Compliance & privacy
Submit a DSAR request
Overview
Data subject access requests (DSARs) require collecting identifiable records across ingestion, identity graph, warehouse exports, and vendor forwards. TrackLayer provides a request queue with evidence packs you can hand to legal.
Steps
- Open Privacy → Requests → New DSAR and supply subject identifiers (email hash, account id, cookie id).
- Attach jurisdiction and deadline; auto-assign owners from your privacy roster.
- Generate the data package—TrackLayer aggregates event history, traits, and destination receipts.
{
"request_type": "access",
"subject": {
"email_sha256": "abc...",
"workspace_user_id": "usr_4488"
},
"due_at": "2026-05-25T23:59:59Z"
}- Review redaction rules before export; share via secure link or attach to your GRC tool.
Troubleshooting
- Missing vendor data: some partners delete faster than TrackLayer—document gaps transparently in the response letter.
- Over-broad identifiers: tighten queries when hashes collide—require secondary factors.
- SLA risk: escalate early if warehouse scans exceed internal runbooks.