The Privacy Center is where data subjects actually exercise their rights: a guided request form that feeds straight into DSR Automation, plus self-service consent and communication preferences — without a single email to your support team.
Privacy Center request form and preference management

The embedded DSR request form

Visitors submit any enabled request type through a guided, multi-step form:
  • Request types — access, deletion, correction, portability, objection, and restriction. Enable only the types relevant to your applicable regulations, ordered and labeled per region: GDPR rights for European visitors, India DPDP rights for Indian visitors, CCPA rights for Californians.
  • Configurable fields — customize the intake fields per request type so you collect exactly what fulfillment needs, and nothing more.
  • Guided flow — the form explains each right in plain language and gathers the identity details needed for verification, reducing malformed and duplicate requests.
Every submission lands in the unified DSR queue with full context, and the regulatory deadline clock starts at submission.
1

Visitor submits a request

The form collects the request type, scope, and contact details, then sends a confirmation email with a unique tracking link.
2

Identity verification runs

The verification challenge configured for that request type is sent automatically — see below.
3

The request enters fulfillment

Verified requests flow into DSR fulfillment. The visitor can check live status — received, in review, processing, completed — from their tracking link at any time, without contacting support.

Identity verification

Every request is verified before it enters the processing queue, with proportional verification configured per request type:
Request sensitivityExampleTypical verification
LowMarketing opt-outEmail confirmation link
MediumAccess requestEmail OTP
HighFull deletionEmail + SMS OTP or knowledge-based checks
Very highSensitive-category dataID document check
Rate limiting and fraud detection run in the background to block automated or mass-submission attacks, and unverified requests expire automatically after a configurable window with the attempt logged.
Fulfilling a request for the wrong person is itself a data breach. Keep verification requirements proportional to what the request exposes — never lower them for speed.
The Privacy Center gives visitors transparent, instant control over what you hold and send:

Consent transparency

Authenticated users see exactly which consents your organization holds for them and when each was given — pulled live from your consent records.

Instant withdrawal

Preferences can be updated or consent withdrawn immediately from the portal; every change is recorded as a consent event with a full audit trail.

Communication preferences

Visitors choose channels and topics — marketing email, SMS, product updates — and changes propagate to your connected marketing stack via integrations.

Cookie preferences

A link reopens the cookie preference center, keeping web consent and portal preferences consistent.

Authenticated access

Enable authenticated access so users can log in with a magic link sent to their email address. Authenticated users get:
  • Their consent history and the live preference center
  • Their submitted request history with statuses
  • All of it scoped strictly to their verified identity
Anonymous visitors can still submit requests — authentication is optional and adds convenience, while identity verification remains mandatory for every request regardless.
Link the Privacy Center from every marketing email’s footer alongside the unsubscribe link. Visitors who can adjust preferences granularly opt down instead of opting out entirely.