Handle requests promptly within 72 hours, verify identity, provide requested information clearly, and document all actions taken.
Data Subject Access Requests (DSARs) are fundamental rights under GDPR, requiring systematic handling procedures to ensure compliance and maintain data subject trust.
Immediate Response (Within 72 hours): Acknowledge receipt promptly and provide estimated completion timeline. Verify the requester's identity using proportionate methods - avoid requesting excessive identification documents.
Request Assessment: Determine the request type (access, rectification, erasure, portability, restriction, or objection). Assess whether the request is manifestly unfounded or excessive, which may justify refusal or charging fees.
Data Compilation: Search all relevant systems including databases, emails, backups, and paper records. Include personal data about the requester, not data they've created about others. Consider pseudonymized data that can be re-identified.
Third-Party Considerations: Redact information about other individuals unless they've consented or disclosure is legally justified. Balance competing privacy rights carefully.
Response Preparation: Provide information in accessible format, preferably matching the original request format. Include data categories, processing purposes, retention periods, and recipient information.
Documentation: Maintain detailed records of all DSARs including request details, actions taken, and response timeline for accountability purposes.
Bob van Bouwel from Lead-Out Legal emphasizes that establishing clear DSAR procedures prevents legal complications and demonstrates organizational commitment to data protection principles.
For personalized guidance, consult a Data Protection specialist on TinRate.
The following Data Protection experts on TinRate Wiki can help with this topic:
| Expert | Role | Company | Country | Rate |
|---|---|---|---|---|
| Bob van Bouwel | Your Lead-Out Legal | Lead-Out Legal | Belgium | EUR 100/hr |
| Kenny Hietbrink | Hack-IT | Netherlands | EUR 110/hr | |
| Niels Vandezande | Data, AI, Cybersecurity, Tech and Crypto/Payments Lawyer | Timelex | Belgium | EUR 200/hr |
| Tim Bracke | CISO / Security Expert | Trustbit | Austria | EUR 95/hr |