DSAR / Subject-Access-Req
Log, track and fulfil UK GDPR Subject Access Requests within the 1-month deadline
Handling Subject Access Requests in email threads and spreadsheets is how compliance teams blow the statutory deadline. This module gives you a complete DSAR workflow: log a request, verify identity, locate where personal data is held (a helper auto-matches the subject's contact / res.partner records; you record data held in other apps and systems in the same register manually), redact third-party data and respond — all against a computed UK GDPR one-month due date with overdue and at-risk flagging. It complements a GDPR privacy app by adding the operational rights-request engine.
Key Features
Full DSAR lifecycle
New → Identity Check → Locating Data → In Review → Responded / Refused, with mail-thread tracking and scheduled activities at every step.
All rights, not just access
Access, rectification, erasure, restriction, portability and objection requests — each handled with the right UK GDPR deadline logic.
Deadline engine
A computed statutory due date from the one-month default, with the permitted two-month (60-day) extension capped and validated, plus on-track / at-risk / overdue SLA states.
Data location register
Record every place personal data was found — model, record reference, category and lawful basis — with a found / redacted / included / excluded state and special-category and third-party flags.
Subject matching
A helper scans contacts by email and name to surface likely matching records and auto-creates location lines for the subject's own res.partner data.
Disclosure pack & portability
Build a structured access pack with per-category counts and a pre-filled response summary, plus a machine-readable JSON-able payload for portability requests.
UK GDPR deadlines built in
The one-month rule and the two-month complex-request extension are encoded, so due dates are right by default.
Daily overdue scan
A cron flags overdue and at-risk requests and notifies owners, so nothing slips through the cracks.
Audit-ready
Refusal reasons, redaction logs and a full status history give the ICO-defensible trail regulators expect.
Pure Community
No Enterprise dependency — it complements any GDPR privacy compliance app with the operational DSAR workflow.
Screenshots
Locate Subject Data
Data Locations
Dsar Requests
Why Choose This Module
Data protection officers, compliance teams and privacy leads at UK organisations who must respond to Subject Access Requests and other data-subject rights requests accurately and on time under UK GDPR and the Data Protection Act 2018.
Specifications
- Compatible: Odoo 18.0 / 19.0
- License: OPL-1
- Languages: English
- Author: Pokutsoft
- Dependencies: mail
- Support: support@pokutsoft.com
Update date: 2026-07-02