Under Chapter III of the European Union General Data Protection Regulation (GDPR), website visitors and consumers have clear legal rights to control their personal data. These requests are commonly referred to as Data Subject Requests (DSR).
QookieQloud™ provides a fully integrated, automated workflow directly inside the consent banner, making it seamless for visitors to exercise their privacy rights and effortless for website owners to maintain compliance without manual overhead.
The Three Core GDPR Rights
Article 15: Right of Access (Data Export)
Visitors are entitled to obtain confirmation and an exported summary of all stored consent parameters, including timestamps, unique consent IDs, and granted cookie categories.
Read Article 15 (GDPR) ↗Article 16: Right to Rectification
Visitors have the right to obtain without undue delay the rectification of inaccurate or incomplete personal data held within your connected databases or CRM systems.
Read Article 16 (GDPR) ↗Article 17: Right to Erasure ("Right to be Forgotten")
Visitors can demand the permanent and irreversible erasure of their personal data and registered consent records across all processing channels.
Read Article 17 (GDPR) ↗How the DSR Workflow Operates in QookieQloud™
Visitor Submits Request via Banner
From the Privacy Rights tab in the active consent dialog, visitors select their desired request type (Erasure, Access, or Rectification) and enter their email address. An automated receipt is immediately emailed to the visitor.
Real-Time Alerts & Sidebar Warning Badges
You receive an instant notification email. In the QookieQloud admin dashboard, the Consents navigation item highlights a warning badge displaying the number of pending DSR requests for the active domain.
Contextual Resolution & Visitor Response
Under Domains > Consents, clicking Resolve DSR provides contextual handling tailored to the specific legal article:
- Access Requests (Art. 15): QookieQloud automatically embeds a structured data export table of the visitor's consent record directly into the completion email.
- Rectification Requests (Art. 16): You can verify connected customer data and include an optional custom confirmation note in the resolution modal.
- Erasure Requests (Art. 17): Once verified, clicking Complete permanently anonymizes the consent log and revokes active tracking states.
Strict Zero-Retention Architecture
The moment a request is resolved, the requester's email address and submitted notes are permanently purged from QookieQloud servers, leaving no lingering sensitive data.
Frequently Asked Questions about DSR & Privacy Rights
What does Zero-Retention mean for my website?
It means the requester's email address and submitted notes are permanently and irreversibly purged from QookieQloud servers the moment you click Complete. No lingering sensitive data is stored.
How does Article 15 Data Access / Export work?
QookieQloud automatically compiles a structured data export table detailing the visitor's consent telemetry (timestamps, ID, anonymized IP/country, and granted categories) and embeds it directly into the completion email.
How do I handle Rectification requests (Article 16)?
You update the visitor's records within your internal database or CRM, and you can provide an optional explanatory message in the resolution modal before closing the request.
What happens when an Erasure request (Article 17) is resolved?
Once you confirm deletion across your internal systems, the consent log in QookieQloud is permanently anonymized and active tracking consent is revoked.
View all questions in the FAQ Hub →
Official Regulatory References
For in-depth legal requirements and controller responsibilities, consult the official European Union documentation:
Explore your active domain settings and handle pending GDPR requests directly from the QookieQloud admin interface.