Data Subject Rights: Handle Every GDPR and CCPA Data Subject Rights Request in One Workflow
The GDPR gives people eight rights over their data. California gives consumers six. Most teams build a process for the access request, then improvise when a correction or portability request lands. Obtainer runs all of them through the same workflow: verify the person, find the data, do the work the right requires, and answer before the clock runs out.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
Data subject rights are the rights a privacy law gives an individual over the personal data an organization holds about them. Under the GDPR there are eight: the right to be informed, the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, the right to object, and rights related to automated decision-making and profiling. Under the California CCPA as amended by the CPRA there are six: the right to know, the right to delete, the right to correct, the right to opt out of sale or sharing, the right to limit the use of sensitive personal information, and the right to non-discrimination. The deadlines differ: the GDPR requires a response without undue delay and within one month, extendable by two further months for complex or numerous requests, while the CCPA gives a business 45 calendar days, extendable once by another 45 days with notice. Nearly every one of these rights depends on the same first step, which is finding where the person's data actually lives. Obtainer runs that step for all of them: it intakes the request, verifies the requester, discovers the data across your systems, compiles a reviewable manifest, and drafts the response against the right deadline. Nothing is disclosed, corrected, or erased automatically. A human approves at a review gate, so you stay in control. Obtainer helps you comply. It is not legal advice, and the legal calls stay with your team. Self-serve DSAR fulfillment from $49/mo, not a six-figure governance suite.
Last updated July 2026
What you get
Data subject rights, built for privacy, legal, and ops teams
One process, not eight
Access, deletion, correction, and portability requests all start by finding the person's data. Obtainer runs that shared step once, so you are not maintaining a separate improvised process for each right.
The right clock on every request
A GDPR request runs on a one-month clock and a CCPA request on 45 days. Each request carries its own countdown, so the deadline is visible rather than something you work out later.
Rights that are not absolute, handled as such
Most of these rights carry exceptions and conditions. Obtainer flags the records that may fall outside a right, so your team makes a deliberate call instead of over-disclosing or over-deleting.
Nothing acts on its own
Whether the request ends in a disclosure, a correction, or an erasure, it waits for a person. A human approves at the review gate, so you stay in control of what happens.
How it works
From an intake request to a ready-to-review response in four steps
Intake and identify the right
Log the request and record which right is being exercised, because a portability request and an access request end in different deliverables on different terms.
Verify the requester
Confirm the person is who they say they are before any data is gathered. Acting on an unverified request is its own risk, whichever right it invokes.
Discover the data
Obtainer surfaces where the person's data lives across your systems and compiles one reviewable manifest, which is the shared foundation under every right.
Do the work and approve it
Disclose, correct, port, or erase, then a human reviews and approves before anything ships. Helps you comply, not legal advice.
Frequently asked
Questions teams ask about data subject rights
What are the 8 data subject rights under GDPR?
The GDPR gives a person eight rights: the right to be informed about how their data is used, the right of access to a copy of it, the right to rectification of inaccurate data, the right to erasure, the right to restrict processing, the right to data portability, the right to object to processing, and rights related to automated decision-making and profiling. Not every right applies to every processing activity.
What is a data subject rights request?
A data subject rights request is a person asking an organization to act on one of their legal rights over their personal data, for example to send them a copy of it, correct it, delete it, or export it. It does not have to use any particular form or wording. A request sent by email to any employee usually still counts, which is why intake matters as much as fulfillment.
How long do you have to respond to a data subject rights request?
Under the GDPR you must respond without undue delay and within one month of receipt, extendable by two further months for complex or numerous requests if you tell the person why within the first month. Under the CCPA a business has 45 calendar days, extendable once by another 45 days with notice, for a total of 90.
What is the difference between GDPR and CCPA data subject rights?
They overlap but are not the same. Both give a right to access and a right to delete. The GDPR adds restriction of processing, objection, and portability on a one-month clock. The CCPA instead adds a right to opt out of the sale or sharing of personal information and a right to limit the use of sensitive personal information, on a 45-day clock. The CCPA also applies only to California consumers and only to businesses that meet its thresholds.
Can a data subject rights request be refused?
Sometimes, on defined grounds. Each right carries its own exceptions, and a request can also be refused where it is manifestly unfounded or excessive under the GDPR. A refusal is not a silent option: you generally have to tell the person you are refusing, explain why, and inform them of their right to complain to a regulator. Document the reasoning at the time you make the call.
Do US companies have to honor data subject rights?
It depends on where your customers are and how big you are, not on where you are incorporated. The GDPR can apply to a US company that offers goods or services to people in the EU or monitors their behavior. Separately, 20 US states now have a comprehensive consumer privacy law in effect, each with its own applicability thresholds, so a US-only business can still owe access and deletion rights to residents of those states.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.