No data subject access request (DSAR) mechanism visible
A Data Subject Access Request (DSAR) is a formal request from a person asking what personal data you hold about them, or requesting it be corrected or deleted. This check looks for a visible way to submit such a request on your site. Privacy laws including GDPR and CCPA give people the legal right to make these requests, and require businesses to respond within a set timeframe. If there is no visible mechanism, regulators can treat that as non-compliance even if you would honour requests informally. Add a short contact form or a privacy@ email address to your privacy policy and/or contact page, labelled clearly as the way to submit a data request. A single sentence with an email address is enough to demonstrate you have a process.
Why this matters
Privacy laws including GDPR and CCPA give people the legal right to make these requests, and require businesses to respond within a set timeframe. If there is no visible mechanism, regulators can treat that as non-compliance even if you would honour requests informally.
How to fix it
Add a short contact form or a privacy@ email address to your privacy policy and/or contact page, labelled clearly as the way to submit a data request. A single sentence with an email address is enough to demonstrate you have a process.