Key Takeaways
- DSARs give individuals the right to access their personal data and understand how an organisation is using it.
- Organisations generally have one calendar month to respond, although complex or numerous requests can qualify for an extension of up to two further months.
- A reliable DSAR process requires five core steps: logging and identity verification, scoping, data retrieval, review and redaction, and secure delivery.
- Manual fulfilment creates significant operational costs and increases the risk of human error, missed deadlines, and accidental disclosure of third-party data.
- Automation can centralise request management, improve data discovery and redaction, strengthen auditability, and help privacy teams handle growing volumes more efficiently.
Introduction
The volume and complexity of data subject access requests (DSARs) are increasing. We see many organisations facing requests used tactically in employee disputes or customer grievances, putting immense pressure on already stretched privacy and legal teams.
Fulfilling these requests is not just a legal obligation under Article 15 of the UK GDPR. It is a complex operational challenge that touches every part of the business, from human resources managing unstructured data to engineering teams querying production databases.
This is a practical guide for privacy leaders, data protection officers (DPOs), and the security and engineering teams tasked with building and managing the DSAR response process. It moves beyond basic definitions to provide an operational framework for handling requests efficiently and compliantly. This article is for general information and does not replace advice from a qualified privacy or legal professional.
We cover the core legal requirements, a step-by-step workflow for responding, how to handle complex exemptions and redactions, and how technology can transform the process from a manual burden into an automated function.
What is a data subject access request?
A data subject access request (DSAR) is a formal, legally enforceable demand from an individual asking an organisation to provide a complete copy of their personal data. Fulfilling this request requires the organisation to securely extract the data and transparently explain exactly how that information is being used.
Definition under UK GDPR and DPA 2018
A data subject access request is a legal right, granted under Article 15 of the UK GDPR, for an individual to request a copy of their personal data from an organisation. The core purpose is to empower individuals by ensuring transparency about how their information is processed.
Alongside the data itself, controllers must provide supplementary information. This includes the purposes of processing, the categories of personal data involved, the recipients who have received the data, and the planned retention periods.
Who can make a request?
The data subject themselves is the primary person who can submit a request. However, requests can also be made on behalf of others. A solicitor might act for a client, or a parent might request access to a child's record. When a third party submits a request, you must verify their identity and ensure they have the legal authority to access the individual's information.
Personal data in a DSAR context
Personal data goes far beyond simple identifiers like names and email addresses. The most difficult data to retrieve often lives in unstructured formats.
In a DSAR context, personal data includes:
- CCTV footage
- Direct messages in team collaboration tools like Slack or Microsoft Teams
- Performance review notes
- Internal email threads
- IP addresses linked to an individual's behaviour
Identifying and extracting this unstructured information is where manual processes typically fail.
5-step DSAR response workflow
The 5-step DSAR response workflow requires a systematic approach to acknowledge the request, define its scope, locate the personal data, redact sensitive information, and securely deliver the final response.
1. Acknowledge, log, and verify identity
Every request must be recorded in a central logging system. Even a simple tracker ensures visibility, but purpose-built privacy platforms provide better audit trails.
Once received, verify the requester's identity to protect against data breaches, but do not collect excessive new data to do so. Acknowledge receipt promptly and start the 30-day statutory clock.
2. Clarify and confirm scope
You cannot force a subject to narrow their request, but you can ask for clarification if they ask for 'all data' and you process a massive volume of records.
Asking, 'To help us locate the specific information you need quickly, could you clarify the date range or context of your request?' is a compliant way to manage broad submissions while demonstrating cooperative behaviour.
3. Search, retrieve, and collate data
The primary operational challenge is searching across multiple structured and unstructured systems, including customer relationship management (CRM) software, HR platforms, email archives, and cloud storage.
An up-to-date Record of Processing Activities (RoPA) or data map is vital here, as it directs your search efforts. Maintaining an accurate RoPA ensures you know exactly where a data subject's information resides.
4. Review, redact, and apply exemptions
Reviewing the extracted data is often the most time-consuming step. You must screen documents for third-party personal data, commercially sensitive information, and legally privileged content.
Redaction involves providing the subject's data while protecting the rights of others. For example, if an internal HR email discusses the requester's performance but also names a colleague, you must redact the colleague's name and any personal opinions about them before delivery.
5. Package and deliver securely
The UK GDPR requires controllers to provide the information in a concise, transparent, intelligible, and easily accessible form.
Security is critical during delivery. Use secure methods such as encrypted files or dedicated privacy portals. Avoid insecure methods like unencrypted email attachments, which create severe security risks.
Deadlines, extensions, and fees
The statutory deadline for fulfilling a DSAR is one calendar month, with limited exceptions allowing for a two-month extension or the charging of reasonable fees.
One-month statutory deadline
You must respond to a request without undue delay and at the latest within one month of receipt.
To calculate the deadline, look at the corresponding date in the following month. A request received on 5 March is due by 5 April. If the corresponding date falls on a weekend or public holiday, you have until the next working day.
Two-month deadline extensions
You can extend the response time by up to two further months if the request is particularly complex or if the individual has made numerous requests.
If you apply an extension, you must inform the individual within the initial one-month period, clearly explaining the reason for the delay.
Charging fees for DSARs
By default, DSARs must be fulfilled free of charge.
You can only charge a reasonable fee to cover administrative costs if a request is manifestly unfounded or excessive, or if an individual requests further copies of their data following a prior request.
Refusing requests and withholding data
You can refuse to comply with a DSAR or withhold specific data if the request is manifestly unfounded or excessive, or if a legal exemption applies under the Data Protection Act 2018.
Manifestly unfounded or excessive requests
According to ICO guidance, a request is manifestly unfounded if the individual clearly has no intention to exercise their right of access, or if the request is malicious and designed purely to cause disruption.
A request is excessive if it is repetitive or heavily overlaps with previous requests where a reasonable interval has not passed. For example, an individual submitting the exact same comprehensive data request every week is likely acting excessively.
Data Protection Act 2018 exemptions
The Data Protection Act 2018 provides specific exemptions that allow you to withhold certain information.
Legal professional privilege
What it covers: Confidential communications between lawyers and their clients.
When to apply it: Protecting legal advice related to a dispute with the data subject.
Management forecasting
What it covers: Information related to business planning that would prejudice the conduct of the business.
When to apply it: Redacting sections of a board report about a planned redundancy that mentions the employee.
Third-party data
What it covers: Data where disclosing it would breach the rights of another individual.
When to apply it: Redacting a colleague's personal opinions from a performance review about the data subject.
Contentious and weaponised DSARs
Across the privacy teams in our community, we often see DSARs used tactically as a tool for pre-action disclosure in employee grievances or complex customer disputes.
When facing a contentious request, remain objective and treat it as a standard compliance process. Document every step meticulously, keep all correspondence professional, and use clarification requests and legal exemptions fairly but firmly to protect the organisation's interests.
Manual vs automated DSAR fulfilment
Automated DSAR fulfilment centralises data discovery and redaction, drastically reducing the cost, human error, and compliance risks associated with manual spreadsheet-based workflows.
Workflow approach
Manual DSAR fulfilment
- Fragmented manual tasks relying on email inboxes for incoming requests and shared spreadsheets for logging.
Automated DSAR tech stack
- Streamlined digital workflow centralising request logging and response management in one unified platform.
Search and discovery
Manual DSAR fulfilment
- Manual searches conducted by IT teams across multiple structured and unstructured systems.
Automated DSAR tech stack
- Data discovery and mapping tools connect systems, enabling unified eDiscovery across all data sources.
Review and redaction
Manual DSAR fulfilment
- Privacy teams spend hours in PDF editors performing manual, line-by-line reviews to redact sensitive information.
Automated DSAR tech stack
- AI-assisted software automatically identifies personal data and suggests precise redactions, saving vast amounts of time.
Delivery and security
Manual DSAR fulfilment
- Often relies on less secure manual methods or disjointed file sharing, increasing the risk of data exposure.
Automated DSAR tech stack
- Dedicated secure portals provide a safe, fully auditable way to deliver the final response to the individual.
Scalability and risk
Manual DSAR fulfilment
- Highly prone to human error, impossible to audit effectively, and scales poorly as data volumes grow.
Automated DSAR tech stack
- Drastically reduces human error, provides clear audit trails, and scales efficiently alongside growing data volumes.
Real costs of manual fulfilment
Evaluating the cost of DSAR fulfilment requires looking beyond software licensing. The hidden costs of a manual process are substantial.
- Person-hours: Consider the time spent by privacy, legal, IT, and HR teams retrieving and reviewing data. If a request takes 40 hours to process, the salary costs alone are significant.
- Legal review: Complex redactions often require external counsel, which drives up costs quickly.
- Risk cost: Manual processes increase the risk of missing the statutory deadline or causing a data breach by delivering unredacted third-party data, both of which can lead to regulatory enforcement.
- Opportunity cost: Every hour a privacy leader spends manually compiling PDFs is an hour not spent on high-value strategic work, like conducting Data Protection Impact Assessments (DPIAs) or preparing for the AI Act.
Calculating the true cost of privacy operations helps highlight why automation is a necessary step for growing organisations. If your current platform takes months to configure and still needs spreadsheets to fill the gaps, we built TrustWorks for you.
Frequently asked questions
Frequently asked questions about DSARs cover the key differences between access requests and freedom of information requests, redaction rules, and the boundaries of disproportionate effort.
What is the difference between a DSAR and a Freedom of Information (FOI) request?
The difference between a DSAR and a Freedom of Information (FOI) request is that DSARs apply to any organisation holding your personal data.
FOI requests only apply to public authorities and concern broader information held by the public body, not just personal data, governed by the Freedom of Information Act 2000.
How do you properly redact third-party personal data from a DSAR response?
To properly redact third-party personal data from a DSAR response, you must balance the requester's right of access with the third party's rights.
This decision involves considering whether the third party has consented to the disclosure and whether it is reasonable to disclose the information without that consent. The ICO provides detailed guidance stressing the evaluation of confidentiality.
Do we have to respond to a DSAR from a former employee?
You do have to respond to a DSAR from a former employee, as the legal right of access does not end when employment terminates.
Former employees are fully entitled to request and receive copies of their personal data just like current employees, external contractors, or general customers. Refusing these requests can lead to regulatory enforcement.
When does a request for email data become 'disproportionate effort'?
A request for email data only becomes a 'disproportionate effort' when it qualifies as manifestly excessive. 'Disproportionate effort' is not a valid exemption to refuse a request outright.
You cannot refuse to comply simply because searching email archives is time-consuming. According to ICO guidance on excessive requests, you must have robust grounds to prove the request crosses the threshold into excessiveness.
Conclusion
DSARs are a core data right and a serious operational test for any organisation. A structured, documented workflow is non-negotiable for ensuring compliance and defensibility. Managing complex requests, especially those involving the redaction of third-party data and handling employee disputes, is where most operational risk lies.
Manual fulfilment is simply unsustainable for modern businesses. Automation is becoming essential for managing DSARs accurately and at scale. As data volumes grow and individuals become more aware of their regulatory rights, the ability to handle DSARs efficiently will become a key indicator of a mature and trustworthy privacy programme.
To automate your RoPA, data map, and DSRs on one platform, book a demo with TrustWorks and see how we help privacy teams centralise their operations.



