Handle an access request

Access-request lifecycle overview

Follow the end-to-end journey for handling a subject access request in DSAR Respond, from intake to completion.

The journey at a glance

Every subject access request (SAR) follows the same lifecycle in DSAR Respond, whichever way it arrives. Work through these task pages in order, or jump straight to the step you need:

  1. Receive and record a request — get the request into DSAR Respond as a case, by manual entry or through the public portal.
  2. Assess the request, scope, and response period — confirm what is being asked and what response period applies.
  3. Verify identity or representative authority — carry out proportionate checks before releasing personal data.
  4. Find data with Microsoft 365 — search connected systems for the requester's personal data.
  5. Add and organise documents — collect everything relevant on the case.
  6. Review and redact documents — prepare material for release, with human review of every decision.
  7. Prepare and securely deliver the response — send the response by an appropriate, secure route.
  8. Complete the case and retain an audit record — close the case with a defensible record of what was done.

If a request needs clarification, an extension, or specialist input at any point, see Clarification, extensions, refusal, and specialist advice.

How a request arrives

A SAR does not have to arrive through any particular door. Someone may write to your support inbox, mention it on a phone call, hand a letter to a receptionist, or use your organisation's public request portal. DSAR Respond gives the two intake routes equal standing:

  • Manual entry — a team member records a request that arrived anywhere in the organisation.
  • Public portal — the requester submits the request themselves through your organisation's portal page.

Both routes create the same kind of case, and from that point on the lifecycle is identical.

UK GDPR context

A subject access request is valid however it arrives. It can be made verbally or in writing, to any part of the organisation, and it does not need to use a form, mention UK GDPR, or contain any particular wording. Anyone in your organisation might receive one, so route anything that looks like a request promptly to the people who record cases — the response period is not delayed by the time it takes to reach the right team.

This is operational guidance for UK organisations, not legal advice.

Case statuses

A case moves through these statuses in DSAR Respond:

StatusWhat it means in the product
NewThe case has been created and awaits triage.
Verifying IdentityAn identity check is in progress.
Discovering DataData is being collected across connected systems.
In ReviewDiscovered data is being reviewed for release.
On HoldWork is paused pending additional input.
CompletedAll tasks have been completed.
ClosedThe case has been closed and archived.

Requesters who use the portal's status lookup see a simplified public vocabulary: Received, Verifying Identity, Processing, and Ready for Download.

Statuses describe workflow progress inside the product. They are not statements about the legal state of the response period: in particular, placing a case On Hold pauses DSAR Respond's own countdown but does not pause the statutory clock. See Assess the request, scope, and response period for what does and does not affect the legal deadline.

The response period

In most cases your organisation must respond to a SAR without undue delay and within one calendar month. The calculated due date is an outer limit, not a target: respond as soon as you reasonably can.

UK GDPR context

For requests governed by the rules in force from 5 February 2026, the response period runs from the latest applicable start event: receiving the request, receiving identity information you reasonably asked for, receiving evidence of a representative's authority you reasonably asked for, or receiving any permitted fee. A running period pauses only while you wait for a qualifying clarification — one you genuinely need because you process a large amount of information about the person. Product holds, internal reviews, and delivery-format questions do not pause it. See the ICO's guidance on responding to a request for the current rules.

This is operational guidance for UK organisations, not legal advice.

Check the statutory deadline yourself

DSAR Respond currently calculates each case's due date as the recorded received date plus one calendar month. That calculation does not yet reflect every lawful start event, qualifying clarification pause, or working-day adjustment under current UK rules. Treat the displayed date as a planning aid, not the statutory deadline: confirm the response period against current ICO guidance and record your reasoning about the start event on the case.

Who can do what

DSAR Respond has three roles. A Viewer can read cases but cannot act on them. A Member can create cases, change status, and assign work. An Admin can additionally run identity verification, extend deadlines, and deliver responses. Role setup is covered in Set up your organisation.

Official sources

What happens next

What happens next

Start the journey with Receive and record a request.

Last reviewed . UK regulatory context.

Previous
Connect Microsoft 365