Security and trust

Built to keep sensitive requests private and under control

Requests can include personal data, evidence, response files, and delivery records. Privacy Requests helps you limit access, control delivery, and keep a clear history of what happened.

Security essentials

Security should be part of the workflow

The right people can see the right request, and every important action is recorded.

Limited access

Team members’ roles determine which requests they can access.

Controlled delivery

Share response files through expiring links, revocation, passcodes, and access logs instead of email attachments.

Clear history

Important actions are recorded so you can review what happened later.

Identity confirmation

Use verification links, email codes, and documented review steps before sensitive materials move.

Review before sending

Response preparation stays reviewable. Attachment checks flag potentially sensitive information for a person to review before approval.

Built-in safeguards

Controls you can verify in the workflow

These safeguards are available in the app today. They do not represent a security certification or guarantee legal compliance.

Session protection

Team members stay signed in for up to 12 hours. Sign-in links expire after 15 minutes and can be used only once.

Expiring links and passcodes

Delivery links default to 72 hours and can be configured from 1 to 720 hours. A delivery access session is limited to 30 minutes or the remaining link lifetime, whichever is shorter.

Revocation and failed attempts

Staff can revoke an active delivery link. A passcode-protected link is revoked after ten failed passcode attempts, and the event is recorded.

Audit records

The case history records when delivery links are created, opened, expire, or are revoked, and when files are downloaded. Records include who took the action and when, where that information is available.

Human approval

High-impact decisions stay visible

Verification, disclosure, deletion, correction, and final response decisions stay with your team, not hidden in the background.

  • Record verification outcomes and notes.
  • Keep review and delivery steps attached to the request.
  • Document exceptions when timing or handling changes.
  • Review access history and revoke links when needed.

Practical safeguards

Built around the security problems privacy teams actually face

Keep files out of email threads

Keep response files in one controlled place instead of sending them through email threads.

Make access reviewable

See who can access requests and how delivery links were used.

Support revocation

When a delivery link should no longer be available, revoke it and keep a record of that action.

Keep your team’s work private

People submit requests through a public portal while your team handles the response privately.

Private progress updates

Requesters can follow a private status link without seeing internal notes, assignments, or case materials.

Complete records before closure

Closure checks keep verification, fulfillment, approval, delivery evidence, and the final export visible before a case is finished.

Shared responsibility

Good controls need careful use

Before delivery, review the actual files and the intended recipient. An attachment check can flag content for review; it cannot decide whether disclosure is appropriate. Choose a link lifetime and passcode that fit the case, and share access details carefully.

Revoking a link prevents future access through that link. It cannot recall a file someone has already downloaded or copied. Plan retention and handling around that boundary.

Include these checks in your process

  • Invite only the people who need workspace access.
  • Review identity and authority beyond access to an email inbox.
  • Upload only information needed for the request.
  • Approve the final response and selected attachments.
  • Review link access and revoke access when appropriate.
  • Set a retention review process; cases are not automatically deleted.

Evaluating the service for your organization?

Review service facts and available materials for hosting information and the status of contractual and assurance documents. Product controls do not imply a certification, a guaranteed hosting region, or an approved data processing agreement.

Contact

Have a security question?

For questions about Privacy Requests security practices, contact support@privacyrequests.co.

Use this address to report a suspected security issue. Do not include requester records or identity documents in your message.