Data subject access request intake
A public form for the requests you enable, separate from the marketing site’s cookie banner.
Rights
Consent Guru includes workflows for data subject access requests and related rights, from intake through a status the person can check.
A DSAR asks what data you hold, or asks you to correct or delete it. A cookie choice does not answer that request. The two workflows should meet, but they should not be collapsed into one checkbox.
The public Privacy Centre accepts Data Principal requests and grievances. The workspace is where your team verifies the request and records the outcome.
Step 1
People submit access, correction, erasure, nomination, grievance, or consent-withdrawal requests through the Privacy Centre.
Step 2
The workflow supports email-token verification and, where configured, an agent-attested path. Verification exists to reduce unauthorized disclosure.
Step 3
Your team updates status, including correction and deletion steps recorded in the rights workspace.
Step 4
The person can check progress with a tracking reference instead of an open-ended email thread.
A public form for the requests you enable, separate from the marketing site’s cookie banner.
Statuses, verification method, and audit metadata stay on the request record.
A grievance path sits beside access and erasure, which matters for DPDP-style complaint handling.
Rights-request retention is configurable and is distinct from consent-evidence retention.
Confirm identity, then record what was provided and when.
Track erasure work without pretending the CMP deleted every downstream system.
Use Data Principal language in the public centre alongside the DSAR-style rights your other markets use.
Deadlines, exemptions, and the scope of a request come from the law that applies, not from the form. This page is not legal advice.
Deletion of personal data is separate from withdrawal of consent. Withdrawing a cookie purpose does not automatically erase data a vendor already received.
A data subject access request is a person’s request to know whether an organization holds personal data about them and, where the law provides it, to receive a copy or related details.
It is the operational process of receiving, verifying, fulfilling, and recording access, correction, deletion, and similar requests.
Use the Data Principal request page in the Privacy Centre. Consent Guru’s own contact for privacy questions is support@consentguru.com.
This page describes how Consent Guru supports privacy operations. It is not legal advice, and using the product does not by itself make an organization compliant with GDPR, CCPA, CPRA, the DPDP Act, or any other law.