---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Configure external-facing PDR form

# External-facing Personal Data Rights form configuration {#ariaid-title1}

* Release version: Australia
* 
* Updated May 24, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Privacy teams can tailor the external-facing Personal Data Rights (PDR) form per jurisdiction and data subject type. This customization allows them to control location specific content, authorized agent submission, and the available request types.

Privacy laws give data subjects, such as customers and ex-employees, specific rights over their personal
data that an organization collects. These can include right to access, correct, delete, or opt out of certain uses. The local laws determine which privacy rights data subjects can exercise, who is allowed to submit a request on their
behalf, what disclosures must appear when a request is submitted, and the information the organization can collect at intake to process the request.

Without a configurable layer, organizations either present the same set of rights to every requester regardless of their location. This can mislead requesters about what's actually available to them under local law, or maintain several
disconnected forms that are hard to keep current.

The external-facing PDR form gives data subjects a single public channel to submit requests. The
configurable form enables privacy teams to adapt that channel, its content, available request types, authorized agent option, and other settings, to the jurisdiction and data subject type the requester selects.  
Figure 1. External-facing PDR form configuration workflow
* **[Create a PDR external-facing form configuration record](https://www.servicenow.com/docs/h~oUhzhPpVGFdKbYLGwSlQ)**   
  Create the parent external form configuration record that anchors all location, data subject type, and request type rules for the external-facing Personal Data Rights (PDR) form.
* **[Configure jurisdictions for the external-facing Personal Data Rights form](https://www.servicenow.com/docs/381fsMBPc2GNBW8vwnDMMQ)**   
  Configure the jurisdictions, authorized agent option, and per-location URLs for the external-facing Personal Data Rights (PDR) form. These settings determine what requesters in each jurisdiction see based on their local privacy rules.
* **[Configure the data subject types for a jurisdiction](https://www.servicenow.com/docs/p1G7t9SfZh6guT_E21wiuQ)**   
  Specify which data subject types the external-facing Personal Data Rights (PDR) form offers in each location, so the form presents only the data subject types that local regulation supports.
* **[Map request types to data subjects for a jurisdiction](https://www.servicenow.com/docs/hH5mDZ06UkuiJ8gsV7arKQ)**   
  Configure the request types available to each data subject type within a jurisdiction. Hide any requester or agent fields that don't apply on the external-facing Personal Data Rights (PDR) form.

