AI is moving fast. See how Whisperly helps you get control back and reduce risk.See how →

    Every data subject
    request, automated.

    Access, erasure, portability and the rest, all arriving through one hosted form into one register. Whisperly finds the data, tracks the one-month deadline and drafts the response, so nothing sits in an inbox.

    Data Subject Requests · Whisperly
    12 open
    12
    Open requests
    2
    Due within 5 days
    6d
    Average completion
    0
    Deadlines missed
    JM
    j.moreau@…
    Former employee · verified
    Erasure
    France
    4 days
    Legal review
    AK
    a.klein@…
    Customer · found in 7 systems
    Access
    Germany
    19 days
    Collating
    RS
    r.stevens@…
    Awaiting identity documents
    Portability
    UK
    Paused
    Verifying
    MO
    m.oliveira@…
    Response sent, pack archived
    Access
    Group
    Closed
    Complete

    The clock starts whether you notice or not.

    A request is valid however it arrives, including a reply to a marketing email or a message to a support agent. Handled by inbox and spreadsheet, the failure modes are predictable.

    Days lost before anyone starts

    The request sits in a shared inbox or with an agent who does not recognise it. By the time it reaches the DPO, a week of the month is gone.

    Nobody knows where the data is

    Finding every system holding one person's data becomes an email hunt across departments, repeated in full for the next request.

    No record of what you did

    If a complaint follows, you need to show when the request arrived, how identity was verified and why anything was withheld. Email threads do not prove it.

    A single front door, on your privacy notice.

    Publish one hosted intake form and link it from your privacy notice, footer and cookie banner. Every submission opens a tracked case with the deadline calculated from the moment it lands, so nothing depends on someone recognising a request in an inbox.

    Every right in one form: access, erasure, rectification, portability, restriction and objection
    Attachments for identity documents, so verification starts in the same step
    Routed to the right legal entity automatically, in that entity's language
    Acknowledgement sent on submission, with the case reference
    See the GDPR obligations behind this →
    privacy.yourcompany.com/request
    Data Subject Request Form

    Submit a request about your personal data. We respond within one month.

    Type of request
    AccessErasureRectificationPortabilityRestrictionObjection
    Full name
    Email address
    Your message
    Identity documents
    Drop a file or browse
    Submit request
    The hosted form, as your data subjects see it

    From submission to response.

    Five stages, each with an owner, a deadline and an audit entry.

    01

    Intake and acknowledgement

    The form opens a case, records the receipt timestamp and sends an acknowledgement with a reference. Requests that arrive by email or post are logged manually into the same queue, so one register covers every channel.

    02

    Verify identity, proportionately

    Verification is scaled to the sensitivity of the data rather than demanding a passport for every request. Where further information is genuinely needed, the clock pauses and resumes when it arrives, with both events recorded.

    03

    Find the data, using your RoPA

    Your record of processing already lists which systems and processors hold which categories of data. The request is scoped against it automatically, producing a targeted list of places to search and owners to task instead of a company-wide email.

    04

    Review exemptions and third parties

    Legal privilege, other people's personal data and retention obligations that override erasure are all flagged for a decision. Each redaction or refusal is recorded with its reasoning, because that is what a regulator asks for if the requester complains.

    05

    Respond and archive

    The response is generated from templates in the requester's language, delivered securely, and the full case archived: what was received, when, who decided what and what was disclosed.

    Every right has its own workflow.

    An access request and an erasure request are not the same task. Each follows the steps and checks that right actually requires.

    Art. 15

    Access

    Collate the data with the required supplementary information: purposes, recipients, retention and the source it came from.

    Art. 17

    Erasure

    Check retention obligations that override deletion, execute across systems, and notify processors that received the data.

    Art. 20

    Portability

    Export the data the requester provided in a structured, machine-readable format, scoped to consent and contract processing.

    Art. 16

    Rectification

    Correct the record at source and propagate the change to every system and recipient that holds the old version.

    Art. 18

    Restriction

    Mark the data as restricted so it is retained but not processed, and log when restriction is lifted and why.

    Art. 21

    Objection

    Weigh compelling legitimate grounds against the objection, and stop direct marketing processing without a balancing test.

    Frequently asked questions

    On receipt by your organisation, not on the day the DPO learns about it. A request sent to any employee, in any wording, through any channel, starts the clock. That is the strongest argument for a single published intake route: everything else depends on an individual recognising a request and forwarding it in time.

    Never miss another deadline.

    See the intake form, the request queue and a full case walkthrough in 30 minutes.