Data Subject Access Requests (DSARs)
Know exactly what to do when a DSAR lands.
A data subject access request can arrive at any time, from anyone, in any format. Your business has one calendar month to respond. Most organisations treat DSARs as a legal problem, but in practice, your ability to respond on time depends almost entirely on how well your IT environment is set up.
We help businesses build the systems, documentation, and processes that make DSAR compliance a structured, repeatable task rather than an expensive scramble.


What Is a DSAR?
Article 15 of the UK GDPR allows individuals to request copies of their personal data. Requests can be informal (e.g., an email) and don’t require specific terminology. The one-month deadline starts once identity is verified.
Anyone, staff, clients, or the public, can submit a DSAR. While there’s no frequency limit, excessive requests may be refused or charged for if justified to the ICO.
Key Facts:
- Deadline: One calendar month
- Format: Any channel (email, phone, social media)
- Cost: Usually free
- Extension: Up to two months for complex cases
- Penalties: Fines and reputational damage
For more on the Data (Use and Access) Act 2025.
Apple-Specific DSAR Challenges
Apple’s privacy focus provides strong protection through FileVault and MDM, but limits device-level searching. Compliance requires platform-level searches across email and cloud tools. Risks include inaccessible data on personal devices and being locked out if FileVault keys aren’t centrally escrowed. Proactive setup is essential to avoid complications during live requests.

Not Sure If You’re DSAR-Ready? Let’s Find Out.
One conversation could save you from a missed deadline and an ICO complaint.







