Certus
← All services

Data Subject Request (DSR) Management

The workflow, tooling and SLA discipline to handle access, correction and deletion requests without scrambling.

What it is

The end-to-end operating process for receiving, verifying, fulfilling and logging data subject requests — access, correction, deletion and objection — within the timeframes PDPL requires, across every system that holds personal data.

Why it matters

A single mishandled DSR — missed deadline, incomplete disclosure, or a response that leaks someone else's data — is one of the fastest ways to turn a routine request into a regulatory complaint. Most organisations discover their DSR process doesn't work the first time a real request arrives, under time pressure, with legal watching.

What Certus does
  • Design the intake, identity-verification and fulfilment workflow across legal, IT and business owners.
  • Build the system-of-record to track every request, deadline and decision with a full audit trail.
  • Train the people who will actually triage requests, including edge cases and refusal grounds.
  • Run a live simulation before go-live so the first real request isn't the first test.
What you receive
  • A documented DSR standard operating procedure with clear RACI
  • A working DSR intake and tracking workflow, built into tools you already use
  • Response and refusal templates reviewed against PDPL requirements
  • A trained internal team, plus 90 days of Certus oversight on live requests
Typical timeline

4–6 weeks to design and implement; ongoing managed support available.

Who this is for

DPOs, Compliance Analysts, Legal and Customer Operations teams who own the moment a data subject actually exercises their rights.

How this differs from a generic consultancy

We don't stop at a policy document. We build the operational workflow and stay until your team can run it under deadline pressure without Certus in the room.