Data subject requests

We just received our first DSAR. What now?

The clock starts when the request is received, not when it reaches the right person. Acknowledge, log, and start the search immediately, even if the position on scope is unresolved.

Start immediately

Acknowledge the request, log it, and begin the search now — even if the business has not yet decided who owns it or how the request is scoped. Delay at this stage is the most common reason deadlines are missed.

Then work out which regime applies based on where the individual sits, because the scope of what you owe them differs. A uniform approach to every request risks under-disclosing, which invites follow-up, or over-disclosing, which slows the response.

The deadline

Under GDPR and UK GDPR the deadline is one month from receipt, extendable by two months for complexity. Under US state laws the typical deadline is 45 days, with a 45-day extension available.

The clock starts when the request is received, not when it reaches the right person. Requests arriving through unofficial channels — a message to a leasing agent or a support inbox — are never recognized as requests at all, so the clock runs without anyone knowing.

Verifying identity

Verify identity proportionately before disclosing anything, using what you already hold rather than demanding new documentation. Identity verification that is skipped creates a disclosure risk; made too onerous it becomes an obstruction complaint.

Lastly, confirm that the applicable regulation permits the verification steps you intend to take, particularly any request for additional documentation.

What a response generally requires

The response and personal information disclosed must satisfy the applicable regulation. Two failures recur. Companies reuse a standardized response without confirming it meets the regulation's requirements, or they search only the obvious systems, missing third-party processors and less-searched holders such as marketing, HR, and customer support.

Common Mistakes

  • Not recognising the request because it arrived by email to a support inbox or a member of staff.
  • Searching only the obvious systems and missing backups, archives, and anything held by processors.
  • Disclosing third-party personal data without redaction.
  • Letting the deadline run while the business decides who owns the request.
  • Applying exemptions inconsistently across requests.

Common questions

Does it matter how the request arrived — email, social media, a phone call?

Yes. The channel does not determine whether a request is valid. Requests arriving through unofficial channels, such as a message to a leasing agent or a support inbox, are never recognized as requests at all, so the clock runs without anyone knowing. If it is a request, it is a request regardless of where it landed.

Can we ask for ID documents before we respond?

Verify identity proportionately using what you already hold rather than demanding new documentation. Verification that is made so onerous it becomes an obstruction complaint is a compliance failure in its own right.

Why do incomplete responses happen even when companies try to get it right?

Companies do not know every system holding the data, so responses are incomplete and a second request exposes the gap. The search needs to cover not just obvious systems but backups, archives, and anything held by processors.

How Applied Privacy Consulting Supports DSAR Operations

  • Compliance Library

    A maintained reference of DSAR rights, response deadlines, verification standards, and exemptions across the regimes that apply to you, so your team is not re-researching the same question each quarter.

  • Jurisdictional SOPs

    Written procedures for handling requests under GDPR and UK GDPR, US state laws, and any GCC or other regimes in your footprint, including where requirements diverge on timing, appeals, and authorized agents.

  • Intake And Verification Design

    Request channels, identity verification standards proportionate to the sensitivity of the data, and criteria for when a request is complete enough to start the clock.

  • Handler Checklist

    A step-by-step working document covering scoping, search, review, redaction, response, and closure, so requests are handled consistently regardless of who picks them up.

  • Data Discovery Scoping

    Mapping where personal data actually sits, including third-party processors, vendors, and less-searched holders such as marketing, HR, and customer support, so searches are complete rather than convenient.

  • Exemption Assessment

    Analysis of which exemptions apply to a given request, whether that is legal privilege, ongoing litigation, trade secrets, or third-party rights, with the reasoning documented to withstand regulator scrutiny.

  • Third-Party Redaction

    Review of responsive material and redaction of other individuals' personal data, with a defensible and repeatable standard applied across requests.

  • Response Quality Review

    Assessment of draft responses against the specific regulation invoked, rather than a standardized template applied to every request.

  • Team Training

    Onsite or remote training for privacy, legal, IT, and frontline teams on recognizing requests, escalation, and handling their portion of the process.

  • Automation Project Management

    Requirements definition, vendor evaluation, and implementation oversight where you want DSAR handling moved into a platform, with the process defined before it is automated.

  • Volume And Readiness Assessment

    Review of current request volume, response times, and near-miss deadlines to identify where the process breaks under load.

Explore

Need to move quickly on a live request?

Book a call

Regulatory and compliance advisory is available at $275/hr or $2,000/day for defined-scope work. Book a call and we can scope what the situation requires.

Write to us

Prefer email? Start here.

A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.