DSR Portal. Automate Data Subject Requests in 30 Days, Not 3 Months
The DPDP Act mandates a 30-day response window for all data principal rights requests. Automate access, correction, erasure, portability, and India's unique Right to Nomination, with identity verification, SLA countdown, and complete audit trail. Built specifically for Section 11-14 DPDP compliance.
Five Legal Rights. One 30-Day Window. ₹50 Crore Penalty.
Sections 11-14 of the DPDP Act create legally enforceable rights. Every Data Fiduciary must have a documented mechanism to receive and respond to them.
Sections 11-14. Data Principal Rights
The DPDP Act grants every data principal five rights: access to data and processing summary (Sec 11), correction and erasure (Sec 12), grievance redressal (Sec 13), and nomination (Sec 14). Data Fiduciaries must provide a "readily available" mechanism to exercise these rights. An email address is insufficient, the DPA expects a structured, trackable system with documented response timelines.
Section 66 Schedule. ₹50 Crore Penalty
Non-compliance with data principal rights obligations, refusing valid requests, missing deadlines, or failing to maintain a grievance mechanism, attracts penalties up to ₹50 Crore under the DPDP Schedule. For organizations processing millions of users' data (D2C brands, FinTechs, HR platforms), a single class complaint to the DPA could trigger an inquiry affecting every unfulfilled DSR request in the past 12 months.
Section 14. Nomination Right (Unique to India)
No other privacy law in the world grants individuals the right to nominate a successor to exercise their data rights after death. Section 14 of the DPDP Act creates this obligation, and most organizations have no process for it. When a data principal dies, their nominee can request access to their data, seek erasure, or submit correction requests. Your DSR portal must be equipped to handle and verify these requests.
End-to-End DSR Automation. All Five Rights, One Platform
Branded Self-Service DSR Portal
A public-facing, branded portal where data principals submit all five request types, access, correction, erasure, portability, and nomination. The portal is embeddable on your website or accessible via a dedicated subdomain. It is fully mobile-responsive and works without requiring users to create an account, lowering the barrier for legitimate requests.
Multi-Layer Identity Verification
Email OTP verification as the baseline, with configurable additional checks including document upload and manual senior review for sensitive data categories. Every verification step is timestamped and stored, providing audit evidence that you fulfilled requests only after confirming identity, and that you rejected unauthorized requests on documented grounds.
30-Day SLA Countdown with Escalation
Automatic SLA clock starts the moment identity verification is complete. Dashboard shows remaining days for every open request. Automatic escalation alerts are sent to the assigned team member at 10 days, 5 days, and 2 days before deadline. Overdue requests trigger a critical alert in the compliance dashboard and an email to the DPO or compliance manager.
Automated Request Routing Workflow
The system categorizes each incoming request by type and routes it to the configured team, access requests go to the Data Ops team, erasure requests go through Legal review, and nomination requests are flagged for senior review. Teams receive in-app and email notifications. Every status change, pending, in review, approved, fulfilled, rejected, is logged with timestamp and user ID.
Right to Nomination. India's Unique DSR
A dedicated nomination workflow that allows data principals to register a nominee during their lifetime, and allows verified nominees to raise DSRs after the principal's death. Nominee verification includes government ID upload and death certificate requirement. This is the only DSR portal in India built specifically to handle Section 14 nomination right requests in a DPDP-compliant workflow.
Automated Data Package Assembly
For access and portability requests, the system auto-compiles the data package from your configured data sources, profile data, transaction history, consent records, and processing log. The package is delivered to the data principal via a secure, time-limited download link. All data is packaged in machine-readable JSON or CSV format as required for portability requests under DPDP.
From Request Submission to Fulfilled DSR. Fully Automated
Your compliance team focuses on decisions, not paperwork. The portal handles intake, verification, routing, tracking, and delivery.
Step 1. Data principal submits request via your branded portal
The user selects the request type (access, erasure, correction, portability, or nomination), enters their identifying information, and submits. The system generates a request reference number and sends an acknowledgment email within seconds, starting the DPDP-compliant acknowledgment obligation clock.
Step 2. Identity verified via email OTP (or enhanced verification)
The requestor completes OTP verification to confirm their email. For sensitive data categories (financial records, health data, Aadhaar-linked data), the system prompts an additional document upload before the request is accepted. Unverified requests are held in a pending state and auto-expired after 7 days if the data principal does not complete verification.
Step 3. Request routed to appropriate team with SLA clock active
The verified request appears in the admin dashboard, assigned to the correct team based on request type and data category. The 30-day SLA countdown begins immediately. Team members can view request details, add internal notes, request clarification from the data principal, and move the request through workflow stages, all with a complete audit log.
Step 4. Data package prepared, reviewed, and securely delivered
For access/portability requests, the data package is assembled from configured sources and reviewed before delivery. For erasure requests, the system logs the deletion confirmation from each data store. The data principal receives a secure delivery notification. The completed request is archived with the full evidence trail, fulfillment record, timeline, verification steps, and any rejection grounds.
Step 5. Generate compliance report for auditors
The DSR module maintains a running log of every request received, response time, fulfillment rate, and breach of SLA incidents. One-click export produces a compliance report showing your organization's DSR response record, suitable for DPA inquiries, internal audit reviews, and ISO 27701 certification audits.
DSR Volume Varies by Sector. So Does the Compliance Challenge
D2C Brands. High-Volume Consumer DSRs
Direct-to-consumer brands with large customer bases face erasure and access requests from churned customers and app uninstall users at scale.
- Handle hundreds of concurrent DSR requests without manual processing
- Auto-compile customer data packages from CRM, order system, and analytics
- Manage erasure requests for marketing databases and email lists
- Prove DPDP compliance to marketplace platforms during onboarding
HR Teams. Employee Data Requests
Employees have the same DPDP data principal rights as customers, and HR data is among the most sensitive an organization processes.
- Handle access requests from current and former employees
- Manage correction requests for performance reviews and payroll data
- Process nomination registrations for employee benefits data
- Coordinate erasure requests with statutory retention obligations under Labour Codes
Healthcare Providers. Patient Data Rights
Patients have a right to access their health records, seek corrections to diagnoses or treatment notes, and nominate a family member to access records after death.
- Secure portal for patient data access requests with enhanced identity verification
- Handle nomination requests from patients for family members
- Document grounds for refusing erasure requests where medical records must be retained
- Maintain audit trail for regulatory reviews by NHSP or State Health Departments
Complete DSR Portal Feature List
Connected to Your Data, and Your Compliance Stack
dcomply Module Connections
The DSR Portal connects with the Consent Management module to cross-reference what processing was consented to, and with the Data Mapping module to understand what systems hold personal data. Erasure requests automatically flag records in all connected data sources. DSR activity is reflected in the Gap Assessment compliance score, every fulfilled request is evidence of active Section 12-14 compliance.
API & Webhook Integration
REST API available for integrating DSR intake directly into your product or support portal, data principals can submit requests from within your app. Webhooks notify your internal systems when erasure or correction requests are approved, enabling automated data deletion workflows. JSON export of all DSR records for GRC platform integration. API documentation available in the developer portal.
Security & Data Handling
All DSR data, including identity documents and personal data packages, is encrypted at rest (AES-256) and in transit (TLS 1.3). Data packages delivered to requestors use time-limited signed URLs that expire after 72 hours. Identity documents uploaded for verification are deleted 30 days after request closure. DSR records are retained for 5 years to support regulatory evidence obligations.
Frequently Asked Questions About DSR Under DPDP
DSR Is Part of a Larger Privacy Program
30-Day Compliance Starts Today
Deploy your DPDP-compliant DSR portal in under 30 minutes. Every data principal right covered, including India's unique Right to Nomination.