Skip to content

Data Subject Requests: Built Into Your Consent Platform

Visitors can exercise CCPA/CPRA privacy rights in the U.S. and the EU’s GDPR via a simple embedded form. No extra tools. No extra cost. Live in minutes.

CCPA/CPRA willful violations carry significant per-violation fines of up to USD 7,500. Lower tier GDPR fines can be up to EUR 10 million or two percent of global annual revenue. It creates direct legal exposure for your business if you make it unnecessarily difficult for consumers to exercise their rights.

A missed response deadline is a regulatory violation waiting to happen. Under the CCPA/CPRA you have 45 days to respond. Under the GDPR you have one calendar month. Manual processes like email inboxes and spreadsheets can’t reliably track, route, or document requests at scale.

How it works

DSR is fully integrated inside your Usercentrics CMP. Available on all paid plans, with no custom development or deployment required. 

Important: Usercentrics DSR manages the request submission and tracking workflow. Businesses remain responsible for fulfilling requests in their own systems, including accessing, correcting, or deleting the relevant personal data.

1

Activate in Your Admin

Login to your Usercentrics account and navigate to the DSR tab in your Admin Interface. Toggle it on to activate. Now you’re ready to set up for form.

2

Customize Your Form

Set your logo, recipient email, title, and description directly in the Admin Interface. Copy your unique DSR link when you’re done.

3

Embed on Your Site

Add your DSR link to your website footer, a privacy button, or your consent banner. Visitors can then submit rights requests directly from your site.

4

Manage and Respond

Verified DSR requests appear in your Admin Interface dashboard with submission date, request type, and status. Track progress and stay ahead of the response deadline.

Built to support privacy compliance

Usercentrics DSR solution is focused and lightweight. It’s built to support compliance, not create complexity.

Starting with the U.S. and Europe

DSR launches with CCPA/CPRA and GDPR support for important data rights.

  • Right to know what personal data is collected
  • Right to access collected personal data
  • Right to request correction of inaccurate or incomplete personal data
  • Right to restriction of processing in certain circumstances (GDPR)
  • Right to request deletion of collected personal data
  • Right to opt out of sale and sharing of personal data
  • Right to know about and opt out of automated decision-making
  • Right to data portability (GDPR, Art. 20)
  • Right to limit use and disclosure of sensitive personal information (CPRA)

Learn more about DSR and privacy rights

Frequently asked questions

A Data Subject Request (also known as a Data Subject Access Request) is a formal request from an individual to exercise their privacy rights under applicable law. Among others, these rights include requesting access to, deletion of, or correction of their personal data. 

Under the CCPA/CPRA, businesses must provide a mechanism for users to submit these requests and respond within 45 days. Under the GDPR, businesses must respond to requests within one calendar month.

Any business that collects personal data from California or EU residents (and meets CCPA thresholds), must provide a mechanism for consumers to exercise their privacy rights, including the right to know, access, delete, correct, and opt out of sale or sharing. Enterprise procurement teams increasingly require this as a baseline compliance check before signing contracts.

Usercentrics DSR is built directly into your existing consent management platform, so you can activate it from your Admin Interface with one click. You don’t have to set up another vendor or complete another integration, and there’s no additional cost. It’s available for all paid plans.

When a visitor submits a DSR, they immediately receive a confirmation email to verify their identity. Only after clicking the confirmation link does the request proceed to your admin dashboard. This helps reduce fraudulent or automated submissions while keeping the process simple for legitimate requesters.

Yes. DSR covers the CCPA/CPRA and the GDPR, and we plan to expand jurisdictional coverage over time.

DSR is available as soon as you log into your Usercentrics Admin Interface. Navigate to the DSR tab, customize your form (logo, email, title, description), copy your unique DSR link, and add it to your site. Most customers go live in under 10 minutes with no developer involvement required.

The user receives an email confirmation to verify their identity. Once confirmed, your team receives a notification and the request appears in the Admin Interface dashboard with the submission date, request type, and status so you can manage your response and deadlines.

Yes, DSR is included in all Usercentrics paid plans at no additional cost. It is available for Starter, Professional, and Enterprise customers. Simply log in to your Admin Interface and activate it from the DSR tab. No upgrade or separate purchase required.