dsar process

Free Download | DSAR Process Workflow

Say goodbye to that DSAR panic 👋

Let's be honest, a Data Subject Access Request (DSAR) is nobody's idea of a good time.

Cue the slight panic and frantic Slack messages asking how to deal with it.

But it doesn't have to go like that. Once you've got a clear process in place, a DSAR is just the same steps every time.

So we've built you a workflow (plus a few checklists) that walks you through the whole thing, start to finish.

You'll never have to dread a DSAR again 🙌

Download your DSAR Workflow!

What's in this DSAR process workflow?


Short on time? Here's what's in this guide:


 

📄 What's inside the DSAR process workflow

The DSAR process, broken into eight steps, each with the common mistake called out next to it, so it's obvious what to watch for, not just what to do. If you want the fuller detail behind any step, Trust Keith's guide on how to respond to a DSAR goes deeper, and the free DSAR response templates cover what to actually write back.

Step What it covers
1. Request received Logging the right date and getting it to the right owner immediately
2. Is it actually a DSAR? Recognising informal requests that still count, and clarifying scope without resetting the clock
3. Verify their identity Matching the level of ID check to the actual risk, not defaulting to either extreme
4. Locate the data Every system worth searching, from the CRM to Slack to spreadsheets nobody remembers exist
5. Apply exemptions What can be withheld or redacted under the DPA 2018, and where people over- or under-share
6. Compile the response Organising the data into categories a person can actually make sense of, not a raw export
7. Send within 30 days The extension rules, and why silence past day 30 counts as a failure to respond
8. Log it What to record in a DSAR register, and why it's what protects you if the ICO ever asks

 


 

Who this DSAR process workflow is built for

This one's for scaleups, not enterprises. It's a good fit if your business:

  • Has roughly 50 to 250 employees
  • Only runs the DSAR process occasionally rather than daily, so it isn't already muscle memory
  • Doesn't have a dedicated privacy team to fall back on for every request
  • Wants a consistent process regardless of who happens to pick up the request

Trust Keith works with data-centric scaleups across fintech, healthtech, HR tech and ed tech, where a DSAR might land with anyone from support to HR, not just legal. Requests from employees follow a few extra twists of their own, covered in Trust Keith's guide to responding to an employee DSAR under UK GDPR.

 


 

How to use this DSAR process workflow

Step One: Get it in front of anyone who might receive a request. Support, HR, and sales are just as likely to get a DSAR as legal or privacy. Pin it somewhere they'll actually see it.

Step Two: Name an owner. Someone needs to be responsible for logging the date and starting the clock the moment a request is spotted, wherever it lands.

Step Three: Set up a register. Even a shared spreadsheet works, as long as every request goes in it. A workflow tool makes this easier to keep on top of as volume grows.

Step Four: Train people to recognise one. Most DSARs are missed because they don't sound formal, not because anyone's ignoring them. Training that covers real, casual phrasing catches far more than a policy document ever will.

Step Five: Get your process reviewed. Have a privacy expert check it holds up before you rely on it day to day. Trust Keith customers get DSARs handled as part of their intelligent workflows, with a dedicated expert on hand for the tricky ones.

 


 

Where the DSAR process usually goes wrong

Missing casual requests. "What info do you have on me?" counts just as much as a formal Subject Access Request. Treating it as a normal support query loses days off the clock before anyone notices.

Verifying identity badly, in either direction. Skipping it risks a data breach of its own. Over-verifying feels hostile and delays things for no good reason.

Only searching the obvious places. Slack messages, shared mailboxes and old spreadsheets are all in scope if they're live and searchable, not just the system the request came in through.

Handing over a raw data dump. An unorganised export technically answers the request and still generates a complaint, because nobody can make sense of it.

Going quiet past day 30. Still working on it isn't a defence if nobody's been told why. The extension has to be communicated within the original deadline, not after it's missed.

 


 

Frequently asked questions

What is a DSAR?

A Data Subject Access Request (DSAR) is a request from an individual asking what personal data a business holds about them. It doesn't need to mention GDPR or use formal language, a casual message like "what info do you have on me?" still counts.

How long do you have to respond to a DSAR?

One calendar month from the date the request was received, not the date someone noticed it. This can be extended by up to two additional months for complex requests, but the individual must be told within the original 30 days, with a reason why.

Is this DSAR process workflow really free?

Yes. Trust Keith built this to help data-centric scaleups handle DSARs consistently, without relying on one person's memory of the process. It's free in exchange for a work email, and it's yours to use and share internally.

Do you have to verify identity before responding to a DSAR?

Yes, but proportionately. A logged-in customer's account login may be enough. A cold email from an unrecognised address needs a bit more, like one piece of photo ID. Skipping verification risks sending someone else's data to the wrong person; over-verifying just causes unnecessary delay.

Can you withhold information when responding to a DSAR?

Some information can be exempt, such as data that would identify a third party, legally privileged material, or certain HR references. Where possible, redact the specific part rather than withholding a whole document.

What happens if you miss the DSAR deadline?

Silence past day 30 with no explanation is treated as a failure to respond, even if the request is still being worked on. If more time is genuinely needed, the individual must be told within the original 30 days.

 


 

Curious how Trust Keith can help take the DSAR process off your plate?

A workflow gets everyone following the same DSAR process. But when a request is genuinely complicated, special category data, multiple systems, a difficult requester, that's when having an expert on hand actually matters.

Trust Keith gives you a dedicated privacy expert, embedded in your business, backed by an intelligent platform that logs, tracks and manages every DSAR from request to response. No need to hire a privacy team.

Talk to an expert →

 


 

Disclaimer: This resource is provided free of charge for general information purposes only. It does not constitute legal advice and should not be relied upon as such.

Trust Keith Platform

Everything you need to run privacy properly in any jurisdiction

Trust Keith holds your hand to get you (and keep you!) as compliant as you need by giving you access to a dedicated human expert and an intelligent platform.