Start here

About this guidance

Understand who this guidance is for, how it relates to UK GDPR, and how to use it responsibly.

Who this guidance is for

This documentation is written for the people who actually handle requests: operations, HR, IT, and compliance staff who may deal with a subject access request only occasionally, and who need to get it right without being privacy specialists. Privacy professionals are an important second audience — you should find enough detail here to see exactly what the product does, and where a decision is being left to your organisation rather than made by the software.

It assumes you work for the organisation responding to requests. If you are a member of the public wanting to exercise your own data rights, contact the organisation that holds your data directly.

What this documentation covers

The site covers two things, in this order:

  • Setting DSAR Respond up. Creating your organisation, inviting colleagues and choosing their roles, and connecting Microsoft 365 so searches can run against your own data.
  • Handling an access request end to end. Recording a request, assessing its scope and response period, verifying identity, finding data, organising and reviewing documents, redacting them, delivering the response securely, and closing the case with a defensible record.

Around that core it covers the situations where the normal path does not apply — clarification, extensions, refusal, and specialist escalation — plus the other data rights the product records, symptom-by-symptom troubleshooting, and how to reach product support. Everything is described against the running product, and only behaviour that has been verified in it is published here.

What this documentation is not

Important

This is practical guidance for using DSAR Respond, not legal advice. It cannot tell you what the law requires of your organisation on your facts, and using the product does not by itself demonstrate that your organisation has complied with its obligations. Decisions about exemptions, third-party information, fees, refusal, extensions, and retention belong with your organisation's data protection officer or legal adviser, informed by current guidance from the Information Commissioner's Office (ICO).

Some things are deliberately out of scope. This site is not a general UK GDPR or EU GDPR knowledge base — where durable legal guidance already exists, pages link to the ICO or to the legislation rather than restating it. It does not cover billing and subscriptions, integrations other than the Microsoft 365 connector, the product's APIs, or specialist scenarios such as requests involving children, health, education, social work, public authorities, law enforcement, or legal privilege. Those are signposted so you can recognise one, not resolved for you.

How UK regulatory context is presented

Regulatory context appears next to the task it affects, in a callout headed "UK GDPR context", rather than in a separate reference section. Each one is short, tied to what you are about to do, and followed by links to the official sources it draws on.

UK GDPR context

The regulatory context throughout this documentation is oriented to the UK regime — UK GDPR as it applies in the United Kingdom, the Data Protection Act 2018, and the changes made by the Data (Use and Access) Act 2025. It may not fully align with EU GDPR requirements, and it does not attempt to cover any other jurisdiction. If your organisation also responds to requests under EU GDPR, or under another country's law, treat the differences as something to check with your own advisers rather than assuming the UK position carries across. Always check current guidance from the ICO and the legislation itself, both of which change.

This is operational guidance for UK organisations, not legal advice.

Two consequences are worth stating plainly. First, a displayed date or status in the product is a planning aid, never a legal conclusion — Assess the request, scope, and response period explains why you should confirm and diarise the statutory deadline independently. Second, AI-assisted analysis and redaction suggestions are proposals for a person to review; nothing in the product replaces that review, and no page here presents an automated output as compliance assurance.

How to read a task page

Task pages follow the same shape, so you can skim one you already know and read closely the one you do not:

  1. A short statement of what the task achieves.
  2. A Before you begin callout listing the role and set-up the task needs. Most actions on a case need the Member or Admin role; Viewers can read but not act, and some actions are Admin-only.
  3. Numbered steps using the exact labels you will see on screen. Product wording is shown in bold; exact on-screen messages and status values appear in code style.
  4. UK GDPR context callouts where the regulation shapes what you should do, followed by warnings, recovery guidance, and the points where you should stop and escalate.
  5. What happens next, linking to the following step in the journey, and the official sources the page draws on.

Every page shows a last-reviewed date. Pages carrying regulatory context also declare their jurisdiction and their official sources, and are reviewed again whenever the product or the guidance behind them changes.

Official sources

Wider ICO guidance for organisations is published at ico.org.uk. For product questions, and for the addresses to use, see Contact product support.

What happens next

What happens next

Last reviewed . UK regulatory context.

Previous
Documentation home