POPIAdesk

Guide

Managing data subject requests: a practical guide

DSRData Subject RightsGuide

Under POPIA, data subjects have the right to request access to, correction of, and deletion of their personal information. These are known as Data Subject Requests (DSRs), and your organisation must respond within 30 days.

Types of requests

  • Access Request: The data subject wants to know what personal information you hold about them.
  • Correction Request: The data subject wants to update or correct inaccurate information.
  • Deletion Request: The data subject wants their personal information removed from your systems.
  • Objection: The data subject objects to the processing of their personal information.

The 30-day deadline

Access requests follow PAIA's 30-day deadline, and correction or deletion requests must be answered within 30 days under the amended POPIA Regulations. In practice that means:

  • You need a system to track when requests are received
  • You need clear internal processes for handling each type of request
  • You need to document your responses for compliance evidence

Best practices

  1. Verify identity - Before disclosing any information, verify the requester's identity to prevent unauthorised access.
  2. Log everything - Maintain a complete record of all requests, actions taken, and responses sent.
  3. Set up alerts - Use deadline tracking to ensure no request goes unanswered past 30 days.
  4. Establish a public intake form - Make it easy for data subjects to submit requests through a branded online form.

Automating DSR management

POPIAdesk provides a complete DSR management system including a public intake form for your organisation, deadline tracking with automatic warnings, and response templates for each request type.

POPIAdesk is not open yet

The product generates the documents and tracks the deadlines this guide describes. Send us an email and we will reply once, on the day it opens.