Docs

DSAR requests

AdminUpdated Sep 15, 2026

DSAR requests

A Data Subject Access Request (DSAR) is any formal ask from a visitor to access, delete, correct, or export the personal data you hold on them. Dashboard → Privacy → DSAR gives you an intake queue, a status workflow, and the tools to actually fulfill the request against your consent records.

Logging a request

Click New request and fill in:

Field

Options

Request type

Access, Deletion, Rectification, Portability, Opt-out

Regulation

GDPR, CCPA

Subject

Any identifier the requester gave you — email, account ID, phone number, etc.

The due date is set automatically from the regulation's statutory deadline: 30 days for GDPR (Art. 12(3)), 45 days for CCPA.

Status workflow

Requests move through a fixed set of statuses, and only in the allowed direction:

Status

Can advance to

received

verifying, rejected

verifying

in_progress, rejected

in_progress

completed, rejected

completed

— (terminal)

rejected

— (terminal)

Use the Advance dropdown on each row to move a request forward — Cookie Munch only offers the statuses that are legal next steps from where it currently sits.

Note: A request past its due date and not yet in a terminal status is flagged Overdue in red — the header badge shows your total overdue count at a glance.

Fulfilling access/deletion requests

Once you've verified the requester's identity, two actions become available on rows where you have their consent receipt stamp (from the consent log):

  • Export data — downloads a JSON file of every consent record tied to that stamp for the given site, satisfying an access/portability request. Nothing is deleted.

  • Erase data — permanently crypto-erases the subject's consent records (their user agent and page URL) for that site. The tamper-evident hash chain stays intact — only the personal fields are unrecoverable — and this cannot be undone.

Both require the site's cbid and the subject's stamp. If crypto-erasure isn't configured (no encryption key set on the server), the erase action tells you so instead of silently no-oping.

Note: Crypto-erasure only removes what's encrypted per-subject (user agent, URL). It does not remove the subject from your own CRM, order history, or any other system — DSAR fulfillment for those systems is your responsibility outside Cookie Munch.

See also: Consent log · Preference center · Audit export & receipts

Was this page helpful?
DSAR requests