Chat on WhatsApp

Rights

Privacy request management for access and erasure

Consent Guru includes workflows for data subject access requests and related rights, from intake through a status the person can check.

Rights requests are not the same as consent clicks

A DSAR asks what data you hold, or asks you to correct or delete it. A cookie choice does not answer that request. The two workflows should meet, but they should not be collapsed into one checkbox.

The public Privacy Centre accepts Data Principal requests and grievances. The workspace is where your team verifies the request and records the outcome.

How a request moves

  1. Step 1

    Intake

    People submit access, correction, erasure, nomination, grievance, or consent-withdrawal requests through the Privacy Centre.

  2. Step 2

    Verify

    The workflow supports email-token verification and, where configured, an agent-attested path. Verification exists to reduce unauthorized disclosure.

  3. Step 3

    Fulfill

    Your team updates status, including correction and deletion steps recorded in the rights workspace.

  4. Step 4

    Track

    The person can check progress with a tracking reference instead of an open-ended email thread.

Key capabilities

Data subject access request intake

A public form for the requests you enable, separate from the marketing site’s cookie banner.

Privacy request management

Statuses, verification method, and audit metadata stay on the request record.

Grievances

A grievance path sits beside access and erasure, which matters for DPDP-style complaint handling.

Retention

Rights-request retention is configurable and is distinct from consent-evidence retention.

What teams use it for

  • One queue for privacy requests instead of a shared inbox.
  • A visible status for the person who asked.
  • An audit trail of verification and status changes.
  • A clean separation from cookie consent records.

Access requests

Confirm identity, then record what was provided and when.

Deletion

Track erasure work without pretending the CMP deleted every downstream system.

India-facing services

Use Data Principal language in the public centre alongside the DSAR-style rights your other markets use.

Privacy considerations

Deadlines, exemptions, and the scope of a request come from the law that applies, not from the form. This page is not legal advice.

Deletion of personal data is separate from withdrawal of consent. Withdrawing a cookie purpose does not automatically erase data a vendor already received.

Questions

1.What is DSAR?

A data subject access request is a person’s request to know whether an organization holds personal data about them and, where the law provides it, to receive a copy or related details.

2.What is privacy request management?

It is the operational process of receiving, verifying, fulfilling, and recording access, correction, deletion, and similar requests.

3.Where do people submit a request?

Use the Data Principal request page in the Privacy Centre. Consent Guru’s own contact for privacy questions is support@consentguru.com.

Related pages

This page describes how Consent Guru supports privacy operations. It is not legal advice, and using the product does not by itself make an organization compliant with GDPR, CCPA, CPRA, the DPDP Act, or any other law.