Handle an access request

Receive and record a request

Record a subject access request as a case in DSAR Respond, whether it arrives through the public portal or any other route into your organisation.

What this task achieves

Every subject access request (SAR) becomes a case in DSAR Respond. This page covers both intake routes — recording a request manually and receiving one through the public portal — and they carry equal weight: neither route is more official than the other, and both create the same kind of case that then follows the shared access-request lifecycle.

Recognise a subject access request

A SAR can be made verbally or in writing, to any person or team in your organisation, on any channel. There is no required form and no required wording — "please send me what you hold about me" in a support chat is as valid as a formal letter.

UK GDPR context

A request is valid however it arrives. Do not tell requesters they must use the portal, put the request in writing, or resubmit it in a particular format. If a request arrives verbally, make a written note of what was asked and when, and record it promptly — the response period is not delayed while a request sits with the wrong team.

This is operational guidance for UK organisations, not legal advice.

Before you begin

Recording a case manually needs any role except Viewer. Have to hand the date the request actually reached your organisation and the request's original wording — you will record both. The portal route needs nothing from your team up front: it is available to requesters at your organisation's portal address.

Record a request manually

Use this route when a request arrived by email, phone, letter, in person, or anywhere else outside the portal.

From the Dashboard, select New DSAR Case to open the Create New DSAR Case wizard. It has three steps.

Step 1: Data Subject Information

  1. Enter the requester's First Name and Last Name.
  2. Enter their Email Address.
  3. Optionally add a Phone number — it helps the team reach the person if clarification is needed.
  4. Select Next.

Step 2: Request Details

  1. Set the Request Received Date. It defaults to today and cannot be a future date. Set it to the date the request first reached your organisation, which may be earlier than today — for example, the day a letter arrived or the call took place, not the day you got around to recording it.
  2. Choose the Request Type: Access, Portability, Deletion, or Rectification. This journey covers Access requests; the other rights have their own guidance in Other data rights in DSAR Respond.
  3. Choose the Received Channel: Email, Phone, Letter, or In Person.
  4. Select Next.

This step shows a One-Month Deadline Guidance panel with a Received on date, a Due on date, and a countdown.

The displayed due date is a planning aid

The panel's Due on date is the recorded received date plus one calendar month. That calculation does not yet reflect every lawful start event, qualifying clarification pause, or working-day adjustment under current UK rules, so do not treat it as the statutory deadline. Confirm the response period as part of assessing the request.

Step 3: Case Summary

  1. Enter the Request Description (10 to 5,000 characters). Capture what was asked, using the requester's own words where possible, plus any context about how the request arrived. This wording drives the later assessment and scoping of the case.
  2. Select Create Case.

The Case Created Successfully! dialog shows the new Case Number. Choose View Case to open it, or Create Another to record a further request.

Note

To record many requests at once, use the import dialog to upload a CSV file and select Start Import. Each imported row becomes a case in the same lifecycle.

Receive a request through the portal

Every organisation has a public portal where requesters can submit a request themselves, at /portal/{org-slug}/intake under your DSAR Respond address. The portal needs no account and no set-up by your team.

The Submit a Data Request form asks the requester for:

  • Full name and Email address.
  • A Request typeAccess my personal data, Delete my personal data, Correct my personal data, Export my personal data, Restrict processing of my data, or Object to processing of my data. Only the first is a SAR; the others are separate rights covered in Other data rights in DSAR Respond.
  • Request details describing what they want.
  • A consent confirmation before submitting.

On submission the requester sees a reference number (for example DSR-1a2b3c4d) and receives an acknowledgement email containing the reference and a response deadline. A case is created automatically: its received channel is recorded as the portal, and its received date is the submission time. The emailed deadline comes from the same calculation described above, so the same caution applies — it is a planning date, not a confirmed statutory deadline.

Let requesters check their status

Requesters can follow their request at /portal/{org-slug}/status. The Check Request Status form asks for their Reference number and Email address, then shows the reference, the current status, and the expected completion date. The portal uses a simplified public vocabulary:

Requesters seeMeaning
ReceivedThe request has been recorded as a case.
Verifying IdentityAn identity check is in progress.
ProcessingThe case is being worked on.
Ready for DownloadThe response is available.

These are simplified product statuses for the requester's benefit, not statements about the legal response period.

Rejoin the shared lifecycle

Whichever route created it, the case starts at status New and follows the same journey from here. The next step is to assess what is being asked and confirm the response period.

Official sources

What happens next

Last reviewed . UK regulatory context.

Previous
Access-request lifecycle overview