Exceptions and other rights

Other data rights in DSAR Respond

Record a request to exercise a right other than access, and understand what DSAR Respond does — and does not — do with it.

These are separate rights, not kinds of SAR

Erasure, rectification, restriction of processing, data portability, and objection are distinct rights. Each has its own conditions, its own exceptions, and its own idea of what a valid response looks like. None of them is a variant of a subject access request, and none of them is satisfied by sending someone a copy of their personal data.

That distinction matters in practice because DSAR Respond's guided journey — discovery, document collection, review, redaction, delivery — is built for the right of access. Running that journey on an erasure request produces a pile of documents, not an erasure. The work that actually fulfils these rights happens in your own systems and processes.

Important

This documentation covers the subject access journey in depth. It does not tell you when another right applies, whether an exception defeats it, or what a compliant response looks like. Those are decisions for your organisation, informed by current ICO guidance and your data protection officer or legal adviser.

What DSAR Respond does with these requests

DSAR Respond is a case-management tool for them. It gives you a record that a request arrived, when it arrived, what was asked, who is handling it, and a one-month deadline to work to. It does not act on your source systems: there is no erasure action, no correction workflow, no restriction flag, and no suppression list. Nothing in the product deletes, amends, restricts, or stops processing a person's data anywhere.

Everything that fulfils the right — locating the data, deciding whether the right applies, making the change, telling anyone you shared the data with — is work your organisation does outside DSAR Respond and then records on the case.

Record the request

Both intake routes accept requests for other rights, as described in Receive and record a request.

Through the portal. The Submit a Data Request form offers six options, covering access, erasure, rectification, portability, restriction, and objection. Whichever the requester picks, a case is created in the same way.

Recorded manually. The Create New DSAR Case wizard offers a shorter Request Type list: Access, Portability, Deletion, and Rectification. There is no option for restriction or objection, so for those two — and whenever the list does not quite fit — say plainly in the Request Description which right the person is exercising, in their own words where you can.

The request type is recorded, not displayed

DSAR Respond stores the request type but does not show it anywhere on the case afterwards: there is no type column on the Dashboard, no type filter, and no way to change it later. The case will look like every other case to whoever picks it up. Put the right being exercised in the Request Description, where it stays visible, and do not rely on the type field to communicate it to your team.

Handle the case

A case created for another right follows exactly the same product lifecycle as a SAR — the same statuses, the same identity verification, the same deadline calculation. Nothing in the workflow changes according to request type. That is a property of the product, not a statement about the law.

Use the case as a container for your own process:

  1. Identify the right correctly, and check with your data protection officer or legal adviser whether it applies to these facts. Getting this wrong at the start is the expensive mistake.
  2. Verify identity proportionately where you have real doubts, exactly as you would for a SAR. See Verify identity or representative authority.
  3. Do the substantive work in the systems that hold the data.
  4. Use Add Note on the case's Timeline & Actions tab to record what you found, what you decided, what you did, and what you told the requester. This is the only free-text record on a case, and for these rights it is the audit trail.
  5. Close the case with the Change Status control when the work is done — there is no separate close button. A case can only reach Completed once every document on it has been reviewed; Closed is available from any status and records no reason of its own, so write the reason in a note first.

You can still use discovery and document management if locating the data is genuinely part of the job — but treat what they produce as an internal working set, not as something to send the requester.

Check the acknowledgement wording

The acknowledgement email DSAR Respond sends when a request arrives through the portal is written for subject access requests, and refers to the person's "data subject access request" whatever right they actually exercised. Read what your requester receives, and follow up in your own words where the wording does not match the request. The same one-month deadline calculation is applied to every case regardless of type, so treat the displayed date as a planning aid and confirm the period that genuinely applies.

UK GDPR context

The rights to erasure, rectification, restriction, portability, and objection are qualified rights: each applies only in defined circumstances, each has exceptions, and some carry obligations beyond the response itself — such as telling other recipients of the data what you have done. A single message can exercise more than one right at once, and a request that mentions erasure may also be a subject access request. Identify each right the person is actually exercising, respond to each on its own terms, and check current ICO guidance for the right in question rather than reasoning from the access rules on this site.

This is operational guidance for UK organisations, not legal advice.

When to escalate

Get advice from your data protection officer or legal adviser before responding when:

  • you are unsure whether the right applies at all, or whether an exception defeats it;
  • complying would affect other people, records you are required to keep, or ongoing legal proceedings;
  • the person disputes your response, or asks you to reconsider;
  • the request comes from a representative, a parent or guardian, or someone who may lack capacity;
  • erasure or rectification would touch data you have shared with other organisations.

Record the outcome on the case whatever is decided. For requests that cannot follow the standard path for other reasons, see Clarification, extensions, refusal, and specialist advice.

Official sources

What happens next

What happens next

If something is not working as expected, see Troubleshoot the core workflow. For product questions, contact product support — support cannot advise on which right applies.

Last reviewed . UK regulatory context.

Previous
Clarification, extensions, refusal, and specialist advice