UK organisations must offer an easy way to exercise access, erasure, and related rights. Use an HTML request form that starts the clock as a ticket, then verify identity through a process that does not involve uploading passports to a marketing backend.
Not the marketing newsletter list.
Access, erasure, rectification, objection, US delete, US opt-out of sale/share.
Tell people you will follow up by email, not that they must upload a passport here.
The form is the ticket. Exports of ‘all data’ still come from your databases.
Under UK GDPR, a data subject can request access to their personal data (a SAR/DSAR), correction, erasure, restriction, objection, and portability in defined cases. The ICO expects you not to put up unnecessary hurdles. You may reasonably verify identity, but demanding NI numbers or passport scans on a public HTML form is a disproportionate hurdle and a new breach risk. You typically have one month, with limited extensions for complex cases.
US visitors may be exercising CCPA/CPRA, VCDPA, or other state rights (access, delete, opt-out of sale/share). Those statutes are not GDPR. Use this form as a single intake labelled for both, then route UK DSARs to the DPO and US requests to your privacy ops playbook. HIPAA medical-record requests in the US are a different regime—use the HIPAA release generator for authorizations to send PHI to third parties.
You need to know who they claim to be and what they want. You do not need a colour scan of their driving licence in your form dashboard.
Never require Social Security, National Insurance, or passport/driving-licence scans on this public form. If you must verify, use a staged process: email challenge, account login, or a secure portal with staff review.
ICO and state AGs still see email to a buried address. A visible form is both UX and evidence you did not hide the door.
A form on /privacy-requests.
DataGrail-class tools help at volume; they still need a public entry point.
Valid under UK GDPR. A form reduces missing subject lines.
Best for simple consumer apps; this form covers people without a login.
Your privacy notice and this form should live on the same static origin. Say which legal entity is the controller.
Log the submission time. That timestamp matters for the one-month UK GDPR clock and for US statutory windows.
It helps. You still need a working inbox, a process, and no punishment of the requester.
You may reasonably verify, but a blanket passport-on-HTML-form policy is hard to justify and dangerous.
No. US PHI disclosures to third parties often need an authorization. Patient access to their own designated record set follows HIPAA access rules, not this DSAR copy.
One intake is fine if your privacy notice explains both and your team routes correctly. Do not tell Californians they must use UK wording.
Typed acknowledgement of activity risks for gyms, events, and classes—not a magic shield against negligence.
Post-activity or settlement-style release language captured as a web acknowledgement.
Permission to use a person’s image in marketing, with named event and typed signature.