# Using Privacy Center

This guide is for staff who handle privacy requests and owners setting the policy. Every step uses the labels you see on screen. Follow your organisation's legal process alongside these steps.

## Using Privacy Center (editor how-to)

### How to handle a data request

1. Go to **Open privacy requests**.
2. Open the request and verify who is asking (mark it verified).
3. Export or erase their data as the request requires.
4. Mark the request **fulfilled** once done.

![An operator triages access, export, and deletion requests from a single compliance queue.](screenshots/privacy-requests-index.png)

### How to export or erase a customer's data

1. From the verified request, choose **Export** to produce their data, or erase to remove it.
2. Keep the evidence the system records.
3. Confirm the request status updates.

![An operator verifies and completes a data-subject request with audited actions.](screenshots/privacy-request-edit-actions.png)

### How to review retention rules

1. Open the **Retention rules** list.
2. Each rule shows what data it covers and how long that data is kept before it is minimised.
3. Review the rules so you know what is removed automatically and when.
4. Adjust a rule if a retention window no longer matches your policy.

![An operator reviews automated data minimisation rules and their retention windows.](screenshots/retention-rules-index.png)

### How to manage consent records

1. Open **Consent records**.
2. Review who granted consent, to which policy version, and when.
3. Use this if a customer or regulator asks for proof.

### How to manage cookie settings

1. Open the **Cookie policy** settings.
2. Set what visitors are asked to consent to.
3. Save. Visitors see the updated cookie preferences.

## Rolling out Privacy Center (for owners)

### Turn on first

- **Consent records and the cookie preference centre.** Capture consent correctly before you need to prove it.

### Add when needed

| Need                        | Enable                            |
| --------------------------- | --------------------------------- |
| Handle formal data requests | The **privacy requests** workflow |
| Show consent history        | **Consent records**               |

### Don't enable yet

- Don't action data requests without your verification and legal process agreed first. Privacy steps must follow policy.

### Who does what

| Role                    | First useful screen                        |
| ----------------------- | ------------------------------------------ |
| Privacy / support staff | **Open privacy requests**                  |
| Site owner              | **Consent policies** and **Cookie policy** |

## Troubleshooting for editors

| What you see                              | What it means                      | What to do                                                          |
| ----------------------------------------- | ---------------------------------- | ------------------------------------------------------------------- |
| A request can't be fulfilled              | It isn't verified yet              | Verify the requester before exporting or erasing                    |
| I can't prove a consent                   | The consent record wasn't captured | Check **Consent records**; ensure consent is recorded going forward |
| The cookie banner shows the wrong options | The cookie policy needs updating   | Update the **Cookie policy** settings                               |