Skip to main content

Subject Rights CSV Import

Import requests into an existing Subject Rights form. You need permission to create requests.

How do I import requests from CSV?​

  1. Open Subject Rights > Forms and select a form.
  2. Open the three-dot menu beside the form name and select Import form submissions.
  3. In Bulk import DSAR requests, select Download CSV. Download a new template after saving form changes.
  4. Keep the header row and enter one request per row. Add Created Date, Due, and Completed Date columns as needed; see the rules below.
  5. Drop the .csv file into the upload area or click to browse. Files must be smaller than 1 MB.
  6. After validation, review the request count and select Import. Processing may take a few minutes.

Review imported requests under Subject Rights > Requests, including their created, regulatory due, and internal due dates.

Preserve created dates and due dates​

Set Created Date to the original receipt date for historical requests. If blank, it defaults to the import time.

  • Due blank: Deadlines are calculated from Created Date. The regulatory deadline uses the applicable privacy law for the request type and location; internal deadlines use the form's settings. No regulatory deadline is calculated without an active applicable law.
  • Due supplied: That date sets both Regulatory Due Date and Internal Due Date.

For example, a Created Date of 2026-01-01T00:00:00.000Z with an applicable 30-day response period and no Due value gives a regulatory deadline of January 31, regardless of the import date. Historical requests may already be overdue when imported.

CSV Import Column Headers​

The downloaded template contains required columns and supported form fields. Add missing date columns when needed. The sample CSV includes historical open, completed, and rejected requests; adapt it to your form.

Headers are case-insensitive and ignore surrounding spaces. Additional columns are allowed. Use one header per field, choosing either its standard name or a listed alternative. Optional columns can be omitted or left blank unless a condition below requires them.

Use ISO 8601 dates, such as 2026-01-01T00:00:00.000Z, for Created Date, Due, and Completed Date.

ColumnRequiredValue
EmailYesRequestor's email address.
Request TypeYesA request type supported by the selected form; see values below.
StatusYesOne of the statuses below.
Phone NumberNoPhone number, preferably with a country calling code, such as +12025550123. Alternative header: Phone #.
Given NameNoFirst name. Alternative header: First Name.
Family NameNoLast name. Alternative header: Last Name.
CountryNoISO 3166-1 alpha-2 code, such as US. Used to determine jurisdiction.
TerritoryNoSubdivision code without the country prefix, such as CA for California. Supply Country and use a territory valid for it.
Requestor TypeNoTypically EMPLOYEE, CUSTOMER, or OTHER.
Created DateWhen Due is in the pastCannot be in the future. Must be earlier than Due when both are supplied. Alternative header: Request Timestamp.
DueNoSets both regulatory and internal due dates.
Completed DateFor COMPLETED or REJECTEDCompletion or rejection date. Cannot precede Created Date when supplied. Leave blank for other statuses.
NotesNoUp to 500 characters.

Request Type values include DELETE, CORRECT, SUMMARIZE, OTHER, DO_NOT_SELL, OPT_OUT, LIMIT_USE, PORTABILITY, and OPT_OUT_OF_USING_SENSITIVE_DATA.

Status values: PENDING_IDENTITY_VERIFICATION, IN_PROGRESS, IN_REVIEW, PENDING_APPEAL, REJECTED, COMPLETED.

Frequently Asked Questions​

Are there any limits on the number of requests that can be imported?​

There is no separate row limit. Split files of 1 MB or larger into smaller files, each with a header row.

How do I enter a single request manually?​

Under Subject Rights > Requests, select the add button to open Submit a Single Request. Select a form and jurisdiction, then complete the request details.

Created Date is required and defaults to today. Set it to the original receipt date for historical requests; calculated deadlines use that date. Completed requests require Completed Date; rejected requests require Rejected Date. Both must be on or after Created Date. Manual date pickers prohibit future dates.

Why was my CSV rejected?​

Check the required headers, field values, and date rules above. Use a .csv file smaller than 1 MB with at least one request row. Column names cannot start with =, @, +, -, or |.

Correct the file and upload it again. If headers are missing, download a fresh template from the form.