The clock starts when the request is received, not when it reaches the right person. Acknowledge, log, and start the search immediately, even if the position on scope is unresolved.
Acknowledge the request, log it, and begin the search now — even if the business has not yet decided who owns it or how the request is scoped. Delay at this stage is the most common reason deadlines are missed.
Then work out which regime applies based on where the individual sits, because the scope of what you owe them differs. A uniform approach to every request risks under-disclosing, which invites follow-up, or over-disclosing, which slows the response.
Under GDPR and UK GDPR the deadline is one month from receipt, extendable by two months for complexity. Under US state laws the typical deadline is 45 days, with a 45-day extension available.
The clock starts when the request is received, not when it reaches the right person. Requests arriving through unofficial channels — a message to a leasing agent or a support inbox — are never recognized as requests at all, so the clock runs without anyone knowing.
Verify identity proportionately before disclosing anything, using what you already hold rather than demanding new documentation. Identity verification that is skipped creates a disclosure risk; made too onerous it becomes an obstruction complaint.
Lastly, confirm that the applicable regulation permits the verification steps you intend to take, particularly any request for additional documentation.
The response and personal information disclosed must satisfy the applicable regulation. Two failures recur. Companies reuse a standardized response without confirming it meets the regulation's requirements, or they search only the obvious systems, missing third-party processors and less-searched holders such as marketing, HR, and customer support.
Yes. The channel does not determine whether a request is valid. Requests arriving through unofficial channels, such as a message to a leasing agent or a support inbox, are never recognized as requests at all, so the clock runs without anyone knowing. If it is a request, it is a request regardless of where it landed.
Verify identity proportionately using what you already hold rather than demanding new documentation. Verification that is made so onerous it becomes an obstruction complaint is a compliance failure in its own right.
Companies do not know every system holding the data, so responses are incomplete and a second request exposes the gap. The search needs to cover not just obvious systems but backups, archives, and anything held by processors.
A maintained reference of DSAR rights, response deadlines, verification standards, and exemptions across the regimes that apply to you, so your team is not re-researching the same question each quarter.
Written procedures for handling requests under GDPR and UK GDPR, US state laws, and any GCC or other regimes in your footprint, including where requirements diverge on timing, appeals, and authorized agents.
Request channels, identity verification standards proportionate to the sensitivity of the data, and criteria for when a request is complete enough to start the clock.
A step-by-step working document covering scoping, search, review, redaction, response, and closure, so requests are handled consistently regardless of who picks them up.
Mapping where personal data actually sits, including third-party processors, vendors, and less-searched holders such as marketing, HR, and customer support, so searches are complete rather than convenient.
Analysis of which exemptions apply to a given request, whether that is legal privilege, ongoing litigation, trade secrets, or third-party rights, with the reasoning documented to withstand regulator scrutiny.
Review of responsive material and redaction of other individuals' personal data, with a defensible and repeatable standard applied across requests.
Assessment of draft responses against the specific regulation invoked, rather than a standardized template applied to every request.
Onsite or remote training for privacy, legal, IT, and frontline teams on recognizing requests, escalation, and handling their portion of the process.
Requirements definition, vendor evaluation, and implementation oversight where you want DSAR handling moved into a platform, with the process defined before it is automated.
Review of current request volume, response times, and near-miss deadlines to identify where the process breaks under load.
Regulatory and compliance advisory is available at $275/hr or $2,000/day for defined-scope work. Book a call and we can scope what the situation requires.
A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.
We use Google Analytics 4 to understand how this site is used and to measure our advertising. These set cookies on your device. Nothing loads until you choose. How we handle your data.