The email arrives: “I am writing to request a copy of all personal data you hold about me.” It is a Data Subject Access Request. You have one month to respond. For most SMEs, this triggers a panicked search through five systems, three spreadsheets, and a shared drive that nobody has organised since 2019.
At Metaluxo we help SMEs build DSAR response processes that turn a month-long scramble into a 48-hour workflow. This post covers the preparation, the process, and the common mistakes.
Step 1: Verify identity
Before you disclose anything, confirm that the requester is who they claim to be. Ask for:
- A copy of photo ID
- Proof of address
- If the request is made by a third party (e.g., a solicitor), confirm their authority
Time: 2–4 hours
Step 2: Search your systems
This is where most companies lose days. Without a data map, you are searching blindly. The solution is to maintain an up-to-date inventory of where personal data lives:
| System | Data types | Retention |
|---|---|---|
| CRM | Name, email, phone, address | 6 years |
| Correspondence | 3 years | |
| Support tickets | Name, issue history | 2 years |
| Marketing platform | Email, preferences | Until withdrawn |
| Finance system | Name, payment details | 6 years |
| HR system | Name, address, salary | 6 years post-employment |
With this map, you know exactly where to search. Use the system’s built-in search or export function.
Time: 4–8 hours
Step 3: Review and redact
You must disclose only the requester’s data. If documents contain information about other people (colleagues, customers, family members), redact those portions.
Common redaction scenarios:
- Email threads mentioning multiple people
- Group chat logs
- Documents with shared annotations
- Photos or videos with multiple individuals
Time: 4–8 hours
Step 4: Compile the response
Use a standard template that includes:
- Cover letter confirming the request and the date received
- A summary of the data you hold and the purposes for processing
- The data itself (organised by system or category)
- Information about retention periods and third-party sharing
- A note about the right to rectification, erasure, and objection
Time: 2–4 hours
Step 5: Send and log
Send the response by secure means (encrypted email or secure portal). Log:
- Date of request
- Date of identity verification
- Date of response
- Data categories disclosed
- Any redactions made
This log is your audit trail. Regulators may ask for it.
Time: 1 hour
Common mistakes
- Searching manually. Without a data map, DSARs take weeks. Build the map before the request arrives.
- Over-disclosing. Sending everything that mentions the requester’s name may include third-party data. Review carefully.
- Under-disclosing. Deliberately omitting data you know exists is a violation. If you find it later, disclose it.
- Missing the deadline. One month sounds like a long time until you spend three weeks trying to find the data.
At Metaluxo we build DSAR response processes for SMEs, typically delivering a data map, search procedures, and response templates in four weeks. If you are receiving DSARs and struggling to respond on time, book a free 30-minute consultation and we will streamline your process.
Common questions
How long do we have to respond to a DSAR?
GDPR gives you one month, extendable to three months for complex requests. But a well-prepared company can respond in days, not weeks.
Can we charge a fee for a DSAR?
Generally no, unless the request is manifestly unfounded or excessive. You can refuse or charge a reasonable fee in those limited circumstances.
What if the DSAR includes data about other people?
You must redact or anonymise third-party data before disclosure. This is one of the most common delays in DSAR response.