Workflow Template
Data Subject Access Request Workflow
Handles individuals' requests to access their personal information: captures identity details, request scope and contact preference; verifies identity; collects and redacts relevant records; routes the response through privacy review; delivers it securely; tracks the statutory deadline; and closes the request.
DSAR requests are a compliance risk when they're handled by email threads and spreadsheets — deadlines slip, identity checks get skipped, and unredacted records go out the door. This workflow captures the request, verifies identity, collects and redacts records, routes the response through privacy review, and delivers it securely while tracking the statutory clock. Privacy, legal, and records teams run it directly inside assess.one, with every step and decision logged.
Business Outcomes
- Zero missed statutory deadlines with automatic deadline tracking from day one
- 100% of requests pass through identity verification before records are released
- Every response reviewed and approved by privacy before it leaves the building
- Full audit trail of who accessed, redacted, and approved each request
- Faster average response time by removing manual handoffs and email chasing
Workflow Steps
Steps
- 1Create DSAR Recordcreate record
Registers the incoming data subject access request.
- 2Set Status to Receivedupdate record
Marks the request as received.
- 3Set Statutory Deadlineset due date
Sets the due date for the statutory response deadline (assumed 30 days).
- 4Send Acknowledgement Emailsend email
Confirms receipt of the request to the requester.
- 5Verify Requester Identitycreate task
Privacy team member checks the submitted proof of identity against the request details.
- 6Persist Identity Verification Outcomeupdate record
Saves the identity verification result to the record.
- 7Route on Identity Verification
Proceeds only if identity is verified; otherwise notifies and closes as rejected.
identity_verified: "Verified"→Set Status to Records Collectionidentity_verified: "Not Verified"→Notify Requester of Failed VerificationDefault→Notify Requester of Failed Verification - 8Notify Requester of Failed Verificationsend email
Informs the requester that identity could not be verified and the request cannot proceed.
- 9Close Request as Rejectedupdate record
Sets the final status to Rejected and closes the request.
- 10Search, Collect and Redact Recordscreate task
Privacy team searches all systems for relevant personal data, compiles records and redacts third-party information.
- 11Persist Records Collection Outcomeupdate record
Saves the collected records summary, redaction notes and response package, and updates status.
- 12Privacy Reviewer Approvalrequest approvalrequires approval
A privacy reviewer checks the redacted response package before it is released.
- 13Route on Reviewer Decision
If approved, send the response; if rejected, loop back for rework.
approval_status: "approved"→Mark Response Approvedapproval_status: "rejected"→Restart Records CollectionDefault→End - 14Restart Records Collectionrestart from step
Rejected response package: send back for rework and resubmission.
- 15Mark Response Approvedupdate record
Sets status to Approved before sending the response.
- 16Send Secure Response to Requestersend email
Notifies the requester that their redacted response package is ready, per their contact preference.
- 17Mark Request Completedupdate record
Sets status to Completed once the response has been sent.
- 18Close Requestupdate record
Closes the request now that the response has been delivered.
- 19Set Status to Records Collectionupdate record
Marks the request as entering the records collection and redaction stage.
Fields
- Full Name*
- Email Address*
- Phone Number
- Preferred Contact Method*
- Proof of Identity Document*
- Scope of Request (what personal data are you seeking?)*
- +7 more fields
Forms
Data Subject Access Request Form
8 fields
Data Views
All DSAR Requests
requester_name, requester_email, contact_preference, dsar_status +1 more
Dashboard Widgets
Recommended integrations
Setup the following integrations to extend workflow capability.
Send email in the workflow
AWS SES
Similar Categories
FAQs
How do I set up the DSAR workflow for my team?
Publish the template inside assess.one and it's live immediately — no build or integration project needed. You then customise the steps, statutory deadline logic, and reviewer roles to match your organisation's policy. Your team can start logging and processing requests the same day.
How long does implementation take?
Publishing the template takes minutes. Once it's live, your privacy and records teams can start running real DSAR requests through it immediately — there's no separate implementation phase or software install.
What do I need before I publish this workflow?
Decide who will act as identity verifier, records collector, and privacy reviewer, since these roles are assigned inside the workflow. You'll also want your statutory deadline rules ready so you can set the correct turnaround time on request creation.
Can I customise the identity verification step?
Yes. You can edit the verification criteria, add required documents or checks, and configure what happens on pass or fail directly in assess.one. The routing step then automatically sends failed verifications to rejection and passed ones forward to records collection.
Who needs access to this workflow?
Typically the DSAR intake team, records/data owners who search and redact, and a privacy reviewer with approval authority. You control access and permissions per role inside assess.one, so people only see the steps relevant to them.
What happens if the privacy reviewer rejects the response?
The workflow routes the request back to the records collection step so redactions or scope can be corrected. It cycles between collection and review until the reviewer approves, and every round is logged for audit purposes.
How does the workflow track the statutory deadline?
The deadline is set automatically when the request status changes to Received, based on the rule you configure. It stays visible throughout the workflow so your team can see time remaining at every stage, from verification through to secure delivery.
How is the response delivered securely to the requester?
Once the privacy reviewer approves the response, the workflow marks it approved and triggers secure delivery to the requester's preferred contact method. This step and the final completion are logged, closing out the request with a full record of the process.
Can we adjust this workflow for different regulations, like GDPR versus CCPA?
Yes. The deadline, verification requirements, and notification wording are all editable, so you can configure separate versions or adjust logic per regulation. This is done directly in assess.one without any external development work.
Ready to use this workflow?
Create a free account and customise this workflow for your business.
