assess.one – AI-powered business operations platform

Workflow Template

Data Subject Access Request Workflow

Handles individuals' requests to access their personal information: captures identity details, request scope and contact preference; verifies identity; collects and redacts relevant records; routes the response through privacy review; delivers it securely; tracks the statutory deadline; and closes the request.

DSAR requests are a compliance risk when they're handled by email threads and spreadsheets — deadlines slip, identity checks get skipped, and unredacted records go out the door. This workflow captures the request, verifies identity, collects and redacts records, routes the response through privacy review, and delivers it securely while tracking the statutory clock. Privacy, legal, and records teams run it directly inside assess.one, with every step and decision logged.

Business Outcomes

  • Zero missed statutory deadlines with automatic deadline tracking from day one
  • 100% of requests pass through identity verification before records are released
  • Every response reviewed and approved by privacy before it leaves the building
  • Full audit trail of who accessed, redacted, and approved each request
  • Faster average response time by removing manual handoffs and email chasing

Workflow Steps

Steps

  1. 1
    Create DSAR Recordcreate record

    Registers the incoming data subject access request.

  2. 2
    Set Status to Receivedupdate record

    Marks the request as received.

  3. 3
    Set Statutory Deadlineset due date

    Sets the due date for the statutory response deadline (assumed 30 days).

  4. 4
    Send Acknowledgement Emailsend email

    Confirms receipt of the request to the requester.

  5. 5
    Verify Requester Identitycreate task

    Privacy team member checks the submitted proof of identity against the request details.

  6. 6
    Persist Identity Verification Outcomeupdate record

    Saves the identity verification result to the record.

  7. 7
    Route on Identity Verification

    Proceeds only if identity is verified; otherwise notifies and closes as rejected.

    identity_verified: "Verified"Set Status to Records Collection
    identity_verified: "Not Verified"Notify Requester of Failed Verification
    DefaultNotify Requester of Failed Verification
  8. 8
    Notify Requester of Failed Verificationsend email

    Informs the requester that identity could not be verified and the request cannot proceed.

  9. 9
    Close Request as Rejectedupdate record

    Sets the final status to Rejected and closes the request.

  10. 10
    Search, Collect and Redact Recordscreate task

    Privacy team searches all systems for relevant personal data, compiles records and redacts third-party information.

  11. 11
    Persist Records Collection Outcomeupdate record

    Saves the collected records summary, redaction notes and response package, and updates status.

  12. 12
    Privacy Reviewer Approvalrequest approvalrequires approval

    A privacy reviewer checks the redacted response package before it is released.

  13. 13
    Route on Reviewer Decision

    If approved, send the response; if rejected, loop back for rework.

    approval_status: "approved"Mark Response Approved
    approval_status: "rejected"Restart Records Collection
    DefaultEnd
  14. 14
    Restart Records Collectionrestart from step

    Rejected response package: send back for rework and resubmission.

  15. 15
    Mark Response Approvedupdate record

    Sets status to Approved before sending the response.

  16. 16
    Send Secure Response to Requestersend email

    Notifies the requester that their redacted response package is ready, per their contact preference.

  17. 17
    Mark Request Completedupdate record

    Sets status to Completed once the response has been sent.

  18. 18
    Close Requestupdate record

    Closes the request now that the response has been delivered.

  19. 19
    Set Status to Records Collectionupdate record

    Marks the request as entering the records collection and redaction stage.

Fields

  • Full Name*
  • Email Address*
  • Phone Number
  • Preferred Contact Method*
  • Proof of Identity Document*
  • Scope of Request (what personal data are you seeking?)*
  • +7 more fields

Forms

Data Subject Access Request Form

8 fields

Data Views

All DSAR Requests

requester_name, requester_email, contact_preference, dsar_status +1 more

Dashboard Widgets

DSAR Pipeline OverviewRequests by StatusDSAR Processing Funnel

Recommended integrations

Setup the following integrations to extend workflow capability.

  • Send email in the workflow

    AWS SES logoAWS SES
data subject access requestDSARsubject access requestprivacy requestpersonal data request

Similar Workflows

Similar Categories

FAQs

How do I set up the DSAR workflow for my team?

Publish the template inside assess.one and it's live immediately — no build or integration project needed. You then customise the steps, statutory deadline logic, and reviewer roles to match your organisation's policy. Your team can start logging and processing requests the same day.

How long does implementation take?

Publishing the template takes minutes. Once it's live, your privacy and records teams can start running real DSAR requests through it immediately — there's no separate implementation phase or software install.

What do I need before I publish this workflow?

Decide who will act as identity verifier, records collector, and privacy reviewer, since these roles are assigned inside the workflow. You'll also want your statutory deadline rules ready so you can set the correct turnaround time on request creation.

Can I customise the identity verification step?

Yes. You can edit the verification criteria, add required documents or checks, and configure what happens on pass or fail directly in assess.one. The routing step then automatically sends failed verifications to rejection and passed ones forward to records collection.

Who needs access to this workflow?

Typically the DSAR intake team, records/data owners who search and redact, and a privacy reviewer with approval authority. You control access and permissions per role inside assess.one, so people only see the steps relevant to them.

What happens if the privacy reviewer rejects the response?

The workflow routes the request back to the records collection step so redactions or scope can be corrected. It cycles between collection and review until the reviewer approves, and every round is logged for audit purposes.

How does the workflow track the statutory deadline?

The deadline is set automatically when the request status changes to Received, based on the rule you configure. It stays visible throughout the workflow so your team can see time remaining at every stage, from verification through to secure delivery.

How is the response delivered securely to the requester?

Once the privacy reviewer approves the response, the workflow marks it approved and triggers secure delivery to the requester's preferred contact method. This step and the final completion are logged, closing out the request with a full record of the process.

Can we adjust this workflow for different regulations, like GDPR versus CCPA?

Yes. The deadline, verification requirements, and notification wording are all editable, so you can configure separate versions or adjust logic per regulation. This is done directly in assess.one without any external development work.

Ready to use this workflow?

Create a free account and customise this workflow for your business.

Data Subject Access Request (DSAR) Workflow | assess.one