Skip to content
Last updated: 2026-04-02
Guide

Data Subject Rights Management

The Rights section is your operational hub for handling Data Subject Rights requests—from initial intake through fulfillment and archival.

Rights Dashboard Overview

Current Status

At a glance, see the current state of all DSRR requests:

  • Pending Requests — Awaiting your action
  • In Progress — Being processed
  • Overdue — Past deadline (needs escalation)
  • Completed This Period — Fulfilled requests

Request Volume

  • Total received (period)
  • By type (Access, Deletion, Rectification, Restriction, Portability, Objection, Automated Decision-Making)
  • By regulation (GDPR, CCPA, etc.)
  • Average response time

Intake DSRR Requests

Create New Request

Click + New Request:

  1. Customer Information
  2. Email address
  3. Full name (optional)
  4. Customer ID (optional)
  5. Preferred contact method

  6. Request Details

  7. Type (Access, Deletion, Rectification, Restriction, Portability, Objection, Automated Decision-Making)
  8. Request notes or customer message
  9. Received date/time

  10. Submit

  11. Dxtra auto-sets deadline based on regulation
  12. Sends acknowledgment to customer (optional)
  13. Creates audit log entry

Bulk Import

Upload multiple requests via CSV:

  1. Click Bulk Import
  2. Upload CSV with columns: email, type, name, notes
  3. Review and confirm
  4. Dxtra creates all requests

Manage Requests

View Request Details

Click any request to see:

  • Customer — Email, name, ID, contact info
  • Request — Type, submission date, deadline
  • Status — Current stage (Received, Verified, In Progress, Completed, etc.)
  • Timeline — All actions and notes
  • Audit Trail — Who did what and when

Update Status

Move request through workflow:

  1. Received → Initial submission
  2. Identity Verified → Confirmed customer identity
  3. Data Collection → Gathering customer data
  4. Review → Privacy officer reviews completeness
  5. Response Sent → Delivered to customer
  6. Completed → Marked done

Each status change is timestamped and logged.

Add Notes & Attachments

Document everything:

  • Notes — Internal discussion, decisions made
  • Attachments — Scan of ID for identity verification, copies of customer email, etc.
  • Tags — Custom tags for organization (urgent, escalated, etc.)

Data Collection

Retrieve Customer Data

For access requests, gather data from connected systems:

  1. Click Collect Data
  2. Select data sources to query:
  3. Salesforce CRM
  4. Shopify Store
  5. Mailchimp Email
  6. Stripe Payments
  7. Google Analytics
  8. Manual upload
  9. Dxtra queries each system
  10. Data appears in request

Review & Validate

Before sending to customer:

  • Verify data is complete
  • Check for any sensitive/redacted information needed
  • Confirm all systems were checked
  • No obvious gaps

Prepare Export

Choose export format:

  • CSV — Spreadsheet format
  • JSON — Structured data
  • PDF — Human-readable report
  • ZIP — Multiple files together

Add cover letter explaining what's included.

Execute Deletions

For deletion requests:

  1. Verify Scope — What to delete?
  2. Account & profile
  3. Order/transaction history
  4. Communications
  5. Analytics data
  6. Keep legal/tax records?

  7. Execute — Dxtra deletes from all systems

  8. Deletion logged with timestamp
  9. Audit trail of what was deleted
  10. Confirms deletion completed

  11. Confirm — Send confirmation to customer

Track Deadlines

Deadline Monitoring

The system displays deadline for each request with automatic color coding to help prioritize work:

  • Green: Plenty of time (>7 days)
  • Yellow: Approaching deadline (1-7 days)
  • Red: Urgent (<1 day)

Days remaining countdown shows how much time you have to respond.

Escalation

Automatic alerts when:

  • 7 days before deadline
  • 3 days before
  • 1 day before
  • Overdue

Assign to priority queue for urgent requests.

Compliance Reports

DSRR Report

Generate report showing:

  • Total requests received
  • By type (Access, Deletion, Rectification, Restriction, Portability, Objection, Automated Decision-Making)
  • By regulation (GDPR, CCPA, etc.)
  • Response time statistics
  • On-time completion rate
  • Any overdue requests

Export for:

  • Executive reporting
  • Audit documentation
  • Regulatory inspection
  • Annual compliance review

Audit Trail

Complete record of all actions:

  • When request received
  • Who did what and when
  • Data collected/deleted
  • Customer communications
  • Verification methods
  • Completion date

Export for auditors and regulators.

Batch Operations

Bulk Actions

Select multiple requests:

  • Mark as completed
  • Add tags
  • Change status
  • Download data
  • Export records

Perform action on all selected requests.

Search & Filter

Find requests quickly:

  • By email/name
  • By status
  • By request type
  • By regulation
  • By deadline (approaching, overdue)
  • By owner/assignee

Customer Communication

Send Messages

Communicate with customer directly:

  • Email — Send via Dxtra or your system
  • In-app — If using customer portal
  • Portal — Share secure link for customer to download data

Track all communications in request timeline.

Pre-built Templates

  • Acknowledgment — "We received your request"
  • Pending Verification — "We need to verify your identity"
  • Ready for Pickup — "Your data export is ready"
  • Completion — "Your request is complete"
  • Cannot Fulfill — "We cannot fulfill part of your request because..."

Customize templates for your company.

Integration with Workflow

Assign to Team Members

Assign requests to:

  • Privacy Officer (for review)
  • Data Engineer (for data retrieval)
  • Support (for customer communication)
  • Legal (for decisions on difficult requests)

Track who's working on what.

Notifications

Get notified when:

  • New request submitted
  • Assigned to you
  • Awaiting your action
  • Deadline approaching
  • Overdue

Not legal advice

AI-generated content does not constitute legal advice. Consult a qualified legal professional for advice specific to your jurisdiction and business context.