DSR (Data Subject Request) / DSAR request
ما هو DSR (Data Subject Request) / DSAR request?
هذا المصطلح متوفر حاليًا باللغة الإنجليزية فقط.
A data subject request (DSR — a data subject access request, or DSAR, when the right being exercised is access) is a verified person's formal ask to exercise a privacy right a law grants them: access to a copy of their data, deletion, correction, portability, or opt-out of sale. Each regime sets a hard response deadline — one month under GDPR (extendable once for complex requests) and 45 days under CCPA/CPRA — and fulfilment must be demonstrable, which is why requests are queued and logged rather than answered ad hoc.
More detail
Request types differ by regime. GDPR grants access, rectification, erasure (the right to be forgotten), and portability; CCPA/CPRA adds the right to know what is collected and to opt out of the sale or sharing of personal data. Intake must capture which right is being exercised, because access, deletion, portability, and opt-out routes produce different fulfilment work.
The deadline belongs to the regime the request invoked, not the longest or shortest possible one: GDPR's one calendar month runs from the verified request (one permitted extension for complex requests), while CCPA/CPRA sets 45 days from receipt. Missed deadlines are reportable violations, so an auditable queue with identity verification, a running SLA clock, and a logged fulfilment trail is what makes the deadline achievable in practice.
On Orbit, a request can be filed two ways — by your support or compliance team on a customer's behalf, or by the data subject through a public self-service portal that proves identity with a two-factor email + SMS OTP before the request is queued. Both routes land in the same fulfilment pipeline, spanning contact records, message and call content, recordings, and delivery metadata rather than a single table.
الأسئلة الشائعة
- Is DSR the same thing as DSAR?
- DSR is the umbrella term for any data-subject right request; DSAR specifically names the access variant. In practice a single intake pipeline handles both, and the recorded request type (access, deletion, correction, portability, opt-out of sale) decides the fulfilment path.
- Which deadline applies — GDPR's month or CCPA's 45 days?
- Whichever regime the verified requester invokes. GDPR allows one calendar month, extendable once for complex requests; CCPA/CPRA allows 45 days from receipt. A fulfilment queue should track the invoked regime's clock separately rather than blanket-apply one deadline.
See also
Build it on Orbit
Voice, messaging, email, video, and AI agents on one platform and one pay-as-you-go bill. Start free — no credit card required.