second step<\/strong>\u00a0is to ensure that identity verification techniques, congruent with the sensitivity of the data being requested, are prominently integrated at the very beginning of the DSR process.<\/p>\n<p>This action alone can weed out bad actors and bots attempting to flood business systems with requests.<\/p>\n<p>The more sensitive the data being requested (think: banking, insurance, healthcare, etc.),\u00a0the higher the verification assurance\u00a0should be for those submitting requests.<\/p>\n<p>When it comes to preventing DoS attacks, manual DSR processes that require personnel to scan hundreds of systems for every request will not cut it.\u00a0<strong>It\u2019s a big data problem.<\/strong><\/p>\n<p>Often in the DSR fulfillment process duplicate data sets are the primary culprits for exposure of sensitive data to unnecessary parties.<\/p>\n<h2>Tips to automate DSR fulfillment<\/h2>\n<ul>\n<li>Avoid creating additional copies of customer data<\/li>\n<li>Reduce PI surface area<\/li>\n<li>De-identify but beware of toxic combinations<\/li>\n<li>Comply with privacy and security-by-design principles<\/li>\n<li>Prepare for a data subject request DoS attack<\/li>\n<li><strong>Respond to data subject requests faster<\/strong><\/li>\n<\/ul>\n<p><a href=\"https:\/\/trustarc.com\/products\/individual-rights-manager\/\" target=\"_blank\" rel=\"noopener noreferrer\">Individual Rights Manager<\/a>\u00a0can help your company with GDPR compliance with regard to individual data protection rights.<\/p>\n<p>This comprehensive 3-in-1 solution combines proven technology with specialized content developed by our privacy experts.<\/p>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\t<div class=\"right sm\">\n\t\t\t\t<div class=\"share-it\">\n\t\t\t\t\t<strong class=\"title block uppercase\">Follow us<\/strong>\n\t\t\t\t\t<div class=\"soc-list\">\n\t\t\t\t\t\t<a href=\"https:\/\/www.linkedin.com\/company\/trustarc\/\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/li-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"\nhttps:\/\/twitter.com\/TrustArc\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/tw-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"javascript:;\" id=\"copy-url\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/link-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<span class=\"copied\" style=\"display:none;\">Link Copied!<\/span>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<div class=\"key-topics\">\n\t\t\t\t\t\t<strong class=\"title block uppercase\">Key Topics<\/strong>\n\t\t\t\t\t\t<ul>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/automation\/\" class=\"badge\">Automation<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/data-subject-requests\/\" class=\"badge\">Data Subject Requests<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"cta-area\">\n\t\t\t\t\t<p>Get the latest resources sent to your inbox<\/p>\n\t\t\t\t\t<a href=\"\/subscription-center\/\" class=\"cta\">Subscribe<\/a>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t<\/section>\n\t","protected":false},"excerpt":{"rendered":"<p>Comply with GDPR and CCPA. Circumvent Denial of Service attacks and streamline DSR processes with automated DSR fulfillment.<\/p>\n","protected":false},"featured_media":1259,"template":"","topic-resource":[76,72],"type-resource":[6],"class_list":["post-2902","resource","type-resource","status-publish","has-post-thumbnail","hentry","topic-resource-automation","topic-resource-data-subject-requests","type-resource-articles"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Automated DSR Fulfillment to Avoid Denial of Service Attacks | TrustArc<\/title>\n<meta name=\"description\" content=\"Comply with GDPR and CCPA. Circumvent Denial of Service attacks and streamline DSR processes with automated DSR fulfillment.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustarc.com\/resource\/automated-dsr-fulfillment-dos-attacks\/\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/automated-dsr-fulfillment-dos-attacks\\\/\",\"url\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/automated-dsr-fulfillment-dos-attacks\\\/\",\"name\":\"Automated DSR Fulfillment to Avoid Denial of Service Attacks | TrustArc\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/automated-dsr-fulfillment-dos-attacks\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/automated-dsr-fulfillment-dos-attacks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-rect-purple-test.png\",\"datePublished\":\"2019-12-04T17:56:00+00:00\",\"dateModified\":\"2024-12-17T15:07:43+00:00\",\"description\":\"Comply with GDPR and CCPA. Circumvent Denial of Service attacks and streamline DSR processes with automated DSR fulfillment.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustarc.com\\\/resource\\\/automated-dsr-fulfillment-dos-attacks\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/automated-dsr-fulfillment-dos-attacks\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-rect-purple-test.png\",\"contentUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-rect-purple-test.png\",\"width\":610,\"height\":152},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\",\"url\":\"https:\\\/\\\/trustarc.com\\\/\",\"name\":\"TrustArc\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustarc.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Automated DSR Fulfillment to Avoid Denial of Service Attacks | TrustArc","description":"Comply with GDPR and CCPA. Circumvent Denial of Service attacks and streamline DSR processes with automated DSR fulfillment.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustarc.com\/resource\/automated-dsr-fulfillment-dos-attacks\/","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustarc.com\/resource\/automated-dsr-fulfillment-dos-attacks\/","url":"https:\/\/trustarc.com\/resource\/automated-dsr-fulfillment-dos-attacks\/","name":"Automated DSR Fulfillment to Avoid Denial of Service Attacks | TrustArc","isPartOf":{"@id":"https:\/\/trustarc.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustarc.com\/resource\/automated-dsr-fulfillment-dos-attacks\/#primaryimage"},"image":{"@id":"https:\/\/trustarc.com\/resource\/automated-dsr-fulfillment-dos-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-rect-purple-test.png","datePublished":"2019-12-04T17:56:00+00:00","dateModified":"2024-12-17T15:07:43+00:00","description":"Comply with GDPR and CCPA. Circumvent Denial of Service attacks and streamline DSR processes with automated DSR fulfillment.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustarc.com\/resource\/automated-dsr-fulfillment-dos-attacks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/trustarc.com\/resource\/automated-dsr-fulfillment-dos-attacks\/#primaryimage","url":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-rect-purple-test.png","contentUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-rect-purple-test.png","width":610,"height":152},{"@type":"WebSite","@id":"https:\/\/trustarc.com\/#website","url":"https:\/\/trustarc.com\/","name":"TrustArc","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustarc.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource\/2902","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource"}],"about":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/types\/resource"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media\/1259"}],"wp:attachment":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media?parent=2902"}],"wp:term":[{"taxonomy":"topic-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/topic-resource?post=2902"},{"taxonomy":"type-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/type-resource?post=2902"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}