DSR Overview
What data subject requests are, the rights MineOS supports, and how a request moves from submission to closure.
A data subject request (DSR) is a request from an individual — the data subject — to exercise their rights over the personal data your organization holds about them. MineOS gives your privacy team one place to receive, verify, process, and close these requests across every connected system, so you can respond accurately and within regulatory deadlines.
What a data subject request is
Under modern privacy laws, individuals can ask an organization to act on their personal data — for example, to receive a copy of it, delete it, or stop it from being sold. Each type of request corresponds to a privacy right. When someone submits a request, MineOS creates a DSR: a single record that tracks it from the moment it arrives until it is closed.
Why DSRs matter
Responding to DSRs is a legal obligation under regulations such as the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and a growing number of other state and national laws. Most set strict response deadlines — GDPR, for example, generally requires a response within 30 days — and expect you to verify the requester's identity before acting. Handling every request consistently, and keeping a clear record of what was done, is central to demonstrating compliance.
The rights MineOS supports
MineOS handles the full range of common privacy rights, including:
- Access (copy) requests — the data subject receives a copy of the personal data you hold about them (a data subject access request, or DSAR).
- Deletion requests — their personal data is removed from your systems.
- Do Not Sell requests — their data is excluded from sale or sharing.
- Right to Edit (correction) requests — inaccurate personal data is corrected.
- Do Not Mail and other rights — including custom rights you define for the regulations that apply to your business.
The request lifecycle
Every DSR moves through a consistent lifecycle:
- Received — the request arrives through one of your intake channels: the Privacy Center, email forwarding, a toll-free number, manual creation, or import of bulk requests.
- Verified — the data subject's identity is confirmed, typically through email verification, before any data is touched. This step is applicable only when submitting a request via the Privacy Center's intake form.
- Pending — an optional waiting period can hold the request before processing begins with Autopilot, which orchestrate automatic processing.
- Processing — MineOS coordinates the work across your connected systems, either automatically or with your team completing tasks manually.
- Closed — the request is completed, rejected, or canceled, and the data subject is notified.
After a request is closed, MineOS can automatically redact personal data from the request record once a retention period has passed. A closed request can also be reopened if further action is needed.
How MineOS helps
Instead of tracking requests across spreadsheets and email threads, MineOS centralizes intake, identity verification, processing across your data sources, communications with the data subject, and a complete audit trail — so your team can meet regulatory deadlines and show that every request was handled correctly.
Updated about 17 hours ago
