Step 1 of 3 · Data Subject Requests

Deploy your DSR form.

Your public-facing intake. Start here.

Open ai.trustsuperset.com/dsars/form.

You're looking at a live preview of the consumer-facing DSR form. Your customers click a link, fill out this form, and submit a verified request. Submissions get classified and routed into your queue in DSR Manager, with identity verification built into the form itself. The form is also where Superset learns what data you need to find a data subject in your records, which the privacy inbox builds on in Step 2.

The DSR Form Preview builder: fields with per-field requirement dropdowns, Add Field, Submit Request, and the Share Portal Link button.
The form builder. Set each field's requirement from the dropdown on its right, drag to reorder, add fields, and grab the public link with Share Portal Link.

Why a webform submission counts as verified

The form has two layers of protection against junk submissions: Cloudflare Turnstile keeps bots out, and every submission triggers an email verification link the data subject has to click to confirm they intended to file. That's what makes a webform submission a verified request, and it's why you can trust these on their face. The full requester experience is at the end of this page.

The fields on the form

Every field the form can collect comes from a fixed menu: name fields (First Name, Middle Name, Last Name), contact fields (Email Address, Business Email, Phone Number), address fields (Address 1, Address 2, City, State, State/Region, Zip Code, Country), other identifiers your data may key on (Date Of Birth, LinkedIn Address, MAID), and Individual or Authorized Agent to capture who's filing. Whatever isn't already on your form is available under Add Field at the bottom.

Customize it before you share the link

Each field has a requirement dropdown on its right with three settings: Optional, Required, or part of an either/or group (next section). Drag a field by the handle on its left to reorder.

  1. Trim the fields you don't need. Every required field is a friction point for legitimate consumers and a verification hook against bad-faith requests. Keep what you need to identify a data subject in your records, mark it Required, and drop the rest.
  2. Only require what's truly required. Anything useful-but-not-essential stays Optional, so a consumer who has it can give it to you without blocking the one who doesn't.

You can also edit the form title and subtitle at the top so the page reads in your brand's voice.

Require one of several fields with either/or groups

Sometimes any one of several identifiers is enough to find someone in your records, and you don't want to demand all of them. That's what either/or groups are for: open a field's requirement dropdown, pick New either/or group, and add the alternative field to the same group. Requesters have to fill in at least one field from the group to submit.

A field's requirement dropdown open, showing Optional, Required, and New either/or group.
The requirement dropdown on every field: Optional, Required, or a new either/or group.

Groups compose with your required fields, so you can express a rule like name, plus a phone number or a business email: mark First Name and Last Name as Required, then put Phone Number and Business Email in one either/or group. On the public form the group renders as a single box with an OR divider and a line telling requesters to provide at least one.

The form builder with Phone Number and Business Email in Group A, separated by an OR divider, under a banner reading requesters must provide at least one of: Phone Number or Business Email.
An either/or group in the builder: Phone Number or Business Email, at least one required.
Applies to email requests too Your field requirements, either/or groups included, define what a complete request looks like everywhere, not just on the webform. A request that arrives through your Privacy Inbox is checked against the same requirements, and one that's missing what you require sits at Needs Info until the gap is filled (that's what the inbox Auto-Reply chases).

Supported request types

The Request Type dropdown gives data subjects eight options, mapped to the rights in CCPA/CPRA, GDPR, and the broader U.S. state landscape:

Right to Erasure Rectification Correction Restrict Processing Data Portability Not Subject to ADM Opt-out of Sales Limit Sensitive PI

When the form looks right, click Share Portal Link at the top of the page to get the URL. Drop that link into your site's privacy page, the footer of your marketing emails, and anywhere else a consumer might go looking for a privacy request.

The Share Portal Link popover showing the public URL to share with users.
Share Portal Link gives you the public URL to drop into your privacy page and email footers.

What the data subject sees

For reference, here's the full flow a consumer goes through after they open your portal link:

The public DSR form a requester fills out, with a Cloudflare Turnstile verification check.
1. They fill out the public form and clear the Cloudflare Turnstile check.
After submitting, the requester sees a Thank You screen saying a verification email has been sent.
2. They're told to check their email. The request isn't processed until they click the verification link.
After clicking the verification link, the requester sees a Request Verified Successfully screen with the request details.
3. Once they verify, the request is confirmed and flows into your queue.