Use controlled links

Controlled delivery links let the team limit the time response files are available and stop access if a concern appears after sending.

  • Set expiration windows for response packets.
  • Support revocation when delivery should stop.
  • Require passcodes for higher-risk deliveries when appropriate.
Pre-delivery control check
ControlConfirmIf it fails
RecipientVerified destination and intended requesterPause and re-check
PacketApproved files and current versionReplace the draft and repeat review
AccessExpiry, revocation, and access recordUse a controlled delivery route

Log delivery activity

Access history gives the team a clearer record than an email attachment. The case should show when delivery was created, opened, expired, revoked, or reissued.

  • Attach delivery events to the case timeline.
  • Record who created and revoked links.
  • Give requesters a clear support path when access expires or fails.

Keep response approval separate

The response should be reviewed before files are delivered. Secure delivery controls do not replace final content approval.

  • Use response templates and packet review before sending.
  • Store delivery files in controlled private storage.
  • Avoid forwarding response packets through personal inboxes.

Example: the wrong file is noticed after sending

The responder discovers that a delivery contains an outdated response file. Stop further access to the existing link, review the materials, and decide whether a corrected delivery is appropriate.

  • Use the case history to check which link and packet were involved.
  • Revoke access to the existing link and document the reason.
  • Review the corrected response before reissuing access; revocation cannot recall a file already downloaded.

Check the packet before creating the link

Delivery settings protect access to the packet. They do not establish that the packet contains the right information for the right person.

  • Confirm the intended recipient, response text, and final attachment list.
  • Check that internal notes and unrelated third-party information are not included accidentally.
  • Choose the expiry and any passcode requirement, and give the requester a clear contact if access fails.

Sources

Sources checked September 20, 2026. These primary and regulator materials support the legal-rule summaries above; check the current rules that apply to your organization.

Common questions

Why avoid email attachments for DSAR exports?

Attachments are hard to revoke, hard to audit, and easy to forward after delivery.

What controls matter for secure DSAR delivery?

Expiration, revocation, optional passcodes, private storage, and access logs are the practical baseline.

What should requesters do when a delivery link expires?

They should contact the company handling the request and ask whether access can be reissued.

Run privacy requests in one controlled workflow

Privacy Requests helps teams manage intake, verification, tasks, response preparation, secure delivery, and audit history without a broad enterprise suite.

Start free