Skip to content

DSAR Record — {{REQUESTER_REF}}

Copy to compliance/dsar/<YYYY-MM-DD>-<requester-ref>.md on intake. This record is the per-request evidence artifact; its git history is the audit trail. Use a pseudonymous requester-ref — do not put the requester's personal data in the filename.

Requester ref {{REQUESTER_REF}} (pseudonymous)
Request type access / deletion / rectification / portability / opt-out
Regime GDPR / CCPA / both
Received {{YYYY-MM-DD}}
Acknowledged {{YYYY-MM-DD}}
Due {{YYYY-MM-DD}} (GDPR +30d / CCPA +45d)
Extension none / +{{N}}d — reason + notified-on date
Owner {{OWNER}}
Status open / fulfilled / refused (DPO-approved)

Identity verification

  • Method: {{e.g. reply-to address matched account email; authenticated session challenge}}
  • Verified on: {{YYYY-MM-DD}} by {{NAME}}

Systems walked (from the data inventory)

Activity id System Found? Action taken Exemption (if any)
crm-customer-records HubSpot CRM yes/no exported / deleted
prod-app-customer-data Prod Azure SQL yes/no exported / purge endpoint
telemetry-logs Log Analytics (J1) yes/no security-retention exemption, documented

Backups statement

Deleted from live systems on {{YYYY-MM-DD}}; backup copies age out per L1 retention ({{PERIOD}}). Restore procedures re-apply pending deletions if a covered backup is restored. No selective backup purge was performed or claimed.

Response

  • Sent: {{YYYY-MM-DD}} via {{CHANNEL}}
  • Contents: {{export format / deletion confirmation incl. exemptions}}

Follow-ups

  • Inventory gaps found: {{none / fixed in PR #…}}
  • Incidents/tickets opened: {{none / E7 ticket ref}}