When someone asks for their data — or asks you to delete it — the clock starts. We stand up a rights-request workflow that meets statutory timelines every time, so access, correction and erasure requests are handled cleanly instead of causing a fire drill.
Privacy laws give individuals enforceable rights over their personal data — to access it, correct it, have it erased, and raise grievances. Under the GDPR these are Data Subject Access Requests (DSARs) and related rights on a one-month clock; under India’s DPDP Act, Data Principals have rights to access, correction, erasure, grievance redressal and to nominate someone to exercise rights on their behalf.
The hard part isn’t knowing the rights exist — it’s answering each request completely and on time, across every system the data lives in, while verifying the requester is who they say they are. That takes a workflow, not goodwill.
Everything needed to answer a request accurately, on time, every time.
A clear channel for individuals to make requests, logged and tracked from the moment they arrive.
Proportionate checks that confirm the requester without creating a new privacy risk of their own.
Repeatable playbooks — powered by your RoPA — for finding all of a person’s data across systems and vendors.
Vetted response templates for access, correction, erasure and refusal, with the required reasoning.
Timeline tracking so every request is answered within statutory limits, with escalation before deadlines slip.
Guidance on refusals, third-party data, and repeated or excessive requests — handled defensibly.
A quick way to place yourself, then confirm it with a readiness assessment.
Data subjects can exercise access, erasure, rectification and objection rights, and you must respond within one month — extendable only in limited cases.
Data Principals have rights to access, correction, erasure and grievance redressal, plus the right to nominate — all of which you must be able to service.
If you serve many users, requests are a matter of when, not if — a workflow is the difference between routine and chaos.
Turn rights requests from a recurring emergency into a logged, repeatable process.
Because we know where data lives, searches are complete and fast — no missed systems, no partial answers.
Every request is tracked against its statutory deadline with escalation built in, so timelines don’t slip.
Where a request can be refused or narrowed, the reasoning is documented to the standard a regulator expects.
The GDPR’s Articles 12–23 set out data-subject rights and the one-month response window (with limited extension). India’s DPDP Act 2023 gives Data Principals rights to access, correction and erasure, to grievance redressal, and to nominate another person to exercise their rights. We build one workflow that services both, on their respective timelines. This is decision-support, not legal advice.
Most engagements fold into a single accountable retainer — usually 40–60% below the cost of a full-time hire. See how the tiers map to your scope.
Under the GDPR you generally must respond within one month, extendable by two further months for complex or numerous requests. Under the DPDP Act, timelines are set under the Act and Rules; we track each request against the applicable deadline.
With proportionate identity checks — enough to be confident without collecting excessive new data. We build verification steps that fit the sensitivity of the request.
That’s exactly why a RoPA matters. With an accurate data map, our search playbooks locate every instance of a person’s data so responses are complete.
Sometimes — for manifestly unfounded or excessive requests, or where an exemption applies. The key is documenting the reasoning defensibly, which our templates handle.
The DPDP Act lets a Data Principal nominate another individual to exercise their rights on their behalf, for example in case of death or incapacity. Your workflow needs to accommodate nominated requests.
No pitch, no obligation — just a clear read on where you stand and what an engagement would cover.
New to privacy roles? Read What is a Data Protection Officer (DPO)?