Make the request easy to understand
Clear intake helps the team identify the requester, relationship, request type, and information needed before fulfillment begins.
- Use a hosted portal for structured submissions.
- Record clarification requests and requester replies.
- Keep staff review attached to the case.
| Checkpoint | Article 12 or 15 question | Working evidence |
|---|---|---|
| Receive | Can the person exercise the right through an accessible route? | Original request and receipt |
| Scope | What personal data and supplementary information are covered? | Search plan and review notes |
| Respond | Is the communication concise, transparent, and intelligible? | Approved response and delivery record |
Coordinate evidence work
DSAR fulfillment often requires system owners to search, export, review, or explain data. Assigned tasks keep that work visible.
- Use system-specific task templates.
- Attach evidence and notes to the case.
- Review response materials before delivery.
Keep a record of the work
The closed case should show how the request moved through verification, fulfillment, approval, delivery, and closure.
- Capture important case events automatically where possible.
- Document exceptions with rationale.
- Avoid scattering sensitive files across inboxes.
Example: an access request spans several systems
A customer asks for information associated with an account used over several years. Product and support teams contribute records while the case owner tracks the scope and the reviewer checks the proposed response.
- Give each contributor consistent account identifiers and an agreed search scope.
- Record where a search found no relevant material as well as where it produced records.
- Reconcile results and review the response before creating a delivery.
Prepare a handoff to your reviewer
The reviewer should receive a clear account of what was requested, what was found, and what remains uncertain. Organizing those facts makes the review more useful than sending a folder of unexplained exports.
- Summarize the request and any clarification received from the requester.
- List completed searches, unresolved questions, and proposed response materials.
- Ask the appropriate reviewer to resolve legal interpretation, exclusions, and timing decisions.
Check every Article 15 response element
Article 15 covers more than a data export. In addition to a copy of personal data, review whether the response addresses processing purposes, data categories, recipients or recipient categories, retention period or criteria, the person's relevant rights, the right to complain to a supervisory authority, available source information when data was not collected from the person, and meaningful information about qualifying automated decision-making.
- Create a response checklist that maps each applicable element to a source and reviewer.
- Review the copy for third-party information and other applicable restrictions before disclosure.
- Use concise, transparent, intelligible language as required by Article 12; a raw database export alone may not answer the supplementary-information elements.
- Record any extension notice and reasons within the first month; do not let a changed internal target stand in for the required communication.
Sources
Sources checked September 20, 2026. These primary and regulator materials support the legal-rule summaries above; check the current rules that apply to your organization.
- EU General Data Protection Regulation, Articles 12 and 15 — Primary text for access rights, transparent communication, identity questions, and response timing.
- ICO: responding to a right-of-access request — Official UK guidance on calendar-month calculations, clarification, extensions, and proportionate identity checks.
Common questions
What does a GDPR DSAR workflow include?
It includes intake, identity verification, scope clarification, evidence collection, response review, secure delivery, and audit history.
Can software determine GDPR obligations for a company?
No. Software can support operational workflow, but legal obligations and exceptions require human review by the appropriate team.
Why use secure delivery for GDPR DSAR responses?
Secure delivery gives the team expiration, revocation, passcode options, and access logs for sensitive response materials.
Run privacy requests in one controlled workflow
Privacy Requests helps teams manage intake, verification, tasks, response preparation, secure delivery, and audit history without a broad enterprise suite.
Start free