DPO Radio

Measure Value, Not Just Traffic Explore new features in AesirX Analytics

AesirX Rights Requests

Overview Image

Why Rights Requests Matters

Organizations subject to Vietnam's Personal Data Protection Law (PDPL) must respond to data subject access requests, correction requests, deletion requests, and portability requests within strict statutory timeframes. Missing a deadline is not just a process failure, it is a regulatory violation with documented consequences.

Enterprise DPOs coordinating multi-department responses face a specific challenge: a single rights request may require data from HR, finance, marketing, IT, and customer service. Without a structured system, the DPO sends emails, tracks responses in spreadsheets, and manually assembles evidence. Department Data Owners receiving these requests often lack clarity on what data is in scope or when their contribution is due.

When fulfillment depends on email threads and shared drives, deadlines slip without warning. Evidence is incomplete. Response letters are inconsistent. Extension requests lack formal documentation. Audit trails are fragmented across inboxes and chat logs, making it difficult to demonstrate compliance during a regulatory inspection..

Rights Requests provides a single workflow from public intake through multi-department fulfillment to final response delivery. The Enterprise DPO (P-VN-01) manages the case lifecycle, assigns per-department tasks with individual sign-off gates, and tracks statutory deadlines with automatic countdowns. Department Data Owners (P-VN-02) receive clear assignments linked directly to the Data Mapping system, so they know exactly which data stores and records are in scope. The DSR Intake and Fulfillment workflow (UC-VN-12) runs end-to-end within the module.

How It Works

Public Intake Form

A multilingual web form allows data subjects to submit requests without authentication. Requests are captured with structured metadata – requester identity, request type, and supporting documentation – and automatically routed into the case management queue.

Public Intake Form

Case Management

Every rights request becomes a tracked case with status, assignments, and SLA monitoring. Cases move through the full ticket lifecycle with visibility into who is responsible, what is pending, and which deadlines are approaching.

Case Management

7-Stage Workflow Engine

Requests progress through seven defined stages: New, In Review, Waiting on Requester, Waiting on Internal Data, Approved, Closed, and Rejected. Each transition is logged with timestamps and responsible parties, creating an immutable record of the fulfillment process.

7-Stage Workflow Engine

Multi-Department Fulfillment

The DPO assigns per-department tasks with individual sign-off gates. Each department confirms its data contribution independently before the response can be finalized. This ensures no department is overlooked and every team's data is accounted for in the final response.

Multi-Department Fulfillment

Evidence Collection

Checklist-based evidence gathering with document attachments ensures that every step of the fulfillment process is documented. Evidence packs can be exported as ZIP archives for regulator submission.

Evidence Collection

Response Templates

Pre-built templates for common response scenarios in Vietnamese and English use variable interpolation to auto-populate requester details, request type, and outcome. Multi-channel delivery tracking covers email, portal, and postal responses.

Response Templates

Statutory Period Extension Workflow

When a request cannot be fulfilled within the standard timeframe, a formal extension request process routes through DPO approval, recalculates the deadline, and notifies the requester, all documented in the audit trail.

Statutory Period Extension Workflow

Data Store Linkage

Fulfillment tasks link directly to the Data Mapping system. Data store owners see exactly which records are in scope for a given request, eliminating guesswork about what data needs to be retrieved, corrected, or deleted.

Data Store Linkage

Compare the Difference

Graphic Image

Without Rights Requests

Graphic Image

With Rights Requests

IconDPOs track requests in spreadsheets with no automatic deadline alerts, risking statutory violations.
IconEvery request follows a 7-stage workflow with statutory countdown timers visible to all stakeholders.
IconDepartment contributions arrive by email with no confirmation of completeness or sign-off.
IconPer-department tasks have individual sign-off gates ensuring every team confirms its data before response.
IconResponse letters are drafted manually with inconsistent formatting and missing details.
IconTemplate-driven response generation with variable interpolation produces consistent, complete letters.
IconExtension requests are handled informally with no documented approval or deadline recalculation.
IconFormal extension workflow routes through DPO approval with automatic deadline recalculation and requester notification.
IconAudit evidence is scattered across email threads, shared drives, and chat logs.
IconAll evidence is collected in structured packs exportable as PDF reports and ZIP archives for regulators.

Built for Real Compliance Operations

Build For Image

Every rights request case maintains a complete audit trail from intake through final response, with contributor lineage showing exactly which department provided which data and when they signed off.

Build For Image

Multi-department fulfillment tasks link directly to the Data Mapping module's system inventory, so data store owners work from the same source of truth rather than interpreting ad-hoc email instructions.

Build For Image

The statutory period extension workflow enforces a formal approval chain with automatic deadline recalculation – preventing informal extensions that lack documentation during regulatory inspections.

Regulatory Framework Support

Framework

How Rights Requests Supports It

Vietnam Personal Data Protection Law (VN_PDPL_LAW_2025)
IconManages the full DSR fulfillment lifecycle with statutory deadline tracking and evidence packs for PDPL compliance demonstration.
Decree 356 — PDPL Implementation (VN_PDPL_DECREE_356_2025)
IconSupports the procedural requirements of Decree 356 including response timeframes, extension documentation, and multi-department coordination for data subject rights.
Background Image

See Rights Requests in Action

Ready to see how Rights Requests works with your compliance workflows? Request a personalized demo.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

People Also Ask

The DPO assigns per-department fulfillment tasks, each with its own deadline and sign-off gate. A department must confirm its data contribution before the overall response can be finalized. The case dashboard shows which departments have completed their tasks and which are still pending.

Yes. The public intake form is a multilingual web form that does not require authentication. Data subjects submit their request with supporting documentation, and it enters the case management queue for identity verification and triage.

The module includes a formal statutory period extension workflow. The case handler initiates an extension request, which routes through DPO approval. Once approved, the deadline is automatically recalculated and the requester is notified, all logged in the audit trail.

Fulfillment tasks link directly to the Data Mapping module's system inventory. When a department receives a task, the linked data stores show exactly which systems and records are in scope, reducing the time spent identifying relevant data.

The module generates PDF reports for individual cases and ZIP evidence packs containing all case documentation, correspondence, department sign-offs, and attachments, ready for regulator submission or inspection response.

Next Steps

Explore the module architecture, then speak with us about the workflows your organization needs to operationalize first.

Icon Image

Start a Compliance Pilot

Test Rights Requests with real DSR cases and see multi-department fulfillment in your environment.

Icon Image

Discuss Your Compliance Needs

Talk through your DSR volume, department structure, and regulatory obligations with our team.