What Is a DSAR and Does Your Team Know What to Do When One Lands?

A laptop displays a blue screen with a yellow padlock surrounded by twelve yellow stars in a circle, symbolising the European Union and data protection, likely referencing GDPR privacy compliance.

A data subject access request can arrive at any time, in any format, and your business has one calendar month to respond. Many companies treat DSARs primarily as a legal problem. In practice, they are an IT problem too, and if your IT team is not ready, even the best legal advice in the world will not get the response out on time.

Under Article 15 of the UK GDPR, any individual has the right to ask your business for a copy of the personal data you hold on them. That request is called a Data Subject Access Request, or DSAR. It does not need to use those words. It does not need to arrive on a form. Someone emailing your reception desk to say, “Can you tell me what information you have about me?” is a valid DSAR, and the clock starts the moment it lands.

For most UK businesses, especially those running lean IT teams, the challenge is not understanding the law. It is knowing where the data actually lives and getting it out in time.

The One-Month Deadline Is Stricter Than It Sounds

Your business has one calendar month from the date a DSAR is received to respond. Not one month from when someone gets around to reading it, or from when it reaches the right person internally. The ICO has confirmed that the clock starts on the day the request is received, even if that day falls on a weekend or bank holiday. If a request arrives on 14 May, the response is due by 14 June.

For complex requests, or where you receive multiple requests from the same individual, the deadline can be extended by a further two months, but only if you notify the requester within that first month and explain why. The ICO takes a dim view of businesses that apply extensions routinely rather than on a case-by-case basis.

If you miss the deadline, the individual can complain to the ICO, which can investigate and, in serious or repeated cases, take enforcement action. More commonly, it simply damages trust with the person who made the request, whether that is a client, a former employee, or a supplier.

The Data (Use and Access) Act Changes Things for 2026

The Data (Use and Access) Act 2025 has introduced several changes to how DSARs work in practice. Some are already in force; others take effect later this year.

The most significant for IT teams is the codification of a “reasonable and proportionate” search standard. Previously, the expectation was that organisations would make reasonable efforts to search all relevant systems. The DUAA now confirms in law that searches need to be intelligent and proportionate rather than exhaustive. You need to search intelligently, document what you searched and why, and be able to justify what you included or excluded.

The Act also formalises a “stop the clock” provision. If you need to verify the requester’s identity or clarify the scope of what they are asking for, you can pause the one-month deadline while you wait for their response. Once they reply, the clock resumes.

From 19 June 2026, a new complaint-handling requirement will also come into force. Organisations will need to have a formal process for handling data protection complaints, including an electronic complaints form, and must acknowledge receipt of data protection complaints within 30 days. If your business does not already have this in place, now is the time to set it up.

Why DSARs Are Really an IT Problem

The legal framework is one thing. The operational reality is another. When a DSAR arrives, someone in your business needs to search every system where that person’s data might exist: email, file storage, chat platforms, CRM, HR systems, cloud drives, and more.

That search is where most businesses struggle, because the data is scattered across platforms that were never designed to work together for this purpose. Each system has its own admin interface, its own search capabilities, and its own limitations. Some make it straightforward. Others make it painful.

This is not to say that legal input is unimportant; it absolutely is. A solicitor or DPO can help you scope what is in or out of scope for a particular request, advise on exemptions, and review the final response before it goes out. But none of that helps if your IT team cannot actually find the data in the first place, or cannot evidence how the search was conducted. Legal oversight and IT execution need to work together.

Take a few common examples from tools many UK businesses use daily:

  • Google Vault allows admins to search across Gmail by keyword and date range, export the results, and download them for review. It is one of the more capable platforms for DSAR searches, but it still requires a Super Admin account, careful use of quoted search terms, and a clear record of what was searched and when.

Download our guide to handling a DSAR in Google Vault:

  • Egnyte supports keyword searches across most common document types and shows content snippets in the results, which helps with relevance. It does not search within images or certain proprietary file formats, so there are gaps you need to account for.

Download our guide to handling a DSAR in Egnyte.

  • Zoom Chat is the most difficult. There is no cross-message keyword search for admins. You have to download chat logs by channel or user, one month at a time, and then search through them manually. Chat history only goes back two years, and if you have a lot of channels to cover, the process can take hours. Tools like Claude Cowork can speed this up significantly by reading through a folder of downloaded chat files and answering questions about the content, but the download step itself is unavoidable.

Download our guide to handling a DSAR in Zoom Chat.

Every platform is different, and every DSAR requires you to work through them one by one. If you do not have a documented process for this, each request becomes an improvised scramble.

What Your Team Needs to Have in Place

The businesses that handle DSARs well are the ones that have thought about the process before one arrives. That does not mean an elaborate compliance programme; it means having a few practical things in place:

  • A named person or team responsible for DSARs. Everyone in the business should know where to forward a request, and more than one person should be able to act on it. If the only person who knows what to do is on holiday, the clock does not stop.
  • A documented list of systems to search. Not every system will be relevant to every request, but you need a master list of everywhere personal data might live, email, file storage, chat, CRM, HR, finance, project management tools, with a note of the admin access required for each.
  • A clear folder structure for each request. Create a dedicated folder for every DSAR with subfolders for search evidence and files for review. This protects you if the ICO ever asks to see how the search was conducted.
  • A redaction step before anything is shared. DSAR responses will almost always contain personal data belonging to other people. That data must be redacted before you share anything with the requester. Use a proper redaction tool that permanently removes the underlying text rather than simply covering it with a black box, which can often be lifted or copied.
  • A record of every search. For each platform, note the exact search terms used, the date ranges covered, and the date the search was carried out. This is your audit trail, and it is essential.

If your business has a DPO or works with a data protection solicitor, this documentation also gives them something concrete to review, and means your legal adviser is not starting from scratch every time.

What “Reasonable and Proportionate” Means in Practice

The DUAA’s new search standard is helpful, but it is not a licence to do less. It means you need to think about where the data is most likely to be and focus your effort there. If someone worked with your business for six months in 2023, you do not necessarily need to search every system going back to 2019. But you do need to be able to explain your reasoning.

In practice, this means your IT team needs to understand not just which systems hold personal data, but how searchable each one is, what its retention limits are, and where the gaps lie. That knowledge is worth documenting once, not rediscovering every time a request arrives.

Getting Ahead Before the Next One Lands

If your business has not yet received a DSAR, it is only a matter of time. Individuals are increasingly aware of their rights, and the ICO actively encourages people to exercise them. The question is not whether a request will arrive, but whether your team will be ready when it does.

Getting the right systems, documentation, and processes in place is as much an IT strategy conversation as a legal one. If you are not sure where to start, or if you have received a DSAR and need practical help working through the search process across your systems, that is exactly the kind of problem we help businesses solve.

Related Articles

FAQs

Can a DSAR be submitted by email, phone, or social media?

Yes. Under the UK GDPR, a data subject access request can be made in any format, including email, phone, letter, social media, or even a WhatsApp message. The request does not need to mention the GDPR or use the term “DSAR.” If someone asks to see the personal data your business holds on them, that counts, and the one-month response deadline starts immediately.

Do we have to search every system in the business when responding to a DSAR?

Not necessarily. The Data (Use and Access) Act 2025 confirms that organisations are required to conduct “reasonable and proportionate” searches rather than exhaustive ones. However, you must be able to justify what you searched and what you excluded. Keeping a documented list of systems where personal data is stored, and recording your search methodology for each DSAR is the best way to demonstrate compliance.

What happens if we miss the one-month DSAR deadline?

The individual can complain to the ICO, which may investigate and require you to respond by a set date. In serious or repeated cases, enforcement action is possible, including fines. Beyond regulatory risk, missing the deadline damages trust with the person who made the request, whether they are a client, employee, or former staff member. The simplest protection is having a documented process in place before a request arrives.

Woman with long dark hair and layered necklaces sits at an outdoor cafe table, with buildings visible in the background.
Paige

Marketing Executive

Paige leads content and marketing at Dr Logic, translating the team's deep technical expertise into practical, straight-talking advice for businesses running on Apple. She covers everything from IT strategy and cyber security to the trends shaping how modern teams work - always with a focus on what actually matters to the people making the decisions.

Explore More Articles

Clear, Actionable Advice – No Jargon, No Pressure.

Get In Touch With an IT Expert

Scaling up, tackling downtime, or reviewing your setup? Contact us or book a quick call for expert advice on running your IT smarter and more securely.

Rather speak to us right now? Our phone number is: 020 3642 6540


Contact Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Book a Consultation Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Want IT to Work Smarter for You?

Get expert tips, security advice, and practical insights for Apple and hybrid teams – straight to your inbox.


Subscription Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.