Every data subject request enters a single unified queue, regardless of channel, with full context preserved.
DSR intake form and verification settings

Intake channels

ChannelHow it works
Privacy Center portalThe branded Privacy Center hosts a request form with configurable fields per request type.
Email inboxPoint a privacy@ address at TruePrivacy; incoming emails are parsed into request records.
REST APICreate requests programmatically from your own apps and support tools. See API Reference.
You can create separate request queues for different data subject categories — customers, employees, contractors, website visitors — each with tailored intake forms, verification methods, and routing rules.

Proportional identity verification

Verification protects against fraudulent requests without adding friction for legitimate ones. TruePrivacy uses proportional verification: the verification level is configured per request type.
Request sensitivityExampleTypical verification
LowMarketing opt-outEmail confirmation link
MediumAccess requestEmail OTP
HighFull deletionEmail + SMS OTP or knowledge-based checks
Very highSensitive-category dataID document check
1

Choose verification methods per request type

Under DSR → Settings → Verification, assign a verification chain to each request type and queue.
2

The requester completes the challenge

The challenge is sent automatically on intake. The deadline clock starts at intake, and verification progress is visible on the request record.
3

Unverified requests expire

Requests that fail or never complete verification are closed automatically after a configurable window, with the attempt logged.
Fulfilling a deletion or access request for the wrong person is itself a data breach. Never lower verification requirements for high-risk request types to speed up throughput.
Verification events — challenge sent, completed, failed — are recorded in the request’s audit trail for regulatory proof.