DSAR Handling

Privacy rights requests handled to deadline, at volume

The obligation is the same in every jurisdiction: verify the requester, locate the data, apply the correct exemptions and redactions, and respond within the statutory deadline. I design and operate that process end to end.

What DSAR handling is and who needs it

DSAR handling is the operational process for responding to individuals exercising their privacy rights — whether that is access, deletion, correction, portability, or opting out of sale and sharing. The rights differ by jurisdiction, but the obligation is the same in every case: verify the requester, locate the data across the business, apply the correct exemptions and redactions, and respond within a statutory deadline.

Any company subject to GDPR, UK GDPR, or the US state privacy laws needs a working process. Consumer-facing organizations holding large volumes of personal data need it to run at volume rather than as a one-off exercise.

When organizations seek this out

Usually a request has arrived that the company cannot answer within the deadline, or volume has grown past what an ad hoc process can absorb.

Common triggers include a complaint or regulatory enquiry following a missed or incomplete response, requests being used as leverage in employment disputes or litigation, an audit finding that the process is undocumented, or a new state law taking effect and expanding the population of people entitled to make requests.

How the engagement runs

  1. 01

    Assess the current position

    Review request volume, the jurisdictions and rights in scope, existing intake routes, and how requests have been handled to date.

  2. 02

    Interview stakeholders

    Speak with the people who hold or touch personal data — typically legal, infosec, IT, HR, marketing, customer operations, and any third parties processing on the company's behalf.

  3. 03

    Map systems and repositories

    Identify every system and repository that must be searched to fulfil a request, and confirm what can be extracted, corrected, and deleted from each.

  4. 04

    Design the end-to-end workflow

    Cover intake and identity verification, triage against the applicable regime, response templates, exemption and redaction criteria, deadline tracking, escalation routes, and record keeping.

  5. 05

    Review, finalise, and train

    Circulate for stakeholder review, finalise the workflow, and train the people who will operate it.

  6. 06

    Hand over or run ongoing

    Deliver the SOP with defined ownership. Where the client prefers that operational capacity sit outside the business, the process can be run on an ongoing basis.

Pricing

Process design and build
Fixed fee Four to eight weeks, depending on the number of systems and jurisdictions involved.
Ongoing request handling — retainer
From $4,500/mo Included within a fractional retainer at the appropriate tier.
Ongoing request handling — supervised delivery
From $1,500/mo Supervised delivery capacity for high-volume operational work. The more cost-efficient route where throughput is steady.

Where DSAR processes break down

Deadlines are the visible failure, but the cause is usually upstream. Companies do not know every system holding the data, so responses are incomplete and a second request exposes the gap.

Identity verification is either skipped, which creates a disclosure risk, or made so onerous it becomes an obstruction complaint. Exemptions are applied inconsistently, and third-party personal data goes unredacted.

Requests arriving through unofficial channels — a message to a leasing agent or a support inbox — are never recognized as requests at all, so the clock runs without anyone knowing. Companies also treat every request as a GDPR request regardless of where the individual sits, which is both slower and wrong.

What is included and what is not

Included

  • Assessment of current handling, volumes, and jurisdictional scope
  • System and repository mapping for search, extraction, correction, and deletion
  • End-to-end workflow design with intake, verification, triage, and escalation
  • Response templates and exemption and redaction criteria
  • Deadline tracking and record keeping standards
  • Third-party and processor coordination requirements
  • Training for the people operating the process
  • SOP with defined ownership

Not included

  • Technical integration or configuration of DSAR tooling
  • Ongoing request handling — available under retainer or through supervised delivery capacity
  • Legal representation, or advice on requests tied to active litigation, which sits with counsel

How this has worked in practice

A large multinational property management company with US and EU operations was receiving privacy rights requests across several jurisdictions with no consistent process behind them. I built the DSAR workflow end to end, covering intake and verification, triage against the applicable regime, search and redaction standards, and deadline tracking, and trained the teams responsible for operating it.

Requests moved from being handled ad hoc by whoever received them to a documented process with clear ownership and a defensible record of every response.

Common questions

How long does it take to stand up the process?

Four to eight weeks for a fixed-fee process design and build, depending on the number of systems and jurisdictions involved.

What if we need someone to handle requests on an ongoing basis, not just design the process?

Ongoing handling is priced separately — either within a fractional retainer or, where volume is steady, through supervised delivery capacity working under my supervision, which is the more cost-efficient route for high throughput.

What about requests that come in through informal channels?

Requests arriving through unofficial channels — a message to a leasing agent or a support inbox — are never recognized as requests at all, so the clock runs without anyone knowing. The workflow design covers intake routes precisely to close that gap.

Is advice on requests connected to active litigation included?

No. Legal representation and advice on requests tied to active litigation sits with counsel and is outside the scope of this engagement.

Our services

Request volume outpacing your current process?

Get in touch

Four to eight weeks to design and stand up a documented workflow with clear ownership. Scope the engagement on a call.

Write to us

Prefer email? Start here.

A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.