The average cost to manually process a single DSAR in the UK is £1,200. It is a high price for a task defined by the fear of missed data in obscure locations. You likely feel the weight of the 30-day deadline every time a new request arrives. Managing dsar requests is a technical challenge that demands precision. It is no longer a simple administrative burden. With UK GDPR fines that reach up to £17.5 million, the stakes for your compliance team are immediate and absolute.
You know that manual searches consume too many man-hours and lead to errors. This guide provides a repeatable process to identify, locate, and disclose personal data to meet statutory deadlines with confidence. We will explain how to use the 2026 'stop the clock' rules and the Data (Use and Access) Act 2025 to your advantage. You will learn to conduct reasonable and proportionate searches that reduce costs and ensure no file is left behind. We start with the mechanics of modern data discovery and the move toward an automated DSAR Disclosure Pack to organise your response.
Key Takeaways
- Learn to manage DSAR requests using the 2026 'stop the clock' provisions. Meet statutory deadlines with precision.
- Find personal data in local mailboxes and images. Use OCR to find what manual searches miss.
- Implement a secure identity verification process. Prevent data breaches before they occur.
- Use a DSAR Disclosure Pack to organise evidence. Reduce compliance costs and save man-hours.
Understanding DSAR Requests and the Right of Access
A Data Subject Access Request (DSAR) is the practical application of the Right of Access under the UK GDPR. It allows individuals to verify what information your organisation processes about them. This is a request for the specific data points you hold, rather than just a collection of documents. You must provide a copy of this personal data alongside supplementary information. This includes your processing purposes, data retention periods, and the sources of the data.
Validity does not depend on a specific format. A request is valid whether it arrives via a formal letter, an email, a social media message, or a verbal comment to a staff member. Your team must recognise these triggers immediately. Failure to identify dsar requests at the point of entry is a common cause of missed statutory deadlines. You cannot insist that a requester uses a specific form or portal to submit their query. If the intent is clear, the clock starts.
What Constitutes Personal Data in 2026?
The Data Protection Act 2018 defines personal data as any information relating to an identified or identifiable living individual. In 2026, this definition is broad and covers more than just contact details. It includes:
- Online identifiers such as IP addresses or cookie IDs
- Location data from mobile devices and vehicle trackers
- Identification numbers, payroll codes, and staff files
- Biometric, genetic, or health-related information
If a piece of information can be linked back to a person, it is in scope. This creates a significant challenge for IT and compliance teams. Data is rarely found in one place. It exists in email threads, local mailboxes, and even scanned images on local drives. Identifying this data manually is slow and prone to oversight. You can find more detail on managing these risks in our GDPR guide.
The Scope of a Subject Access Request
The right covers data held in electronic formats and structured paper filing systems. Under the Data (Use and Access) Act 2025, which came into force on 5 February 2026, you are required to conduct a "reasonable and proportionate" search. You are not expected to search every archived backup tape or obscure system if the effort is extreme. However, when handling dsar requests, you must search all locations where data is reasonably likely to be found. This includes local drives and external hard drives used by staff.
The right of access is not absolute. You may withhold data if it includes the personal information of others or if specific legal exemptions apply. Whilst the search must be thorough, it must also be proportionate. Your task is to balance the individual's right to transparency against the privacy of third parties. This requires a methodical approach to discovery and disclosure.
Statutory Deadlines and Regulatory Requirements
Compliance is a race against the calendar. The standard response time for dsar requests is exactly one calendar month from the date of receipt. If you receive a request on 10 September, you must provide the data by 10 October. This deadline is absolute. The Information Commissioner's Office (ICO) monitors these timelines closely. Late responses are the most common cause of individual complaints and subsequent regulatory scrutiny.
Failure carries a heavy price. The UK GDPR allows for fines up to £17.5 million or 4% of your global annual turnover. Beyond regulatory action, you face the risk of civil litigation from data subjects. A single missed deadline can escalate into a costly legal dispute. You need a process that prioritises speed without sacrificing accuracy. For deeper compliance insights, consult our GDPR guide.
Calculating the One-Month Deadline
The "corresponding day" rule determines your due date. If you receive a request on the 31st of a month followed by a shorter month, the due date is the last day of that next month. For example, a request received on 31 August is due by 30 September. However, new rules introduced in 2026 offer some flexibility. You can now pause the one-month response deadline if you reasonably require clarification from the requester to proceed. The response time limit also begins only after you verify the requester's identity. These rules prevent unauthorised disclosure and protect your internal resources.
Extensions and Refusals
Complex dsar requests allow for a two-month extension. This applies if the volume of data is vast or the search involves multiple systems. You must notify the individual within the first month. State the reason for the delay clearly. You cannot simply claim a request is complex to buy more time. You must be able to justify the extension to the ICO if challenged. Following the government's Subject Access Request procedure provides a reliable framework for these communications.
Refusal is a last resort. You can refuse a request only if it is "manifestly unfounded or excessive." This usually means the request is intended to harass the organisation or is repetitive. In these rare cases, you can charge a reasonable administrative fee or refuse to act. You must still issue a refusal notice. Explain your reasoning and inform the individual of their right to lodge a complaint. If you want to avoid these administrative bottlenecks, you can test our automated discovery tools for free.
Identifying and Locating Personal Data Across the Network
Standard search tools are a liability in a compliance context. Most organisations rely on Windows Explorer or Outlook to find information. These tools are built for convenience, not for the rigour required by dsar requests. They often fail to index deep directory structures or content within compressed files. If your search misses a single local mailbox or an external hard drive, your response is legally incomplete. This oversight creates a direct path to ICO intervention.
Personal data is rarely confined to central servers. It is scattered amongst local drives, legacy backups, and hidden folders. For remote workers, this fragmentation is even more severe. Sensitive files often sit on individual laptops, never touching the corporate cloud. You cannot disclose what you cannot see. Effective discovery requires a shift from centralised indexing to local endpoint scanning. This ensures that every byte of data - regardless of where it resides - is accounted for in your final disclosure pack.
The Problem with Manual Data Discovery
Manual search is a process built on human error. Staff frequently save files locally to avoid slow network speeds. They forget to move these documents to the "official" repository. Email attachments represent another significant black hole. A single PDF containing a name or identification number can hide in a subfolder for years. Manually opening every file to verify its content is impossible within the statutory 30-day window. It consumes hundreds of man-hours and provides no guarantee of accuracy. You can see how this technical gap increases your risk in our explanation of endpoint scanning.
Using OCR to Find Data in Scanned Documents
Unstructured data is the primary blind spot for most compliance teams. Many businesses store scanned contracts, passports, or utility bills as image files. To a standard search engine, these images are invisible. They appear as empty containers. Optical Character Recognition (OCR) is the only way to bridge this gap. OCR technology converts the visual pixels of an image into searchable text strings. This allows you to map PII hidden in "flat" files like JPEGs or non-searchable PDFs. Without OCR, your search for dsar requests is fundamentally flawed. You are effectively ignoring a massive portion of your data estate whilst claiming to be compliant. Modern data discovery must include OCR scanning to ensure that no identification number or address remains hidden in a scanned image.

Executing the DSAR Procedure: A Step-by-Step Guide
Managing dsar requests is a high-stakes operation. It requires a repeatable, defensive workflow. You cannot afford to guess which files contain personal data. A structured procedure ensures you meet the ICO's standards whilst protecting your organisation from accidental data leaks. Accuracy is your priority.
Step 1: Verification and Clarification
Verification is your first line of defence. You must confirm the individual's identity before processing the request. This prevents data breaches caused by social engineering. Requesting a copy of a photo ID or a recent utility bill is permitted if it is necessary and proportionate. The one-month deadline begins only after you verify the requester's identity. Use this time to clarify the scope of the request. If the subject has a long history with your business, ask them to specify date ranges or departments. This narrows the search and reduces the volume of irrelevant data you have to review. Efficiency starts with clarity.
Step 2: Search and Collection
The search phase must be exhaustive. Standard file explorers are not enough. You need to scan local mailboxes, desktop folders, and external drives for the subject's name and unique identifiers. Using GDPR data discovery software UK allows you to automate this across all endpoints. It finds PII in seconds, including within images and non-searchable PDFs. Move all identified files into a single secure review folder. This creates a central workspace for the final redaction phase. It ensures that no data is left behind on a remote worker's laptop.
Step 3: Redaction and Disclosure
Redaction is a legal necessity. You must remove any information that identifies third parties unless they have given explicit consent. This includes names in email chains, phone numbers, or signatures in scanned documents. A failure to redact is a breach of the UK GDPR. Once the files are clean, organise them into a DSAR Disclosure Pack. Format the data in a commonly used electronic format like a PDF or a CSV file. Provide your privacy policy and details of the subject's rights alongside the data. This final step completes the lifecycle of dsar requests and provides an audit trail for compliance.
Simplifying Disclosure with Automated Data Discovery
Manual search is a resource drain. Your team cannot sustain it. Every hour spent digging through local mailboxes is an hour lost to higher-value security tasks. Managing dsar requests through automation changes the economics of compliance. It replaces guesswork with a surgical, repeatable process. You move from a state of anxiety to one of controlled efficiency. This isn't just about speed. It is about the accuracy of your final disclosure.
Most platforms require you to upload data to a central dashboard for analysis. This creates a secondary security risk. It moves sensitive PII across your network or into the cloud. Local processing eliminates this friction. The data stays where it is. Only the metadata and audit evidence move. This approach respects your existing security architecture whilst fulfilling your legal obligations. You maintain total control over the data lifecycle without the need for file exfiltration.
The Benefit of Endpoint-Only Scanning
Scanning data directly on the hard drive is significantly faster than querying a central server over a saturated network. It allows you to reach remote workers' laptops without moving large volumes of data. Our platform uses salted SHA - 256 fingerprints to create audit-ready evidence. This ensures you have a verifiable record of what was found without exposing raw files to unnecessary eyes. It is a cleaner, safer way to handle discovery. By processing files at the source, you bypass the technical bottlenecks of traditional network indexing.
Building a Repeatable DSAR Workflow
A consistent audit log is your best defence against an ICO enquiry. Automated tools generate these logs by default. They record every search parameter and every file identified during the process. This speeds up the redaction phase by highlighting PII instantly. You no longer need to read every line of a 50 - page PDF to find a single name. The goal is to produce a DSAR Disclosure Pack that is ready for immediate review. This pack organises your findings into a structured format that includes both the data copy and the required supplementary information.
A structured workflow provides a clear trail of your 'reasonable and proportionate' search efforts under the Data (Use and Access) Act 2025. You can verify your current data risks immediately and ensure your team meets every statutory deadline. Check the EmberHound pricing to see how this workflow scales for organisations of any size. Start a free scan today to see what manual searches are missing.
Secure Your Compliance Pipeline
Managing dsar requests is no longer a manual burden defined by the fear of oversight. You have the technical means to identify personal data in mailboxes, local drives, and scanned images using built-in OCR. This methodical approach replaces the uncertainty of manual searches with a definitive audit trail. Local-only scanning ensures that sensitive files never leave the endpoint. This removes the risk of file exfiltration during the discovery process. You can now produce audit-ready evidence with masked previews to satisfy regulators whilst protecting third-party privacy.
Transition from reactive anxiety to a repeatable, automated workflow that respects your team's time. By automating the identification of PII, you reduce the risk of ICO fines and lower your compliance costs. You don't have to guess if your search was thorough enough. You can see the results instantly and act with confidence. Accuracy is your shield. Speed is your advantage.
Take control of your data estate today. Ensure your business remains resilient against the growing volume of subject access requests.
Frequently Asked Questions
How much can I charge for a DSAR request in the UK?
In most cases, you cannot charge a fee for dsar requests. The UK GDPR mandate is that information must be provided free of charge. You can only request a payment if the request is "manifestly unfounded or excessive." If you do charge, the fee must be reasonable and reflect the administrative cost of locating and copying the data. Most businesses avoid this to prevent regulatory friction with the ICO and potential complaints from the data subject.
Can an employee submit a DSAR for their own emails?
Employees have the same right of access as any other data subject. They can request copies of their own emails and any internal communications where they are the primary subject. However, you must be careful not to disclose the personal data of other staff members or clients. Redaction is essential in these cases to protect third-party privacy. You are only providing the individual's own personal data, not every document they have ever touched or authored.
What happens if I cannot find all the data within 30 days?
Respond within one calendar month. If the request is complex or you are handling multiple requests from the same person, you can extend the deadline by a further two months. You must notify the individual of this extension within the first month and explain the delay. Under 2026 rules, you can also "stop the clock" whilst waiting for identity verification or necessary clarification from the requester to proceed with the search.
Do I have to provide data that is already in the public domain?
Yes, you must provide the data if you are processing it. The fact that information is publicly available elsewhere doesn't exempt you from the obligation to disclose what you hold. A subject access request is about transparency regarding your specific processing activities. If the data is in your systems, it's in scope. You must provide a copy of the data and the required supplementary information regardless of its source or public availability.
Can I refuse a DSAR if the requester is a disgruntled former employee?
You cannot refuse a request simply because of the individual's motive. The right of access is purpose-blind in most circumstances. You can only refuse if the request is "manifestly unfounded or excessive." This usually applies if the request is intended to harass the business or is a repeat of a recent request. Refusal requires a formal notice explaining your decision and informing the subject of their right to complain to the ICO or seek a judicial remedy.
How do I handle a DSAR request made via social media?
A request made via social media is legally valid. Your staff must be trained to recognise dsar requests across all platforms, including LinkedIn or X. Once identified, you should move the conversation to a secure, private channel to verify the requester's identity. Never send personal data through a social media platform. Verification is critical to prevent a data breach, and the one-month deadline begins only after the identity is confirmed by the organisation.
Is a verbal request for data a valid DSAR?
Yes, a verbal request is a valid exercise of the right of access. An individual can ask any member of your staff for their data during a phone call or a face-to-face meeting. You don't have the right to insist they put it in writing or use a specific form. It's your responsibility to log the request, verify the individual's identity, and begin the search process within the statutory timeframe to avoid non-compliance.
What information should be redacted from a DSAR response?
You must redact any information that identifies third parties unless they have consented to the disclosure. This includes names, contact details, or specific identifiers of other individuals. You should also withhold information covered by legal professional privilege or data that would reveal trade secrets. Redaction ensures you meet your transparency obligations to the requester without violating the privacy rights of others or compromising your organisation's legal position. Use automated tools to ensure no PII is missed.