Use case

A privacy request process your small team can actually run

Move beyond forwarded emails and a spreadsheet. Give the person responsible for privacy a clear path from the first request to an approved response.

A familiar situation

Start with responsibility, not a bigger spreadsheet

A customer asks for a copy of their data. Your operations lead can find the support history, but engineering owns the account database and a second person needs to review the response. The hard part is keeping those handoffs together while ordinary work continues.

A lightweight process still needs an owner, a reviewer, and a record of what each person did. Privacy Requests brings intake, collection tasks, response preparation, and delivery into one case. You can see what is waiting on someone without rebuilding the story from email.

See the actual product screens →

From intake to outcome

A practical way to run the request

  1. Give customers one starting point

    Publish your hosted portal link in your privacy information and support replies. Use a fictional request to check the form before inviting customers to use it.

  2. Name an owner and arrange review

    An Admin or Privacy Manager can coordinate the case and approve their own response in self-review mode. If you want a separate approval step, invite a Legal Reviewer and add them in response approval settings.

  3. Ask for specific work

    List the systems that may hold relevant data and assign tasks to their owners. Explain what to search, what evidence to return, and what requires a separate decision.

  4. Review, deliver, and keep the record

    Select only the files intended for the requester, obtain packet approval, and create an expiring delivery link. Complete the closure checks and export the case record.

Make each responsibility clear

Agree who owns each part before the request is urgent. These are suggested working responsibilities; workspace roles determine access.

Suggested responsibilities for this workflow
PersonResponsibilityUseful result
Operations leadRequest scope, follow-up, task assignments, and deliveryA case with a visible owner and next steps
Engineering or data ownerSearch the systems they manage and record findingsTask evidence that the response owner can review
Legal ReviewerReview the proposed response and selected attachmentsRecorded packet approval before delivery

A process that survives the next handoff

The useful result is more than a sent email: a request with an owner, documented verification, collection evidence, an approved response, and delivery history. When someone is away, another authorized teammate can pick up the record. As your team grows, task templates and clearer system ownership help you repeat the same process.

Workspace members showing separate administrator and Legal Reviewer roles
Product example with fictional data.

Before your first request

Set up the people and the process

Rehearse the whole workflow with controlled addresses and fictional data. A working intake form is only the first step.

Rehearse your first access request →

What your team still owns

This is a workflow tool, not an automatic search across your customer databases. Your team still retrieves records, decides what may be disclosed, and performs any approved deletion in the relevant systems. If you are a solo operator, plan how you will provide the required Legal Reviewer approval before adopting the full delivery workflow.

Read the security safeguards and current plan availability before deciding whether the workflow fits your organization.

Try a real workflow

Give your next request a clear path

Start with a workspace, a responsible owner, and a reviewer.

Compare workflows for other teams →
Start free