The obligation is the same in every jurisdiction: verify the requester, locate the data, apply the correct exemptions and redactions, and respond within the statutory deadline. I design and operate that process end to end.
DSAR handling is the operational process for responding to individuals exercising their privacy rights — whether that is access, deletion, correction, portability, or opting out of sale and sharing. The rights differ by jurisdiction, but the obligation is the same in every case: verify the requester, locate the data across the business, apply the correct exemptions and redactions, and respond within a statutory deadline.
Any company subject to GDPR, UK GDPR, or the US state privacy laws needs a working process. Consumer-facing organizations holding large volumes of personal data need it to run at volume rather than as a one-off exercise.
Usually a request has arrived that the company cannot answer within the deadline, or volume has grown past what an ad hoc process can absorb.
Common triggers include a complaint or regulatory enquiry following a missed or incomplete response, requests being used as leverage in employment disputes or litigation, an audit finding that the process is undocumented, or a new state law taking effect and expanding the population of people entitled to make requests.
Review request volume, the jurisdictions and rights in scope, existing intake routes, and how requests have been handled to date.
Speak with the people who hold or touch personal data — typically legal, infosec, IT, HR, marketing, customer operations, and any third parties processing on the company's behalf.
Identify every system and repository that must be searched to fulfil a request, and confirm what can be extracted, corrected, and deleted from each.
Cover intake and identity verification, triage against the applicable regime, response templates, exemption and redaction criteria, deadline tracking, escalation routes, and record keeping.
Circulate for stakeholder review, finalise the workflow, and train the people who will operate it.
Deliver the SOP with defined ownership. Where the client prefers that operational capacity sit outside the business, the process can be run on an ongoing basis.
Deadlines are the visible failure, but the cause is usually upstream. Companies do not know every system holding the data, so responses are incomplete and a second request exposes the gap.
Identity verification is either skipped, which creates a disclosure risk, or made so onerous it becomes an obstruction complaint. Exemptions are applied inconsistently, and third-party personal data goes unredacted.
Requests arriving through unofficial channels — a message to a leasing agent or a support inbox — are never recognized as requests at all, so the clock runs without anyone knowing. Companies also treat every request as a GDPR request regardless of where the individual sits, which is both slower and wrong.
A large multinational property management company with US and EU operations was receiving privacy rights requests across several jurisdictions with no consistent process behind them. I built the DSAR workflow end to end, covering intake and verification, triage against the applicable regime, search and redaction standards, and deadline tracking, and trained the teams responsible for operating it.
Requests moved from being handled ad hoc by whoever received them to a documented process with clear ownership and a defensible record of every response.
Four to eight weeks for a fixed-fee process design and build, depending on the number of systems and jurisdictions involved.
Ongoing handling is priced separately — either within a fractional retainer or, where volume is steady, through supervised delivery capacity working under my supervision, which is the more cost-efficient route for high throughput.
Requests arriving through unofficial channels — a message to a leasing agent or a support inbox — are never recognized as requests at all, so the clock runs without anyone knowing. The workflow design covers intake routes precisely to close that gap.
No. Legal representation and advice on requests tied to active litigation sits with counsel and is outside the scope of this engagement.
Four to eight weeks to design and stand up a documented workflow with clear ownership. Scope the engagement on a call.
A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.
We use Google Analytics 4 to understand how this site is used and to measure our advertising. These set cookies on your device. Nothing loads until you choose. How we handle your data.