Skip to content
Privacy Requests
Guides
Reviewing Requests

Managing privacy requests

The Request Manager is the Astralis Admin UI workspace where you review privacy requests after they are submitted: approve or deny them, extend their response deadlines, and track their progress to completion.

The data subject's location determines the regulation that applies and with it, the time limit for when a privacy request must be completed. This table describes the timeframes for common privacy regulations, and the extension each one allows:

RegulationTimeframeExtension
GDPR (EEA)28 days (one calendar month)Up to 60 further days
UK GDPR28 days (one calendar month)Up to 60 further days
US state regulations45 daysUp to 45 further days (90 total)
FDBR (Florida)45 daysUp to 15 further days
PIPEDA (Canada)30 daysUp to 30 further days
Law 25 (Quebec)30 daysNone available to a reviewer
LGPD (Brazil)15 daysNone available to a reviewer

Exceptions

There are some situations where you may not be able to, or required to, complete a privacy request. It's important to know when these might apply and how to manage them. In each case you should evaluate the circumstances and risks for your specific organization to ensure you're complying at all times.

Legal obligation

There are certain categories of personal data that you may be required to retain in order to fulfill legal or compliance obligations. In such cases, you're permitted to retain that data in the event when an erasure request is received- provided you restrict the use of the data to that purpose.

Confidentiality risk

In circumstances where returning data to a subject might reveal confidential or sensitive information about any organization or another individual, you're not required to return that specific piece of information.

Privacy request statuses

Each privacy request is assigned a status that reflects its current stage in the workflow:

StatusDescription
Identity UnverifiedRequest received from a user, but they have not completed the identity verification flow via email or SMS.
PendingRequest is ready for processing (verification complete or not required), but is awaiting approval or rejection in the Astralis Admin UI.
ApprovedRequest has been approved in Astralis (either automatically, or via the Admin UI) and will be enqueued for processing as soon as possible.
DeniedRequest has been denied in Astralis and the user has been notified. No further action required.
In ProcessingRequest was approved and has begun processing by executing all configured integrations.
Requires InputRequest began processing and is currently waiting for data to be manually input via the Astralis Admin UI.
PausedRequest began processing but was paused by a policy webhook and is waiting to be resumed via a webhook.
Awaiting Email SendRequest began processing and is currently waiting for the next scheduled batch email send (weekly).
Awaiting Access ReviewAccess request has finished collecting results and is being held for a human to review, redact, and approve the access package before delivery.
CompleteRequest has completed all configured integrations, uploaded results to storage, and notified the user.
Requires Manual FinalizationRequest has completed automated processing but requires manual finalization before it can be marked complete.
Pending ExternalRequest is awaiting action from an external system, such as a Jira ticket.
DuplicateRequest has been identified as a duplicate of another privacy request.
Awaiting Pre-ApprovalRequest is awaiting responses from external pre-approval webhooks before it can proceed. See Pre-Approval Webhooks.
Pre-Approval Not EligiblePre-approval webhook(s) responded that the request is not eligible for automatic approval; manual review is required.
CanceledRequest was canceled via the Data Right Protocol (DRP) API.
ErrorRequest began processing and encountered an error in one or more integrations.

Review privacy requests

When privacy requests are received, they're registered in Astralis as a New request available to view in the Request Manager. Each row shows the subject's identity, the request's status and type, the policy and source it came from, and the location it was submitted under — the location being what determines the response deadline and any extension allowance:

The Request Manager, listing privacy requests with their status, type, policy, source, location, and time remaining

Approve or deny a request

A request awaiting review can be approved or denied from two places: inline on its row in the Request Manager, or from the Actions menu on the request's details page.

On a row, the tick approves the request and the cross denies it. Both appear only while the request is in a status that can still be reviewed:

A request row in the Request Manager, with the approve and deny buttons and the more-actions menu at the right

On the details page the same two actions are named in the Actions menu, alongside Extend and the other per-request operations:

If access package review is enabled, completed access requests are held in the Awaiting Access Review status so a reviewer can inspect the results and redact fields before anything is delivered to the subject. See Access Packages.

Rejecting a request

After approval, the privacy request is processed using the configured Privacy Request Policy. When the request is complete, the data subject will be notified by email. If the request is an access request, the confirmation email will include a download link to retrieve a copy of their personal data.

When denying a request, you'll be prompted for a reason. That reason is stored in the Astralis audit trail for reporting purposes, and is shown to the subject in their notification email:

The privacy request denial dialog, asking for a reason that is included in the subject notification email

Extend a request

Sometimes a request needs more time than its standard response window allows. You can extend a request's response deadline by a set number of days, along with a required reason for the extension. The Extend action is available for any request that has a due date and hasn't reached a completed, denied, or canceled status. Consent requests, which have no due date, can't be extended.

To extend a request from the Request Manager, hover over the kebab menu ... for the request. If the request can also be deleted, the two actions are combined into a single More actions menu, with the extend option labeled Edit request deadline:

The More actions menu on a Request Manager row, with the Edit request deadline option

To extend a request from the request details page, open the Actions menu and select Extend:

The Actions menu on a request details page, with the Extend option

Either path opens the same dialog. Enter the number of days to extend the deadline by, and a reason for the extension:

Extend request deadline dialog for a California request, with the days field prefilled at 45 and a caption reading CCPA allows up to 45 days total, 45 remaining

Understand extension limits

Requests cannot be re-extended, and certain regulations, like Brazil's LGPD, do not permit extensions.

The reason you provide is required, and is included in the notification email sent to the data subject if the deadline extension notification setting is enabled for your environment.

You'll also see a warning — though you can still proceed — if the request is already past its original response deadline.

Once confirmed, the new due date takes effect immediately, and an Extended tag appears next to the request on its details page:

A request details page with the Extended tag shown next to the request status

Every extension is recorded in the request's audit trail.

View request details

To open a request, click it in the Request Manager. The details page shows:

  • Request ID: The unique ID for the privacy request.
  • Request type: The privacy request type, such as access or erasure.
  • Policy key: The privacy request policy being applied to the privacy request.
  • Status and time remaining: The current status, and how long is left to complete the request.
  • Source and location: Where the request came from, and the jurisdiction it was submitted under.
  • Subject email: The identity the request was made for.
  • Activity: A log of everything that has happened to the request, where you can also add a comment.

Filter and search requests

Requests can be filtered by status, request type, source, property, and location, or narrowed to a date range. The same bar searches by request ID or identity value, and sorts the result set:

The Request Manager filter bar, with search, date range, status, request type, source, property, location, and sort controls

Download reports

The toolbar above the list reports how many requests match the current filters, and offers bulk actions for the ones you select. To download a report of the currently filtered view, click the download button on the right:

The Request Manager toolbar, showing the result count, bulk actions, and the refresh and download buttons