Process Data Subject Requests (DSR console)
Review, start, complete, reject, or statutorily deny the access/correction/erasure requests your Data Principals file.
What this is, and why it matters
Every request a Data Principal files from Exercise your rights lands here. The DSR console is your side of that same workflow: it tracks each request’s statutory response deadline, lets you move it through its lifecycle, and — where the law genuinely doesn’t allow erasure — lets you record why instead of silently ignoring the request. Handling these correctly and on time is a direct DPDP Act obligation, and unresolved or overdue requests are exactly what a Data Protection Board complaint looks like from the outside.
Before you start
- Available to both Fiduciary Admin and DPO roles.
- If you plan to deny an erasure request on legal-obligation grounds (e.g. a sector-specific retention law), have the statute name and citation ready — or use the built-in suggestion picker if your sector has common ones pre-loaded.
Steps
-
Open DSR Requests from the sidebar. Requests are listed with their type (access / share / correct / erase), current status, and a due-date badge — Due soon or Response overdue — driven by the same 90-day clock the Data Principal sees on their end.
Caption: the request list, each row showing type, status badge, and an overdue/due-soon flag where relevant. -
Select a request to open the process dialog. From here you can:
- Start — move it to in progress once you’ve begun working on it.
- Complete — mark it resolved once you’ve fulfilled it.
- Reject — decline the request outright.
Caption: the request detail dialog with the three primary lifecycle actions. -
For an erasure request you can’t fulfil because another law requires you to keep the data (e.g. RBI KYC or PMLA retention rules), use Deny on a statutory basis instead of a bare rejection. If your sector has common citations pre-loaded, pick one from Common statutory bases to auto-fill the statute and citation fields — or type your own — then select Deny with statutory basis.
Caption: the “Deny on a statutory basis” panel, showing the suggestion dropdown plus the editable Statute and Citation fields.
What happens next
- Start and Complete update the request’s status immediately — the Data Principal sees the new status on their Exercise your rights page right away.
- A statutory denial is recorded with its statute and citation attached to the request, so the reasoning is auditable later — unlike a plain rejection, it documents why rather than just that you declined.
- Requests approaching or past their due date keep showing their overdue flag until you resolve them — treat that flag as your primary SLA signal.
Related
- Exercise your rights — the Data Principal side of this same workflow.
- Grievances console
- DPBI Complaints