Boost Efficiency and Collaboration with Osano’s Integrated Assessment Tools
Imagine this: You’re knee-deep in a privacy impact assessment, trying...
Read NowGet an overview of the simple, all-in-one data privacy platform
Manage consent for data privacy laws in 50+ countries
Streamline and automate the DSAR workflow
Efficiently manage assessment workflows using custom or pre-built templates
Streamline consent, utilize non-cookie data, and enhance customer trust
Automate and visualize data store discovery and classification
Ensure your customers’ data is in good hands
Key Features & Integrations
Discover how Osano supports CPRA compliance
Learn about the CCPA and how Osano can help
Achieve compliance with one of the world’s most comprehensive data privacy laws
Key resources on all things data privacy
Expert insights on all things privacy
Key resources to further your data privacy education
Meet some of the 5,000+ leaders using Osano to transform their privacy programs
A guide to data privacy in the U.S.
What's the latest from Osano?
Data privacy is complex but you're not alone
Join our weekly newsletter with over 35,000 subscribers
Global experts share insights and compelling personal stories about the critical importance of data privacy
Osano CEO, Arlo Gilbert, covers the history of data privacy and how companies can start a privacy program
Upcoming webinars and in-person events designed for privacy professionals
The Osano story
Become an Osanian and help us build the future of privacy!
We’re eager to hear from you
Updated: February 26, 2024
Published: March 1, 2023
Processing data subject access requests (DSARs) is a core part of every privacy program. From GDPR in Europe to the slew of new laws passed in the US and around the world, almost every privacy regulation includes provisions for the rights of the data subject (the person whose data is being collected and processed).
And yet, most businesses are still processing DSARs manually using email and spreadsheets. According to Gartner, manually processing a subject rights request costs an average of $1400 USD[1]. Today, we’re pleased to announce Osano’s new automated DSAR summaries and deletion so you can process DSARs in less time with more confidence.
This demo video shows an end-to-end flow of Osano’s subject rights management solution including Osano’s new capabilities to automate data summaries and data deletion.
When a data subject makes a DSAR to an Osano customer, there are several points of automation that would otherwise be a manual process without Osano:
Read on to learn more about how Osano automates these processes for you.
Osano provides DSAR forms out-of-box that are simple to add to your website with one line of code. Forms are the best way to capture subject rights requests as they ensure you have all the key information you need such as the requestor name, location (so you know which laws apply), and the type of request (summary of data, delete data, correction, etc.).
But what about requests made to your email address that isn’t processed through your form?
These emails can be time-consuming to process and often require multiple back-and-forth emails to obtain all the necessary info. Often, a group inbox needs to be set up and coordinating between internal stakeholders on who will answer which email is difficult.
With Osano's automated intake, you get a forwarding address with each DSAR form you create. Osano will then process any emails sent to your address by replying with a link to fill out the correct information in the DSAR form. This ensures every request is complete and you don’t waste time processing requests that don’t have the necessary info.
Once Osano receives a request, the first thing it does is send an email verification. This helps in 3 ways:
The next step in processing a DSAR is to gather a list of all of the data stores that could be holding personal information (PI) and all of the data store owners. These data store owners are the administrators who are able to search that data store and fulfill a subject right request.
With Osano, you only have to set up this information once, and then every DSAR that comes in gets processed according to the rules you pre-set. You can designate how each field in a data store should be processed when a DSAR comes in. For example, when a deletion request comes in, you may want to delete a user’s data from a CRM system, but you may want to only redact information in your financial system if local laws require you to keep the record for a period of time.
When each DSAR comes in, Osano automatically identifies all the data stores that apply to that request type, and for manual data stores, automatically assigns the data store owner a task to process the DSAR. (For automated data stores, Osano processes the request for you!)
Once you’ve identified which data stores and which data store owners need to be part of a DSAR, you need to communicate with all of them. In a manual system, this can lead to a tedious chain of emails.
With Osano, each data store owner is automatically notified via email that they have a DSAR to process. They can log into Osano to see all of the relevant information, such as the data subject’s details along with any notes about the data store fields.
Then, data store owners can even upload files that can be automatically packaged up when all the processing is complete.
Osano has a large and growing list of SaaS integrations that can perform automated summaries. In this case, when a data subject requests a summary of their data, Osano will automatically search the SaaS app for the user’s PI and output a CSV file with the summarized information.
Using automated data stores, processing DSARs goes from being a complex, multiple-step task to being as simple as clicking a button. With one click, the data requests manager can mark an identity verified, and with one click, they can package and send all files to the data subject using Osano’s secure messaging portal.
Automated deletion works the same way as Osano’s automated summaries. As long as the SaaS app supports deleting data via its API, then Osano will automatically delete the PI and provide a CSV file summarizing all the data that was deleted to send to the requester.
If you’d like, you can test an integration first by enabling automated summaries to see what info would be deleted. Then, when you feel comfortable doing so, you can enable automated deletion so your data store owners no longer need to manually delete the data. Instead, you can let Osano automate the process.
The final step in processing a subject rights request is to send the data to the user and inform them the request has been completed. In the case of a summary or deletion request, this includes packaging up all of the CSV files from associated data stores into a single zip file and sending it to the user. Osano automatically gathers all files that are either auto-generated by the platform or uploaded by data store owners and lists them together for the data request manager to review. There’s also an option to upload additional files if the manager wishes to do so. Then, with the click of a button, all of the files are packaged together into one zip file and sent to the original requestor via Osano’s secure messaging portal.
Osano subject rights management is included in Osano’s Premier pricing plan. If you are an Premier plan customer today, you already have access to subject rights management. Visit the geting started guide along with the automation docs to learn how to set up DSAR automation for your organization.
If you are not yet an Osano Premier plan customer, reach out to our sales team to start a conversation about how Osano can save you time while allowing you to comply with privacy laws in 50+ countries around the world.
Are you in the process of refreshing your current privacy policy or building a whole new one? Are you scratching your head over what to include? Use this interactive checklist to guide you.
Download Now
Osano Staff is pseudonym used by team members when authorship may not be relevant. Osanians are a diverse team of free thinkers who enjoy working as part of a distributed team with the common goal of working to make a more transparent internet.
Osano is used by the world's most innovative and forward-thinking companies to easily manage and monitor their privacy compliance.
With Osano, building, managing, and scaling your privacy program becomes simple. Schedule a demo or try a free 30-day trial today.