Start here
Documentation home
Everything your team needs to receive, manage, and respond to subject access requests with DSAR Respond, alongside the UK regulatory context each task calls for.
Set up your organisation
Create your organisation, invite your team, and assign the Admin, Member, and Viewer roles.
Handle an access request
Follow the end-to-end journey for handling a subject access request, from intake to completion.
Troubleshoot the core workflow
Resolve common problems with cases, connectors, and the response workflow.
About this guidance
Who this guidance is for, how it relates to UK GDPR, and how to use it responsibly.
What this documentation covers
DSAR Respond is the product your organisation uses to manage requests from people exercising their data rights. This site is its companion documentation: how to set the product up, and how to take a subject access request (SAR) from the moment it arrives to a securely delivered response and a retained audit record.
Alongside the product steps, each page carries the short UK regulatory context you need to carry out that task responsibly. That context is oriented to UK GDPR and may not fully align with EU GDPR requirements, and it is operational guidance rather than legal advice. About this guidance explains the boundary in full, and is worth reading before you rely on anything here.
How this guidance is organised
This guidance is written for the operations, HR, IT, and compliance staff who handle requests day to day. Start with the set-up pages, then follow the access-request journey in order, or jump straight to the task you need.
The sidebar lists every page in journey order. Each task page tells you what the task achieves, what you need before you begin, the numbered product steps, and where the journey goes next. Use the search box at the top of any page, or the ⌘K keyboard shortcut, to jump straight to a task.
Where to start
Three routes cover almost every reason to be here:
- Setting the product up for the first time. Work through Set up your organisation, then Connect Microsoft 365. You need the Admin role for both.
- Handling a request that has just arrived. Begin at the access-request lifecycle overview, which links the eight task pages in order, from receiving and recording the request through to completing the case.
- Something is not working. Troubleshoot the core workflow is organised by symptom. If it does not resolve the problem, contact product support — that page also lists what must never be sent in a support message.
Requests that need clarification, an extension, refusal, or specialist input are covered in Clarification, extensions, refusal, and specialist advice. Rights other than access — erasure, rectification, restriction, portability, and objection — are covered in Other data rights in DSAR Respond.
What happens next
What happens next
Read About this guidance to understand who this documentation is for and how to use it responsibly.
Last reviewed

