Products

DSAR automation

Give people a simple way to ask for their data to be deleted, and let DataCops carry it out. This is DSAR handling for the GDPR right to erasure (Article 17) and CCPA deletion requests, with far less manual work.

What it does

A visitor asks to have their data deleted, and DataCops erases it. The person enters their email on your privacy page, confirms with a link sent to that inbox, and DataCops removes their personal data from its own systems. They get a status page they can check. It covers the GDPR right to erasure (the right to be forgotten) and CCPA deletion.

Why it matters

Under GDPR Article 17, any person can ask you to delete the personal data you hold about them, and you generally have one month to do it. The hard part is the plumbing. The same person is a different identifier in every tool: an email in your store, a hashed value in an ad platform, a contact ID in your CRM. Finding all of them by hand is slow.

DataCops keeps one identity per visitor for each site, so finding everything it holds about a person is one lookup, not a hunt across many systems.

How DSAR automation works

  • Request. The person enters their email in the form you place on your privacy page.
  • Verify. DataCops emails them a confirmation link. Nothing is deleted until they click it, so no one can erase another person’s data by typing their email. The reply is the same whether or not DataCops holds data for that email.
  • Erase. On confirmation, DataCops blanks the person’s email, phone, and IP on their sessions, deletes their identity record, and deletes any held conversions that still carry their details. After 30 days a background job permanently purges what is left.
  • Confirm. The person is sent to a status page showing the request is complete. You can also send them a completion email from your dashboard.

What happens on your ad platforms

Once a person is erased from DataCops, nothing more is sent about them to any platform. For data already sent, DataCops helps where the platform allows it: from the dashboard you can trigger removal of the person from a Google Ads Customer Match list, and LinkedIn removal is being added. DataCops also accepts deletion requests that Meta, TikTok, and LinkedIn send to it. Data held in your own CRM or other tools stays your responsibility to delete, and DataCops flags it for you.

The audit trail

Every request is recorded: when it arrived, when it completed, and how many records were changed. That record survives the 30-day purge, so if a regulator asks you to prove a deletion, you have an answer. The public status page masks the email, so it never exposes personal data.

GDPR and CCPA deadlines

The GDPR right to erasure generally gives you one month to respond. The CCPA and most US state privacy laws give 45 days. The same DataCops flow handles both, and every request is timestamped.

Set it up

Drop one script tag on your privacy page and the request form renders inline:

<script src="https://cdn.joindatacops.com/dsar-embed.js" data-cop-key="YOUR_COP_KEY"></script>

People submit, confirm by email, and their deletion is handled and logged. You can see every request in your dashboard.

Frequently asked questions

What is a DSAR?

A data subject request (DSAR) is when a person asks a business to access or delete the personal data it holds about them, under laws such as the GDPR and CCPA. A deletion request is the right to erasure, also called the right to be forgotten.

How long do I have to respond to a deletion request?

Under the GDPR you generally have one month. Under the CCPA and most US state privacy laws the deadline is 45 days. In DataCops, personal data is blanked as soon as the person confirms, and the rest is permanently purged after 30 days.

Does it delete data from Meta and Google too?

DataCops erases the person from its own systems, so nothing more is sent about them. From your dashboard you can also trigger removal from a Google Ads Customer Match list. Other platforms, and your own CRM, may need a manual step, and DataCops flags them for you.

Is CCPA covered, or only GDPR?

Both. The same request flow handles the GDPR right to erasure (Article 17) and CCPA and US state deletion requests.

How is the requester’s identity verified?

The person confirms through a link sent to their own email before anything is deleted, so no one can erase another person’s data by typing their address.

Was this page helpful?