All case studies
Netflix

Privacy operations · Case study

Netflix: answer data-access requests

Take each customer’s request for their data from identity check to a complete, reviewed answer before the deadline.

By OneShot · Updated

Read the solution ↓

What the workflow produces

Access request file
Request
Requester, identity check, receipt date and deadline.
Data collected
Systems searched, exports received and systems holding nothing.
Completeness check
Required explanations present, missing or unclear.
Sign-off
Reviewer, date sent and record of what was disclosed.

The documented problem

In December 2024 the Dutch Data Protection Authority fined Netflix €4.75 million. It found that between 2018 and 2020 Netflix’s privacy statement was not clear enough, and that customers did not receive sufficient information when they asked which data the company collects about them. The authority noted that Netflix has since updated its privacy statement and improved its information. Netflix objected to the fine.

A second regulator reached a similar finding about another streaming service. In June 2023 Sweden’s privacy authority fined Spotify SEK 58 million. It found that Spotify released the personal data it held when asked, but did not explain clearly enough how that data was used, and it rated the shortcomings as low in seriousness overall. Spotify appealed; this summary covers the regulator’s 2023 decision, not the outcome of that appeal. Both decisions concern past periods and are not statements about either company’s current practice. The OneShot workflow below is a proposed design for handling such requests.

The OneShot solution

Data-access requests answered in full and on time

Answer every access request completely, in plain language and within the legal deadline, with a reviewer’s sign-off on what was disclosed.

Work enters the queue
A new access request, an overdue system export or a request approaching its deadline.
Decision owner
Privacy team reviewer
  1. 01

    Log and verify the request

    Record the request, its receipt date and the deadline. Follow the company’s identity-check procedure and ask the requester for anything missing through the approved channel.

  2. 02

    Collect from each system

    The OneShot agent asks each system owner on the approved data inventory for the requester’s data and tracks what has arrived. It chases overdue exports and records the systems that hold nothing.

  3. 03

    Check the answer is complete

    Compare the draft answer with what the law requires alongside the data itself: purposes, recipients, retention period and transfers. Flag any category that is missing or described only in technical terms.

  4. 04

    Review and send

    Give the reviewer the draft, the completeness check and any proposed redactions. Send the approved answer, record the date and keep the evidence of what was disclosed.

What counts as complete

The reviewer has approved the answer, it was sent within the deadline, and the file shows which systems were searched.

Decisions and exceptions

  • Identity doubts, third-party data and legal exemptions go to the privacy team.
  • The agent does not decide what to withhold.
  • A deadline at risk is escalated before it passes, with the missing systems named.

What to measure

  • Requests answered within the deadline
  • Overdue system exports
  • Answers sent back by the reviewer
  • Follow-up complaints

Establish the baseline and review period before launch. Compare completed cases, unresolved work and reviewer corrections against the same scope.

The agent’s tool basket

OneShot gives its agents the tools to analyze records, communicate, research and act on authorized business data. The platform carries the workflow from the first action through to the recorded result.

  • Privacy request records

    Read the request queue and approved data inventory; track each system's export and the reviewer's sign-off.

Workflow pricing

Scope the full workflow around your volume, business systems and required outcome.

Discuss workflow pricing →

Bring a workflow
like this one.