Ten-stage DSAR lifecycle from public submission through identity verification, automated data discovery, vendor sub-requests, response compilation, review, fulfillment, and regulatory evidence package. SLA-tracked at every stage.
Privacy Center accepts requests without account creation — addresses ICO and CNIL guidance that account creation is an unlawful barrier.
For Access and Erasure requests, platform identifies all datastores tagged with IncludeForDsar=true and generates a scoped search checklist.
If data is held by vendors, sub-requests generated to vendor contacts through the Vendor Portal automatically.
Per-request: submission timestamp, verification status, datastore search record, vendor sub-requests, review chain, fulfillment date, delivery confirmation.
GDPR Article 15 / CCPA — a structured report of all data held about the subject. The discovery engine queries every tagged datastore to assemble it.
GDPR Article 16 — the subject flags incorrect data; a case opens and runs through an internal review and correction workflow.
GDPR Article 17 / CCPA deletion — routed to data owners across all tagged datastores, with erasure confirmations collected as evidence.
GDPR Article 18 — processing is restricted pending dispute resolution, with a flag applied across data holdings.
GDPR Article 20 — the subject's data is exported in a machine-readable format (JSON/CSV) and delivered securely.
GDPR Article 21 / CCPA opt-out — the objection is recorded against the specific processing purposes it applies to.
Where a request is denied, the subject can formally appeal through the Privacy Center — the documented appeal channel regulators expect to see.
Data subjects submit via the public Privacy Center with no account required, or staff raise a request on a subject's behalf.
Where verification is required, identity documents are attached and reviewed before any data is released.
The request is assigned to a named team member, who is notified by branded email; priority and complexity are assessed.
For access and erasure, the platform identifies every datastore tagged for DSAR inclusion, so nothing is missed.
Where a third party holds the data, sub-requests are raised through the vendor mappings and tracked to completion.
The team assembles the data extract, correction confirmation, erasure evidence or denial justification with supporting records.
Complex requests and denials route to the DPO or senior reviewer, with the full multi-reviewer approval chain recorded.
The response goes to the subject via a secure, time-limited download link — never an email attachment.
If denied, the subject is told of their right to appeal, and appeals are tracked as their own linked request.
Every request produces a complete audit trail — submission, tracking number, verification, assignee history and delivery.
Deadlines calculated per jurisdiction — 30 days under GDPR (extendable to 90 for complex requests), 45 under CCPA — configurable per tenant.
Every request shows green, amber, red or overdue, so the whole queue's SLA health is visible at a glance.
Configurable reminders at 14, 7 and 3 days; overdue requests escalate straight to the DPO.
When an extension is invoked, the platform records the justification, the date the subject was notified, and the new deadline.
Open requests, average days-to-fulfil, SLA breach rate and volume by type and status — the numbers a regulator or board asks for.
Today the platform generates scoped system checklists and schema guidance; connector-driven auto-query is on the roadmap to cut hours to minutes.
Verisq's DSAR Automation is part of the Trust Operations Platform — one data model, one audit trail, one auditor seat.