
The embedded DSR request form
Visitors submit any enabled request type through a guided, multi-step form:- Request types — access, deletion, correction, portability, objection, and restriction. Enable only the types relevant to your applicable regulations, ordered and labeled per region: GDPR rights for European visitors, India DPDP rights for Indian visitors, CCPA rights for Californians.
- Configurable fields — customize the intake fields per request type so you collect exactly what fulfillment needs, and nothing more.
- Guided flow — the form explains each right in plain language and gathers the identity details needed for verification, reducing malformed and duplicate requests.
Visitor submits a request
The form collects the request type, scope, and contact details, then sends a confirmation email with a unique tracking link.
Identity verification runs
The verification challenge configured for that request type is sent automatically — see below.
The request enters fulfillment
Verified requests flow into DSR fulfillment. The visitor can check live status — received, in review, processing, completed — from their tracking link at any time, without contacting support.
Identity verification
Every request is verified before it enters the processing queue, with proportional verification configured per request type:| Request sensitivity | Example | Typical verification |
|---|---|---|
| Low | Marketing opt-out | Email confirmation link |
| Medium | Access request | Email OTP |
| High | Full deletion | Email + SMS OTP or knowledge-based checks |
| Very high | Sensitive-category data | ID document check |
Consent and communication preferences
The Privacy Center gives visitors transparent, instant control over what you hold and send:Consent transparency
Authenticated users see exactly which consents your organization holds for them and when each was given — pulled live from your consent records.
Instant withdrawal
Preferences can be updated or consent withdrawn immediately from the portal; every change is recorded as a consent event with a full audit trail.
Communication preferences
Visitors choose channels and topics — marketing email, SMS, product updates — and changes propagate to your connected marketing stack via integrations.
Cookie preferences
A link reopens the cookie preference center, keeping web consent and portal preferences consistent.
Authenticated access
Enable authenticated access so users can log in with a magic link sent to their email address. Authenticated users get:- Their consent history and the live preference center
- Their submitted request history with statuses
- All of it scoped strictly to their verified identity
Anonymous visitors can still submit requests — authentication is optional and adds convenience, while identity verification remains mandatory for every request regardless.