DSAR requests
- Written for
- + Written for
- Deprecated
- + Deprecated
- Applies to
- + Applies to
DSAR requests
A Data Subject Access Request (DSAR) is any formal ask from a visitor to access, delete, correct, or export the personal data you hold on them. Dashboard → Privacy → DSAR gives you an intake queue, a status workflow, and the tools to actually fulfill the request against your consent records.
Logging a request
Click New request and fill in:
Field | Options |
|---|---|
Request type | Access, Deletion, Rectification, Portability, Opt-out |
Regulation | GDPR, CCPA |
Subject | Any identifier the requester gave you — email, account ID, phone number, etc. |
The due date is set automatically from the regulation's statutory deadline: 30 days for GDPR (Art. 12(3)), 45 days for CCPA.
Status workflow
Requests move through a fixed set of statuses, and only in the allowed direction:
Status | Can advance to |
|---|---|
|
|
|
|
|
|
| — (terminal) |
| — (terminal) |
Use the Advance dropdown on each row to move a request forward — Cookie Munch only offers the statuses that are legal next steps from where it currently sits.
Note: A request past its due date and not yet in a terminal status is flagged Overdue in red — the header badge shows your total overdue count at a glance.
Fulfilling access/deletion requests
Once you've verified the requester's identity, two actions become available on rows where you have their consent receipt stamp (from the consent log):
Export data — downloads a JSON file of every consent record tied to that stamp for the given site, satisfying an access/portability request. Nothing is deleted.
Erase data — permanently crypto-erases the subject's consent records (their user agent and page URL) for that site. The tamper-evident hash chain stays intact — only the personal fields are unrecoverable — and this cannot be undone.
Both require the site's cbid and the subject's stamp. If crypto-erasure isn't configured (no encryption key set on the server), the erase action tells you so instead of silently no-oping.
Note: Crypto-erasure only removes what's encrypted per-subject (user agent, URL). It does not remove the subject from your own CRM, order history, or any other system — DSAR fulfillment for those systems is your responsibility outside Cookie Munch.
See also: Consent log · Preference center · Audit export & receipts