Handle an access request
Complete the case and retain an audit record
Close a completed case and retain the audit record your organisation needs.
What this task achieves
Delivering the response is not the end of the case. Closing is a separate, deliberate step that says the work is finished and nothing further is expected. Before you take it, make sure the record left behind explains what you did and why — because that record, not your recollection, is what answers a complaint, an ICO enquiry, or a colleague picking the case up in two years' time.
Before you begin
Before you begin
- The response should have reached the requester, and the Delivery card should show the outcome you expect. See Prepare and securely deliver the response.
- Admins and Members can change a case's status. Only Admins can export the audit trail.
- Closing cannot be undone in the product. Confirm any outstanding question before you close.
Completed and closed are not the same
The two end states mean different things, and it matters which one a case is left in:
| Status | What it means |
|---|---|
| Completed | All tasks have been completed. The response package has been built and the download window may still be open. The case can still be moved back to In Review — for example to add a document and re-issue a corrected response. |
| Closed | The case has been closed and archived. No further status change is available from Closed, in either direction. |
Leave a case at Completed while anything might still change: the requester may not have downloaded the response, may be about to query it, or may need the download re-issued. Move it to Closed when you are satisfied the request has been answered and no further action is expected.
Close the case
- Open the case and go to the Timeline & Actions tab.
- Before closing, add a note recording that the response was delivered, by what route, and anything outstanding that was resolved. Use Add Note on the same tab.
- In the Status & Assignment card, use Change Status and select Closed.
What closing changes
Closing tidies up the identity evidence held for the case. The verification records for the case are deleted, along with any identity documents the requester uploaded through the portal. This is deliberate: identity evidence is collected to answer one question, and there is no reason to keep it once that question is settled. If your organisation needs a record that identity was verified, make sure the decision and its reasons are recorded as a note on the case before you close it, rather than relying on the documents themselves surviving.
The case itself, its timeline, its correspondence, and its Delivery card all remain available after closing.
Closing is not deleting
Deleting a case removes it and its history, and the product warns that the action cannot be undone. Never use Delete Case as a way of finishing a request — a deleted case leaves you unable to show what you did. Delete only where your organisation has a specific, recorded reason to, and never simply to tidy a list.
Keep a record that explains the decisions
Most of the case record builds itself: the Activity Timeline captures status changes, assignments, extensions, verification steps, and notes, and the Correspondence tab holds the outbound emails, replies, and system notifications for the case in order, each showing whether it was sent, delivered, bounced, failed, or drew a complaint.
What the product cannot capture is your reasoning. Before closing, check the case explains:
- how the request was interpreted, and any scope agreed with the requester;
- what identity or authority evidence was accepted, or why a check was not needed;
- what was searched and why that search was reasonable and proportionate, including the reason for any excluded item;
- why material was withheld — the reason recorded against each manual redaction, and the basis for any third-party or exemption decision, together with who was consulted and what they advised;
- how the response was delivered, and the reasons for any alternative arrangement;
- any extension, hold, or clarification, and the reason for it.
Record these as notes on the case as you go, not at the end. A reason written the day the decision was taken is worth considerably more than one reconstructed at closure.
Export the audit trail
An Admin can produce a point-in-time record of the case from the Audit Trail card on the Timeline & Actions tab. Select Export Audit Trail and a PDF downloads.
The export contains a Case Summary — case reference, data subject, when the request was submitted, when it was completed and closed, the deadline, the current status, the assigned staff member, and the organisation — followed by an Action Timeline of the recorded events, each with its timestamp, the action, who performed it, and a description.
Export the audit trail when you close a case, and keep the file wherever your organisation keeps its request records.
Important
The exported PDF contains personal data about the requester and about your staff. Handle it as case material: store it where case records belong, share it only with people who need it, and never send it to a general support or helpdesk address. The same applies to any copy of the response package.
Retention is your organisation's decision
UK GDPR context
You are accountable for demonstrating how you handled the request, so keep enough of a record to show what was decided, by whom, and on what basis. But a request record is itself personal data, and personal data must not be kept for longer than is necessary for the purpose it was collected for. How long to keep case records, audit exports, and delivered response packages is a decision for your organisation's own retention schedule, taking account of complaint and limitation periods relevant to your sector — it is not something DSAR Respond determines and not something this guidance can set for you. If your organisation has no retention schedule covering request records, raise it with your data protection officer rather than deciding case by case.
This is operational guidance for UK organisations, not legal advice.
Official sources
- ICO: A guide to subject access
- ICO: Responding to a request, timing, identity, clarification, and extensions
- UK GDPR, including Articles 12 and 15
What happens next
What happens next
That completes the standard journey — see the access-request lifecycle overview to start the next request. If a request cannot follow the standard journey, see Clarification, extensions, refusal, and specialist advice.
Last reviewed . UK regulatory context.