Rights Request Portal

Handle Rights Requests Without a Compliance Team

Self-serve portal. OTP-verified. 30-day SLA countdown enforced. Closure PDF auto-generated on resolution.

Your penalty exposure
₹50Crrights request SLA miss (S.11–14)

Without this: Rights requests arrive by email with no tracking, no SLA enforcement, and no closure proof. Each unresolved request beyond 30 days is a direct penalty trigger.

End-to-end in 5 steps, fully automated

1
User submits request
Your data principal visits the portal and submits an Access, Correction, Erasure, Nomination, or Grievance request.
2
OTP verification
A 6-digit OTP is sent to the user's email. Verified within 10 minutes. Prevents fraudulent requests.
3
DPO auto-notified
Your DPO inbox receives the request instantly with full context, identity proof, and 30-day SLA countdown.
4
Team responds
Use response templates or write custom replies. The SLA timer is always visible and escalates automatically.
5
Closure PDF generated
On resolution, a court-admissible closure PDF with full audit timeline is generated and stored in R2.

Everything to handle rights requests correctly

Core

5 Request Types

Access, Correction, Erasure, Nomination, and Grievance — all DPDPA-mandated right types covered.

OTP Identity Verification

6-digit OTP, 10-minute expiry, bcrypt-secured, 3 max attempts. Verifiable identity for every request.

Auto-Acknowledgement (<60s)

Confirmation email sent to the user within 60 seconds of submission. Legally, this matters.

30-Day SLA Countdown

Live countdown on every request. Red/amber/green status. Auto-escalation when approaching deadline.

Closure PDF with Audit Trail

Immutable PDF generated on resolution. Includes full timeline, identity proof, response content, and closure reason.

Embeddable or Standalone

Deploy as a standalone page at /rights/[your-slug] or embed as an iframe in your privacy policy page.

30-day
SLA enforced
<60s
Auto-acknowledgement
5
Request types
₹50Cr
Penalty coverage
Available from Starter plan onwards

Portal, SLA enforcement, OTP verification, and closure PDFs available on all plans.

DPDPA rights obligations — answered

What are the four Data Principal rights under DPDPA?+

DPDPA grants four core rights: Right of Access (S.11) — know what data is held and how it is used; Right to Correction/Erasure (S.12) — correct inaccurate data or request deletion; Right to Grievance Redressal (S.13) — escalate unresolved complaints; Right of Nomination (S.14) — nominate someone to exercise rights on death or incapacity. All five request types (including Grievance) are available in the DPDPA Shield portal.

What is the SLA for responding to rights requests under DPDPA?+

DPDPA requires Data Fiduciaries to respond within 30 days. DPDPA Shield enforces this with a live countdown on every request, amber alerts at Day 20 and Day 25, and a red critical alert at Day 28. If a response is not initiated by Day 29, the DPO is auto-notified by email. The SLA timer is always visible to your entire compliance team.

How does DPDPA Shield verify the identity of someone making a rights request?+

Each submission triggers a 6-digit OTP sent to the email address provided. The OTP expires in 10 minutes and allows 3 attempts. Only after successful OTP verification is the request accepted and forwarded to your DPO. This prevents fraudulent erasure requests and provides a verifiable identity trail for your audit records.

What is a closure PDF and why does it matter?+

A closure PDF is an auto-generated document created when a request is resolved. It includes the original submission, identity verification record, every status change, all communications sent, and the final closure reason — timestamped and stored immutably in Cloudflare R2. If challenged by a regulator, this document is your complete evidence of compliance.

Ready to handle rights requests the right way?

Your portal is live in under 15 minutes. Free trial, no credit card required.