GDPR Article 15 Support

Structured, defensible DSAR management — without disrupting operations.

Locate, review, redact, and deliver Subject Access Requests within statutory timelines. Build a repeatable process that protects third-party privacy and satisfies the ICO.

Stage 1: Intake
Request Ref: SAR-9082
Type: Employee Access
Stage 2: Redact
User email is tom.s@company.com...
Stage 3: Release
🔒
Evidence Released
Compliant in 28 Days
Our DSAR Compliance Standard:
Regulatory Obligations

What Is a Data Subject Access Request (DSAR)?

A Data Subject Access Request (DSAR) is a legal right under UK GDPR Article 15 and GDPR Article 15 that allows any individual to request access to the personal data an organisation holds about them. Organisations are legally required to respond within one calendar month of receiving a valid request, with a possible extension to three months for complex or numerous requests.

A DSAR response must tell the individual what data you hold, why you hold it, who you share it with, and how long you retain it. Failure to respond correctly and on time is one of the most commonly reported GDPR breaches to the ICO and can result in formal enforcement action, financial penalties, and reputational damage.

Handling Risks

Why DSAR Handling Is Harder Than It Looks

A DSAR sounds simple: find the data, send it to the requester. In practice, it involves a series of legally sensitive decisions. You must verify identity without over-collecting data. You must scope the search correctly across email archives, databases, and third-party processors. You must apply legal exemptions and redact third-party information to balance the requester's right of access with other individuals' right to privacy. Crucially, every decision must be documented to defend your response if the ICO investigates.

KewData Capabilities

How KewData Handles Your DSAR Operations

KewData provides end-to-end DSAR management, from intake through to response delivery. We ensure your response process is operationally efficient, legally defensible, and fully logged.

01

Proportionate Identity Verification

We manage identity checks using methods that match the sensitivity of the data at risk, protecting you from data leaks without violating GDPR minimization guidelines.

02

Multi-System Search Coordination

We coordinate search efforts across all your systems, email databases, server logs, backups, and external processors to locate every trace of the subject's data.

03

Exemption & Redaction Control

Our specialists review documents to redact third-party PII and apply statutory exemptions accurately (e.g. legal privilege, business negotiations), preventing privacy breaches.

04

ICO-Ready Audit Trails

Every step of the intake, scoping, search, and redact process is logged in detail. We supply a complete audit pack to defend your actions if the ICO reviews the request.

DSAR Intake Scenarios

When Do Organisations Seek Our Support?

We support businesses handling high request volumes, navigating complex legal disputes, or building repeatable internal workflows.

High-Volume Backlog Scaling

Handling seasonal or growth-related spikes in consumer data requests without pulling internal engineering and support staff off core projects.

Complex Employee Disputes

Managing high-stakes DSARs from former employees involved in litigation or grievance procedures, requiring meticulous redaction of internal communications.

Ongoing Monthly Retainer Support

Outsourcing your entire DSAR handling pipeline to KewData privacy practitioners to guarantee response SLA compliance.

Process Design & Staff Training

Creating custom response libraries, writing internal policy playbooks, and training your customer support teams to manage intake correctly.

Disputed & ICO-Referred Appeals

Responding to individual complaints escalated to the ICO, resolving scope disputes, and explaining applied redactions to regulatory officers.

Consumer Product Compliance

Managing individual rights infrastructure for consumer-facing apps, fintech platforms, and e-commerce brands handling large visitor volumes.

DSAR Scope

The Scope of a KewData DSAR Delivery Pack

Our end-to-end management pipeline maps search areas, handles identity verification, and builds clean disclosure files.

Intake & Scoping

  • Assessment of request validity and scope parameters.
  • Official logging of the statutory calendar month clock.
  • Advising on seeking clarification without pausing deadlines.
intake_registry.json
Intake Scope Valid
Statutory Clock 30 Days
DPO Review Approved

Identity Verification Records

  • Managing proportionate verification checks based on data risk.
  • Documenting verification checks as required by the ICO Code of Practice.
  • Ensuring no excessive data (over-collection) is stored during ID checks.
Proportionate Identity Check Portal
👤
User Passport Token Check Method: Visual Check • Cryptographic Signature Logged
ID Verified
🛡
Verification Audit Log Entry Timestamp: 2026-07-05 12:30 UTC
Logged

Multi-System Search Map

  • Mapping database columns, server files, and email folders.
  • Coordinating search queries inside cloud platforms and backups.
  • Documenting data discovery scopes to verify search completeness.
System Discovery Scan Area
MySQL DB
Exchange Mail
Salesforce CRM
Cloud Backups

Exemption & Redaction

  • Redacting third-party personal identifiers.
  • Applying statutory exemptions (business info, legal advice).
  • Logging the rationale for every redaction applied.
Interactive Redaction Editor
CONFIDENTIAL // EMAIL RECIPIENTS:
From: manager@kewdata.ai
To: third_party_user@gmail.com
Subject: Refund Request details for customer John Doe

Compliant Response Pack & Audit Evidence

  • Preparing structured personal data files for the requester.
  • Assembling Article 15(1) supplementary privacy disclosures.
  • Structuring secure response transport protocols.
  • Storing the complete decision log and search history for regulator review.
DSAR Delivery Pipeline Validation
01
Verify Identity Confirm requester checks
02
Search & Redact Redact PII & apply log
03
Article 15 Disclosures Format supplementary info
04
Secure Send Deliver response pack
Roadmap

Our Handling Methodology — Step by Step

We follow a structured handling process to ensure every request is resolved on time and legally logged.

1

Intake and Initial Assessment

We receive the DSAR and assess request validity, identify the relevant data subject, and confirm the scope. We log the intake date, which starts the statutory one-month clock, and handle any necessary scope clarifications.

2

Identity Verification

We manage identity checks, ensuring they are proportionate to the sensitivity of the data at risk. We document the verification method and outcome as required under the ICO's Subject Access Code of Practice.

3

Scope Definition and Data Location

We map all systems, databases, email archives, third-party processors, and informal records that may hold personal data within the scope of the request.

4

Data Collection and Review

We coordinate collection, apply relevant exemptions with documented justifications, and carry out third-party PII redaction. The review is conducted against legal requirements, not just internal practice.

5

Response Pack Preparation

We prepare a legally compliant response pack containing the personal data disclosure, the Article 15(1) supplementary privacy information, and a covering communication.

6

Quality Assurance and Delivery

The response pack is reviewed for completeness and accuracy before delivery. We confirm delivery within the statutory timeline and retain the complete handling log.

Exemption Logs
DSAR Exemption Log
Documented rationale mapping withheld or redacted content to specific GDPR/UK GDPR statutory exemptions.
Status: Fully Logged
Accountability Logs
DSAR Handling Trail
Audit evidence file tracking intake, identity verification methods, search queries, and delivery timestamps.
Status: Completed Log
Disclosure Files
Compliant Response Pack
Structured disclosure file containing redacted personal data and all Article 15(1) supplementary information.
Status: Ready to Deliver
Outputs

What You Receive at the End of the Handling Process

Our DSAR deliverables ensure you satisfy individual rights requests while protecting company secrets and third-party data.

Deliverable Asset Target Audience Compliance Value
Compliant Response Pack Requesting Subject Provides the disclosure data and Article 15 disclosures.
DSAR Exemption Log DPO & Legal Counsel Statutory justification for withholding sensitive documents.
Handling Audit Trail Pack ICO Case Officers Protective evidence showing procedural timeline compliance.
Interactive Simulator

DSAR Statutory Deadline Calculator Sandbox

When must you legally respond to an incoming request? Use our timeline calculator below to find the target response deadline, including statutory extensions.

  • Automated timeline tracking: Get alerts on remaining days before enforcement risk triggers.
  • Extension assessment: Calculate the impact of marking complex requests under Article 12(3).
  • Identity verification buffers: See how delayed identity checks adjust the target deadline.
Request Retainer Pricing
Simulation Sandbox
Calculate Deadline
Mark as "Complex" (+2m)
No
ID Verification Delay (+7d)
No
Statutory Deadline Date
05 August 2026
Standard statutory response window (1 calendar month). Clock started on receipt.

Tom S.

Reputation Manager
Medical Practice
★★★★★ May 21, 2026
"Improved control over sensitive medical data"

"Practical guidance on access controls and data protection. Helped define structured access policies and introduced tokenisation for patient identifiers used in analytics."

Sarah S.

Experience Design Manager
Retail, Enterprise
★★★★★ May 21, 2026
"Reliable partner for telecom data protection"

"Quickly understood telecom data complexity; helped classify sensitive datasets and apply protection measures for subscriber, usage, and billing data."

Pauliina H.

PR Manager
Entertainment, Enterprise
★★★★★ Apr 10, 2026
"Effective support for securing customer data"

"Identified where sensitive data lived and applied tokenization and anonymization strategies in a complex telecom environment."

Jordan R.

Senior Director, Marketing Ops
Computer Networking
★★★★★ Apr 11, 2026
"Practical approach to safeguarding e-commerce"

"Helped protect PII, payment data, and order histories with tokenization and anonymization; advised on GDPR compliance for international operations."

Charmaine S.

Finance Specialist
Int. Trade & Development
★★★★★ Mar 24, 2026
"Systematic Approach Enhances Data Security"

"Methodical approach through discovery, planning, and implementation; implemented Microsoft Purview for a scalable compliance framework."

Kateryna H.

Sr. Finance & Operations
IT and Services
★★★★★ Mar 23, 2026
"Practical approach to protecting sensitive Data"

"Structured data discovery and classification combining technical analysis with finance data privacy expertise; strong masking and tokenization policies."

Snow D.

Marketing Coordinator
Market Research
★★★★★ Apr 30, 2026
"Practical expertise for telecom information"

"Introduced tokenization and controlled access strategies for subscriber data while still supporting analytics and reporting."

Laura H.

Senior Research Manager
Hospital & Health Care
★★★★★ Apr 30, 2026
"Valuable expertise in healthcare protection"

"Strong expertise in healthcare data security; introduced anonymization techniques for safely using patient data in research and reporting."

DSAR Q&A

Frequently Asked Questions

Standard questions regarding individual rights requests and KewData response services.

Under GDPR and UK GDPR, you must provide a copy of the personal data free of charge. The only exception is if the request is "manifestly unfounded or excessive," in which case you may charge a reasonable administrative fee or refuse to respond. However, the legal threshold for this is extremely high.

Yes. As the data controller, you are legally responsible for all personal data processed on your behalf. This includes data stored in third-party CRM platforms, billing engines, support desk software, or cloud backups. We coordinate search protocols across all external processors.

Under Article 15, you must supply the requester with specific details including: the purposes of processing, categories of data collected, third-party recipients, retention periods, the right to lodge complaints, and any automated profiling details. KewData includes a complete, pre-formatted disclosure pack with every response.

If a request is exceptionally complex or you receive multiple requests from the same individual, you can extend the deadline by up to two additional months (three months total). However, you must notify the subject within the first month and explain the exact legal justification for the extension.

Facing a complex DSAR, employee dispute, or high backlog volumes?

Ensure your response is legally compliant and delivered within deadlines. Speak with a KewData specialist today.

Schedule a Free Consultation