Handle an access request
Access-request lifecycle overview
Follow the end-to-end journey for handling a subject access request in DSAR Respond, from intake to completion.
The journey at a glance
Every subject access request (SAR) follows the same lifecycle in DSAR Respond, whichever way it arrives. Work through these task pages in order, or jump straight to the step you need:
- Receive and record a request — get the request into DSAR Respond as a case, by manual entry or through the public portal.
- Assess the request, scope, and response period — confirm what is being asked and what response period applies.
- Verify identity or representative authority — carry out proportionate checks before releasing personal data.
- Find data with Microsoft 365 — search connected systems for the requester's personal data.
- Add and organise documents — collect everything relevant on the case.
- Review and redact documents — prepare material for release, with human review of every decision.
- Prepare and securely deliver the response — send the response by an appropriate, secure route.
- Complete the case and retain an audit record — close the case with a defensible record of what was done.
If a request needs clarification, an extension, or specialist input at any point, see Clarification, extensions, refusal, and specialist advice.
How a request arrives
A SAR does not have to arrive through any particular door. Someone may write to your support inbox, mention it on a phone call, hand a letter to a receptionist, or use your organisation's public request portal. DSAR Respond gives the two intake routes equal standing:
- Manual entry — a team member records a request that arrived anywhere in the organisation.
- Public portal — the requester submits the request themselves through your organisation's portal page.
Both routes create the same kind of case, and from that point on the lifecycle is identical.
UK GDPR context
A subject access request is valid however it arrives. It can be made verbally or in writing, to any part of the organisation, and it does not need to use a form, mention UK GDPR, or contain any particular wording. Anyone in your organisation might receive one, so route anything that looks like a request promptly to the people who record cases — the response period is not delayed by the time it takes to reach the right team.
This is operational guidance for UK organisations, not legal advice.
Case statuses
A case moves through these statuses in DSAR Respond:
| Status | What it means in the product |
|---|---|
| New | The case has been created and awaits triage. |
| Verifying Identity | An identity check is in progress. |
| Discovering Data | Data is being collected across connected systems. |
| In Review | Discovered data is being reviewed for release. |
| On Hold | Work is paused pending additional input. |
| Completed | All tasks have been completed. |
| Closed | The case has been closed and archived. |
Requesters who use the portal's status lookup see a simplified public vocabulary: Received, Verifying Identity, Processing, and Ready for Download.
Statuses describe workflow progress inside the product. They are not statements about the legal state of the response period: in particular, placing a case On Hold pauses DSAR Respond's own countdown but does not pause the statutory clock. See Assess the request, scope, and response period for what does and does not affect the legal deadline.
The response period
In most cases your organisation must respond to a SAR without undue delay and within one calendar month. The calculated due date is an outer limit, not a target: respond as soon as you reasonably can.
UK GDPR context
For requests governed by the rules in force from 5 February 2026, the response period runs from the latest applicable start event: receiving the request, receiving identity information you reasonably asked for, receiving evidence of a representative's authority you reasonably asked for, or receiving any permitted fee. A running period pauses only while you wait for a qualifying clarification — one you genuinely need because you process a large amount of information about the person. Product holds, internal reviews, and delivery-format questions do not pause it. See the ICO's guidance on responding to a request for the current rules.
This is operational guidance for UK organisations, not legal advice.
Check the statutory deadline yourself
DSAR Respond currently calculates each case's due date as the recorded received date plus one calendar month. That calculation does not yet reflect every lawful start event, qualifying clarification pause, or working-day adjustment under current UK rules. Treat the displayed date as a planning aid, not the statutory deadline: confirm the response period against current ICO guidance and record your reasoning about the start event on the case.
Who can do what
DSAR Respond has three roles. A Viewer can read cases but cannot act on them. A Member can create cases, change status, and assign work. An Admin can additionally run identity verification, extend deadlines, and deliver responses. Role setup is covered in Set up your organisation.
Official sources
- ICO: A guide to subject access
- ICO: Responding to a request, timing, identity, clarification, and extensions
- UK GDPR, including Articles 12 and 15
- Data (Use and Access) Act 2025, section 76
What happens next
What happens next
Start the journey with Receive and record a request.
Last reviewed . UK regulatory context.