Modules/Privacy Operations

DSAR Requests

by Formiti's Global DPO Team

A workflow-driven module for receiving, triaging, fulfilling, and closing data subject access requests with full audit trails and deadline tracking.

Who uses this module?

DPOs, Privacy Operations Teams, Customer Service Leads, Legal Counsel.

What governance problem does it solve?

DSAR deadlines are strict, and they are not the same everywhere. GDPR Article 12(3) gives one calendar month, extendable by two further months where a request is complex; California allows 45 days with a separate 10-day acknowledgement; Singapore and Thailand work to 30 days; Brazil requires a full statement within 15 days. Teams working from a single hard-coded deadline are either late in one jurisdiction or over-servicing in another. This module applies the correct statutory period per request, tracks it to closure, and produces the evidence a regulator would ask for.

What are the key workflows?

  • Log incoming requests with subject identity verification
  • Categorise request type (access, erasure, rectification, portability, objection)
  • Apply the statutory response period for the applicable jurisdiction and assign to a named handler with a deadline countdown and escalation alerts
  • Track multi-step fulfilment with internal notes and evidence attachments
  • Close with documented response and regulatory-ready audit record
Workflow sequence
1

Log incoming requests with subject identity verification

2

Categorise request type (access, erasure, rectification, portability, objection)

3

Apply the statutory response period for the applicable jurisdiction and assign to a named handler with a deadline countdown and escalation alerts

4

Track multi-step fulfilment with internal notes and evidence attachments

5

Close with documented response and regulatory-ready audit record

One request, different clocks

The statutory period for responding to a data subject request is not the same in any two regimes, and the difference is not cosmetic. Privacy360 identifies the applicable law when a request is logged and applies that jurisdiction's period, counted the way that law counts it.

  • EU and UK — one calendar month from receipt under Article 12(3), extendable by two further months where the request is complex or numerous. A calendar month is not 30 days, and Privacy360 does not treat it as one
  • California — 45 days to respond under the CCPA regulations, with a separate obligation to acknowledge within 10 days and an available 45-day extension
  • Singapore and Thailand — 30 calendar days, against the PDPC's published benchmark and section 30 of Thailand's PDPA respectively
  • Brazil — simplified confirmation immediately, with the full statement due within 15 days under Article 19 of the LGPD
  • Vietnam — two clocks on every request since 1 January 2026: respond within 2 working days, then implement within 10, 15 or 20 days depending on which right is exercised, with longer windows where a processor or third party must act
  • Extensions are recorded with their justification, not merely flagged, because several regimes place the burden of proving the extension was necessary on the controller

Where a request spans multiple entities in different regions, the deadline is resolved per entity rather than per tenant, so a group response does not inherit the shortest or the longest clock by accident.

The applicable period, the date it was calculated from, and any extension and its stated reason are all retained on the request record. That is what turns a closed request into evidence rather than an assertion.

What evidence and reporting does it produce?

Built-in outputs for accountability and regulatory readiness

Request-to-resolution timeline analytics

SLA compliance rates by request type

Volume trends by entity, department, and period

Complete audit trail per request for regulatory enquiries

How does it connect to other Privacy360 modules?

  • Links to ROPA to identify relevant processing activities for the data subject
  • Breach incidents may trigger related DSARs
  • Processor Records identify third parties holding subject data
  • Evidence can be cross-referenced with Privacy Documents

What are some example use cases?

Customer Ops

A customer submits an erasure request; the privacy team identifies all relevant processing activities via ROPA, confirms deletion with two processors, and closes the request in 18 days with full documentation.

Scenario 1
DPO

A DPO generates a quarterly DSAR volume report showing a 40% reduction in average response time after workflow optimisation.

Scenario 2
Legal Counsel

Legal counsel reviews the audit trail of a contested DSAR to prepare a response to a DPA enquiry.

Scenario 3

Frequently asked questions

Is the GDPR deadline 30 days or one month?

One calendar month from receipt, under Article 12(3), extendable by two further months where the request is complex or numerous. It is not 30 days — a request received on 31 January falls due on 28 February. Privacy360 calculates calendar months rather than applying a fixed day count.

How does Privacy360 decide which jurisdiction's deadline applies?

The applicable law is resolved when the request is logged, from the entity the request is made against and the data subject's jurisdiction, and the corresponding statutory period is applied to that request. Requests spanning entities in different regions are resolved per entity.

Can we track extensions?

Yes. An extension records the new due date, the reason given to the data subject, and the justification for it. Several regimes place the burden of proving an extension was necessary and reasonable on the controller, so the justification is stored as evidence rather than as a status flag.

What evidence does a closed DSAR produce?

A full audit trail: identity verification, request classification, handler assignment, every fulfilment step with internal notes and attachments, the response issued, and the deadline calculation that applied — exportable for a regulatory enquiry.

See the operational platform in action

Book a demo to see how Privacy360 brings assessments, records, consent, contracts, AI governance, training and evidence into one operational system tailored to your programme.

Privacy-first website: We do not use tracking cookies, advertising pixels, or third-party analytics on this site. Read our Privacy Notice.