Skip to main content
ASIRI

Data subject rights and DSR operations

Run access, erasure, rectification, objection, portability, and consent withdrawal requests with identity checks and evidence.

Plain English

What the chapter means in practice.

DSRs are not just inbox work

A request touches identity, systems, exemptions, processors, legal review, customer communication, and audit evidence.

Operational takeaway

A DSR workflow should show who approved the response, what data sources were searched, what exemptions applied, and when the final response was sent.

Checklist

What to document.

  • Create an intake channel that records request type and timestamp.
  • Verify identity before disclosing or deleting data.
  • Export a response pack and audit timeline for each request.
Related workflows

Turn the chapter into an operating workflow.