DSAR consultancy · Buyer guide
DSAR Consultancy vs Managed DSAR Operations
A DSAR consultancy can provide advice, overflow support or a fully outsourced matter. The useful question is not the label; it is which retrieval, review and delivery responsibilities are in scope.
What does a DSAR consultancy do?
A DSAR consultancy can provide advice, overflow capacity, redaction or an outsourced response process. Commercial models include scoped projects, fixed fees, pay-as-you-go work and retainers. Confirm who retrieves, reviews, drafts and delivers; the controller remains responsible for the response.
Match the model to the problem
When is a DSAR consultancy the right choice?
Start with the risk and the missing capability. A qualified adviser is a strong fit when a request does not fit the standard procedure: it is contested, litigation-adjacent, spans legal entities, may involve exemptions or privilege, or has already reached a regulator. A delivery consultancy can also add temporary capacity for collection, review and redaction when that work is explicitly in scope.
If the recurring pain is coordination and retrieval across known systems, compare the consultancy with a configured platform or managed operational service. The deciding question is who owns the source-by-source work after the advice is given.
The boundary question to ask first: “Does your scope include pulling the requester’s data out of our systems, or does it start once we hand you the export?” The answer determines whether the engagement solves your actual problem.
What do current providers publicly offer?
The category is broader than hourly advice. The DPO Centre describes advice, partial work or full outsourced support on pay-as-you-go or retainer terms. Data Driven Legal describes a lawyer-led fixed-fee service after assessment. Shoosmiths SmartSAR describes technology-assisted processing and a fixed-fee quote after data assessment. Ametros separates targeted advice, managed support and embedded support.
These are provider-reported propositions checked on 4 August 2026, not Trace endorsements or capability tests. Ask each provider for current scope, qualifications, security controls, price basis and delivery terms.
Consultancy, software, managed service
How does consultancy compare with the alternatives?
Each model leaves different work with the customer. Compare the operating boundary before comparing the headline price.
| Dimension | DSAR consultancy | Self-serve software | Managed service |
|---|---|---|---|
| What you buy | Advice, delivery capacity or both, as scoped | A licence and a workflow your team operates | An agreed operational outcome |
| Who retrieves the data | Varies; name every source and owner in scope | Connected sources automate; your team handles gaps | Provider and customer follow an agreed retrieval plan |
| Implementation | Search brief, secure transfer and matter protocol | Workflow, integrations, permissions, testing and maintenance | Scope, sources, roles, access, exceptions and delivery window |
| Review | Qualified advice can be included; check credentials and jurisdiction | Your own staff decide | An authorised privacy professional decides and approves; the operations provider prepares |
| Maintained source map | Usually scoped to the matter unless a retainer says otherwise | Your team configures and maintains it | Can be maintained inside an explicitly scoped operating boundary |
| Reusable workflow | Project learning may remain in matter files | Configured workflow can be reused by trained operators | Case method, evidence manifest and exceptions can be reused across accepted work |
| Recurring readiness | Depends on retainer scope and capacity | Depends on internal ownership and testing | Can include periodic source-map checks when explicitly contracted |
| Client ownership | Your adviser may own the matter relationship | Your team owns the requester and internal stakeholders | The privacy firm retains judgement and the client relationship |
| Pricing model | Hourly, fixed-fee, pay-as-you-go or retainer | Licence plus implementation and internal operation | Readiness, coverage and per-request preparation can be separately scoped |
| Cost drivers | Data volume, scope, seniority, review, redaction and exceptions | Licence, implementation, modules, operators and maintenance | Source count, access, unstructured volume, security and exceptions |
| Best fit | Contested, unusual or judgement-heavy matters | Repeatable volume and an internal operating owner | Fragmented operational work without platform capacity |
| Legal accountability | Stays with you as controller in every model | ||
Models can combine
Can you use a consultancy and a service together?
Yes. The models can divide along the line described on the DSAR automation page: intake, deadline tracking, mapped retrieval, evidence assembly and delivery records can follow a repeatable workflow, while identity doubt, third-party data, exemptions, privilege and final wording need authorised judgement.
One possible arrangement is an adviser for defined judgement calls plus an operational route for agreed preparation work, with a written escalation rule. Whether that split is suitable depends on the controller’s circumstances and the contracts in place.
What should the escalation rule cover?
- Requests arriving through a lawyer, a regulator or a formal complaint.
- Requests where identity doubt cannot be resolved proportionately.
- Exports containing another identifiable person’s data that cannot be cleanly separated.
- Any case where a limitation or exemption is being considered.
- Requests spanning multiple legal entities or jurisdictions.
Trace’s proposed operating model uses this boundary: Trace prepares agreed case materials and records legal questions for an authorised privacy professional rather than answering them. See how a request moves through the workflow and how a case pack is prepared for review.
The constant across all three
Who stays legally responsible?
The controller remains accountable for the response and the decisions inside it, whichever operating model supports the work.
Article 12 requires the controller to act without undue delay and in any event within one month of receipt, extendable by two further months where necessary with notice and reasons. Article 15 sets out the right of access. The European Commission also describes the one-month and identity-confirmation framework. A processor acts on documented instructions and carries its own obligations, but the controller’s responsibility does not move to a tool or service provider.
This is why every model above needs an explicit approval boundary. Advice can inform the decision. Software and services can make the work easier to coordinate and evidence. In Trace’s proposed model, Trace prepares the evidence and open questions; an authorised privacy professional retains legal judgement and approval.
Sources
Official law and provider descriptions used.
Provider pages describe their own service propositions. They are not Trace endorsements, capability tests or legal advice.
Common questions
DSAR consultancy questions, answered
General operational guidance. Trace does not provide legal advice and does not act as your adviser.