Skip to content
🚨 DPDP Rules 2025: Compliance Deadline 42 weeks awayRead handbook →

Process Data Subject Requests (DSR console)

Review, start, complete, reject, or statutorily deny the access/correction/erasure requests your Data Principals file.

What this is, and why it matters

Every request a Data Principal files from Exercise your rights lands here. The DSR console is your side of that same workflow: it tracks each request’s statutory response deadline, lets you move it through its lifecycle, and — where the law genuinely doesn’t allow erasure — lets you record why instead of silently ignoring the request. Handling these correctly and on time is a direct DPDP Act obligation, and unresolved or overdue requests are exactly what a Data Protection Board complaint looks like from the outside.

Before you start

  • Available to both Fiduciary Admin and DPO roles.
  • If you plan to deny an erasure request on legal-obligation grounds (e.g. a sector-specific retention law), have the statute name and citation ready — or use the built-in suggestion picker if your sector has common ones pre-loaded.

Steps

  1. Open DSR Requests from the sidebar. Requests are listed with their type (access / share / correct / erase), current status, and a due-date badge — Due soon or Response overdue — driven by the same 90-day clock the Data Principal sees on their end.

    Screenshot: DSR Requests list with status and due-date badges Caption: the request list, each row showing type, status badge, and an overdue/due-soon flag where relevant.

  2. Select a request to open the process dialog. From here you can:

    • Start — move it to in progress once you’ve begun working on it.
    • Complete — mark it resolved once you’ve fulfilled it.
    • Reject — decline the request outright.

    Screenshot: process dialog with Start / Complete / Reject actions Caption: the request detail dialog with the three primary lifecycle actions.

  3. For an erasure request you can’t fulfil because another law requires you to keep the data (e.g. RBI KYC or PMLA retention rules), use Deny on a statutory basis instead of a bare rejection. If your sector has common citations pre-loaded, pick one from Common statutory bases to auto-fill the statute and citation fields — or type your own — then select Deny with statutory basis.

    Screenshot: statutory denial form with the common-statutory-basis picker open Caption: the “Deny on a statutory basis” panel, showing the suggestion dropdown plus the editable Statute and Citation fields.

What happens next

  • Start and Complete update the request’s status immediately — the Data Principal sees the new status on their Exercise your rights page right away.
  • A statutory denial is recorded with its statute and citation attached to the request, so the reasoning is auditable later — unlike a plain rejection, it documents why rather than just that you declined.
  • Requests approaching or past their due date keep showing their overdue flag until you resolve them — treat that flag as your primary SLA signal.