A practical, step-by-step guide for IT managers and business owners at UK Mac-first businesses.
Last updated: April 2026
Relevant Resources:
- Handling a DSAR in Egnyte Guide
- Handling a DSAR in Google Vault Guide
- Handling a DSAR in Zoom Chat Guide
A data subject access request can arrive at any time, in any format, from anyone whose personal data your business holds – a current employee, a former client, a supplier, or a member of the public. When it does, you have one calendar month to respond. The businesses that handle DSARs well are not the ones with the best lawyers. They are the ones who have thought through the process before a request arrives. This guide tells you what to put in place, what to do when a request lands, and what to avoid along the way.
Part 1 | The Rules in Simple Terms
Under Article 15 of the UK GDPR, any individual has the right to ask your business for a copy of the personal data you hold on them. That request is a data subject access request, or DSAR. You do not get to decide whether it is valid. You do not get to charge for it. And the clock starts the moment it arrives.
The One-Month Deadline
Your business has one calendar month from the date the request is received to respond. Not from when it reaches the right person internally, not from when someone gets around to reading it, but from the day it lands. If a request arrives on 14 May, the response is due by 14 June. The ICO is clear on this, and missing the deadline gives the requester grounds to complain.
Any Format Counts
A DSAR does not need to use the words “data subject access request.” It does not need to reference the GDPR. Someone emailing your reception desk asking what information you hold on them is a valid DSAR, and the clock starts immediately. Train everyone in your business to recognise the substance of a request, not just the terminology.
Extensions – When and How
For complex requests or where you receive multiple requests from the same individual, you can extend the deadline by a further two months. You must notify the requester within the original one-month window, explain why the extension is needed, and apply it case by case. The ICO takes a dim view of businesses that use extensions routinely.
Stop the Clock
If you need to verify the requester’s identity or clarify the scope of what they are asking for, you can pause the one-month deadline while you wait for their response. Once they reply, the clock resumes. Document when you paused it and why.
The Data (Use and Access) Act 2025
The DUAA introduced two significant changes for IT teams. First, it codifies a “reasonable and proportionate” search standard. You are not required to search every archive and every legacy system for every request, but you must search intelligently and be able to justify what you included or excluded. Second, from 19 June 2026, organisations must have a formal process for handling data protection complaints, including an electronic complaints form, with acknowledgement within 30 days. If that is not yet in place, now is the time.
Part 2 | Before a Request Arrives – Get This in Place
Everything in this section can be done now, before a request arrives. Doing it now means that when one does land, your team is working from a process rather than improvising under pressure.
Nominate a DSAR Lead and a Backup
One named person should own the DSAR process in your business. More importantly, a second person needs to be able to cover when the first is unavailable – the one-month clock does not pause for annual leave. Both should know where the documentation lives and how to run a search.
Build Your System Map
Write down every system in your business where personal data is stored, processed, or transmitted. This is the single most important thing you can do. Your list will probably include email, file storage, chat and messaging platforms, your CRM, HR and finance tools, and project management software. For each system, note the admin access required to run a search, the platform’s search capabilities and limitations, and how far back its data goes.
You will not search every system for every request – the DUAA’s reasonable and proportionate standard allows for judgement. But you need a complete list to make that judgement from. Working from a map is very different from trying to remember what platforms you use while a deadline is running.
Confirm Admin Access for Each Platform
For every system on your map, confirm that the right person has the admin-level access required to run a DSAR search. Some platforms require a Super Admin account. Others have dedicated export or audit features that are not available to standard users. Find this out now, not at 4 pm on a Friday when a request just came in.
Set Up Your Folder Structure Template
Create a standard folder template for each DSAR. At a minimum, you need a subfolder for search evidence, records of what was searched, when, and what terms were used, and a subfolder for files under review before redaction. Using a consistent structure protects you if the ICO ever asks to see how a search was conducted.
Check Your Apple Environment Specifically
For Mac-first businesses, a few Apple-specific checks are worth doing now:
- FileVault recovery keys. FileVault encryption is enabled by default on every Mac with Apple silicon. If a device needs to be accessed as part of a DSAR and the user is unavailable, you need the recovery key. If your MDM is properly configured, those keys are escrowed centrally and retrievable by IT. If they are not, you may find yourself locked out of a device containing data you are legally required to produce. Check this now.
- Managed Apple Accounts. Ensure that work data and personal data are cryptographically separated on enrolled devices. This matters for DSAR searches and for BYOD clarity.
- Apple Business. Your MDM gives you visibility over enrolled devices, installed apps, and security policies. It will not search the contents of a device for you. DSAR searches happen at the platform level, through your email, file storage, and chat tools. Know which platforms your business data travels through, and make sure those are the ones your system map covers.
- BYOD boundary. If staff use personal iPhones or iPads for work, confirm that business data flows through centrally managed, searchable platforms rather than sitting only on personal devices. If your team uses iMessage or AirDrop to share files informally, that data may be very difficult to locate and produce in response to a DSAR.
Part 3 | When a Request Lands – What to Do
Follow these steps in order. Do not skip the documentation steps – your audit trail is part of your compliance, not an afterthought.
1. Log It and Start the Clock
Record the date and time the request was received, who it came from, and what they are asking for. Create a new folder using your standard template. Note the response deadline on your calendar immediately.
2. Acknowledge Receipt
Send an acknowledgement to the requester confirming you have received their request and noting the date by which you will respond. If you need to verify their identity before proceeding, do this now and pause the clock until they respond. Keep a record of when you paused it and why.
3. Work Through Your System Map
Search each relevant platform systematically, starting with the most likely sources of data for this individual. Use your documented search terms and date ranges, and record what you searched for on each platform. Below are notes on the platforms where DSAR searches are most commonly run.
4. Review What You Have Found
Search each relevant platform systematically, starting with the most likely sources of data for this individual. Use your documented search terms and date ranges, and record what you searched for on each platform. Below are notes on the platforms where DSAR searches are most commonly run.
5. Redact Before Sharing
Any data you share in response to a DSAR will almost certainly include personal information belonging to people other than the requester. That data must be removed before you send anything. Use a proper redaction tool that permanently removes the underlying text – placing a black box over text in a PDF is not sufficient if the text can still be copied or lifted from the file.
6. Respond Within the Deadline
Send the response to the requester before the one-month deadline. If you are applying for an extension, notify them within the original window with a clear explanation. Keep a copy of everything you sent and when.
Platform-By-Platform: What to Expect
Every system handles data retrieval differently. Here is what to be aware of for three platforms that appear in most UK businesses running Mac-first environments.
Google Vault is one of the more capable platforms for DSAR searches. It allows admins to search across Gmail by keyword and date range, export results, and download them for review. You will need a Super Admin account, and the quality of your results depends on using well-chosen search terms. Record exactly what you searched and when.
Egnyte supports keyword searches across most common document types and returns content snippets in the results, which helps with relevance. It does not search within images or certain proprietary file formats, so be aware of those gaps and note them in your search record.
Zoom Chat is the most demanding platform to search. There is no cross-message keyword search for admins. You need to download chat logs by channel or user, one month at a time, and search through them manually. Chat history only goes back two years. If you have a large number of channels to cover, this process can take hours; build in time accordingly.
Part 4 | Common Mistakes to Avoid
Most DSAR problems are not caused by bad intentions. They are caused by gaps in the process that nobody noticed until a request arrived.
Not Recognising the Request
A DSAR does not announce itself as one. If a team member receives an email asking what data the business holds on someone and treats it as a general enquiry, the clock has already started while the request sits in an inbox. Make sure everyone in your business knows to forward anything that looks like a personal data enquiry to the DSAR lead immediately.
Assuming MDM Will Do the Work
Apple’s MDM framework cannot search the contents of devices. It will not tell you what personal data sits on a specific MacBook or iPhone. DSAR searches happen at the platform level, through your email provider, file storage, and chat tools, not through device management. Building a DSAR process that relies on MDM for data discovery will leave significant gaps.
Searching Only the Obvious Places
Email tends to get searched thoroughly. Chat platforms, shared drives, and CRM records often do not. If your system map is incomplete, your search will be too. Conduct a proper audit of your platforms once, document it, and keep it current.
Redacting Incorrectly
Covering text with a black box in a PDF is not redaction if the underlying text can still be copied. Use a tool that permanently removes the text from the file before anything is shared with the requester.
Applying Extensions Without Cause
Extensions exist for genuinely complex requests. Using them routinely, or failing to notify the requester within the first month, is both non-compliant and, if challenged, difficult to defend. If your process is well documented, most requests should be managed within the standard deadline.
FAQs
Do we need a solicitor to respond to a DSAR?
Not for a standard request. Most DSARs can be handled internally if you have a documented process, the right admin access to your platforms, and a clear understanding of what you are looking for. Where legal support becomes valuable is when a request is unusually complex, when the requester’s intentions are unclear, or when your business has received multiple requests from the same individual. Getting your IT foundations right means you are unlikely to need legal help for day-to-day requests.
How do we know if our search was thorough enough?
The Data (Use and Access) Act 2025 sets a “reasonable and proportionate” standard, which means your search needs to be intelligent and well-documented rather than exhaustive. A good test: could you explain to the ICO which systems you searched, what terms you used, and why you included or excluded certain platforms? If the answer is yes and you have the records to prove it, your search is likely to stand up to scrutiny.
What if a DSAR arrives and we are not prepared?
Start the clock, send an acknowledgement to the requester, and work through every system where their data is likely to live as methodically as you can. Document every step as you go. If the request is genuinely complex and you need more time, you can apply a two-month extension, but you must notify the requester within the first month and give a reason. Use the request as a prompt to get the foundations in place before the next one arrives.