Metaluxo
← Insights

GRC

GDPR Data Subject Access Requests: How to Handle Them in 48 Hours

To handle a DSAR — without the usual panic.

The email arrives: “I am writing to request a copy of all personal data you hold about me.” It is a Data Subject Access Request. You have one month to respond. For most SMEs, this triggers a panicked search through five systems, three spreadsheets, and a shared drive that nobody has organised since 2019.

At Metaluxo we help SMEs build DSAR response processes that turn a month-long scramble into a 48-hour workflow. This post covers the preparation, the process, and the common mistakes.


Step 1: Verify identity

Before you disclose anything, confirm that the requester is who they claim to be. Ask for:

  • A copy of photo ID
  • Proof of address
  • If the request is made by a third party (e.g., a solicitor), confirm their authority

Time: 2–4 hours


Step 2: Search your systems

This is where most companies lose days. Without a data map, you are searching blindly. The solution is to maintain an up-to-date inventory of where personal data lives:

SystemData typesRetention
CRMName, email, phone, address6 years
EmailCorrespondence3 years
Support ticketsName, issue history2 years
Marketing platformEmail, preferencesUntil withdrawn
Finance systemName, payment details6 years
HR systemName, address, salary6 years post-employment

With this map, you know exactly where to search. Use the system’s built-in search or export function.

Time: 4–8 hours


Step 3: Review and redact

You must disclose only the requester’s data. If documents contain information about other people (colleagues, customers, family members), redact those portions.

Common redaction scenarios:

  • Email threads mentioning multiple people
  • Group chat logs
  • Documents with shared annotations
  • Photos or videos with multiple individuals

Time: 4–8 hours


Step 4: Compile the response

Use a standard template that includes:

  1. Cover letter confirming the request and the date received
  2. A summary of the data you hold and the purposes for processing
  3. The data itself (organised by system or category)
  4. Information about retention periods and third-party sharing
  5. A note about the right to rectification, erasure, and objection

Time: 2–4 hours


Step 5: Send and log

Send the response by secure means (encrypted email or secure portal). Log:

  • Date of request
  • Date of identity verification
  • Date of response
  • Data categories disclosed
  • Any redactions made

This log is your audit trail. Regulators may ask for it.

Time: 1 hour


Common mistakes

  • Searching manually. Without a data map, DSARs take weeks. Build the map before the request arrives.
  • Over-disclosing. Sending everything that mentions the requester’s name may include third-party data. Review carefully.
  • Under-disclosing. Deliberately omitting data you know exists is a violation. If you find it later, disclose it.
  • Missing the deadline. One month sounds like a long time until you spend three weeks trying to find the data.

At Metaluxo we build DSAR response processes for SMEs, typically delivering a data map, search procedures, and response templates in four weeks. If you are receiving DSARs and struggling to respond on time, book a free 30-minute consultation and we will streamline your process.

Common questions

How long do we have to respond to a DSAR?

GDPR gives you one month, extendable to three months for complex requests. But a well-prepared company can respond in days, not weeks.

Can we charge a fee for a DSAR?

Generally no, unless the request is manifestly unfounded or excessive. You can refuse or charge a reasonable fee in those limited circumstances.

What if the DSAR includes data about other people?

You must redact or anonymise third-party data before disclosure. This is one of the most common delays in DSAR response.

Related reading

Send us a message
Message us Book now