Governance & Compliance · Software component
Data Subject Request Handler
Software componentGovernance & ComplianceSafety, Security & Governancearc:DataSubjectRequestHandler
A governance workflow component that receives access, rectification, erasure, portability and objection requests, has the requester's identity verified, routes each to its fulfilment component and tracks the statutory deadline.
Responsibility. Coordinates fulfilment of data-subject rights requests end to end.
Also known as: DSR handler, Data subject rights fulfilment
Relationships
invokes dependency
is invoked by dependency
writes dependency
escalates to dynamic
routes to dynamic
Design guidance
- MUST verify that the requester owns the data before fulfilling any request.
- MUST complete requests without undue delay, within about one month.
- SHOULD classify request type (access, rectification, erasure, portability) and route it to the privacy team when needed.
Quantitative guidance
As stated by the sources; verify before use.
- Erasure executed within approximately one month of receipt (Ch9.7).
- Access and deletion requests completed within 30 days (Ref9.05).
- CCPA requests processed within 45 days (Ref9.05).
Classification
- Quality attributes
- Transparency and accountability (NIST AI RMF: accountable and transparent)Performance efficiency (ISO/IEC 25010)
- Risks mitigated
- Missed statutory response deadlines
- Frameworks & regulations
- GDPR Art. 15GDPR Art. 16GDPR Art. 17GDPR Art. 20GDPR Art. 21CCPA
Sources
- Ch9.7: T. Nguyen, "GDPR and Data Protection Regulations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.7. ISBN: 9798244538229.
- Ref9.05: "Privacy and Data Protection for AI Systems," unpublished reference note (references/Chapter 9 - Safety, Ethics, and Compliance/05-Privacy-Data-Protection.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note