DSAR consultancy · Buyer guide
DSAR consultancy: when hourly advice is the right answer
Advisory fees buy judgement, not throughput. That is exactly right for a contested request and exactly wrong for the fifth routine one this quarter.
What does a DSAR consultancy do?
A DSAR consultancy provides expert advice on handling data subject access requests: scoping the request, assessing exemptions, deciding what to withhold and drafting the response. Engagements are usually hourly or per matter. Advisory scope rarely includes retrieving the data from your systems, and the controller keeps legal accountability either way.
Match the model to the problem
When is a DSAR consultancy the right choice?
Hire advice when the difficulty is legal. A consultancy earns its fee on the request that does not fit the template: one arriving through a solicitor, one where an exemption might apply, one spanning several legal entities, or one already in front of a supervisory authority. These are judgement problems, and judgement is what you are buying.
Do not hire advice for throughput. If the pain is that three engineers spend a day each quarter exporting records from four systems, an hourly adviser does not touch the cost — retrieval usually sits outside advisory scope, so you pay for the analysis and still do the work.
The boundary question to ask first: “Does your scope include pulling the requester’s data out of our systems, or does it start once we hand you the export?” The answer determines whether the engagement solves your actual problem.
Why doesn’t the second request get cheaper?
Advisory work is priced per matter, so the economics do not improve with volume unless someone captures the process — the source map, the identifiers, the decisions taken last time and the reasons. Without that record, request five costs roughly what request one cost, and the institutional knowledge leaves with the invoice.
Consultancy, software, managed service
How does consultancy compare with the alternatives?
The three models fail in different places. Choose by which failure you can least afford.
| Dimension | DSAR consultancy | Self-serve software | Managed service |
|---|---|---|---|
| What you buy | Judgement, per matter | A licence and a workflow | Prepared cases |
| Who retrieves the data | Your team, almost always | Your team, via connectors | The provider, with agreed access |
| Cost per request at volume | Roughly flat | Falls after setup | Falls after scoping |
| Handles a contested request | Its core strength | Not designed for it | Escalates to your adviser |
| Leaves a reusable record | Only if contracted | Yes, once configured | Intended core deliverable |
| Runs out when | Volume rises | The case is unusual | The question is purely legal |
| Legal accountability | Stays with you as controller in every model | ||
Not actually a choice
Can you use a consultancy and a service together?
Usually you should. The two models divide cleanly along the line drawn on the DSAR automation page: the operational steps — intake, deadline tracking, source discovery, retrieval, evidence assembly, delivery records — are repeatable, while identity doubt, third-party redaction, exemptions and final wording are not.
A practical arrangement is a retained adviser for the hard calls plus an operational route for the routine work, with a standing rule for which requests get escalated. Agree that rule before the first difficult request arrives, not during it.
What should the escalation rule cover?
- Requests arriving through a lawyer, a regulator or a formal complaint.
- Requests where identity doubt cannot be resolved proportionately.
- Exports containing another identifiable person’s data that cannot be cleanly separated.
- Any case where a limitation or exemption is being considered.
- Requests spanning multiple legal entities or jurisdictions.
Trace’s proposed model assumes this split: it prepares the case and routes legal questions to your adviser rather than answering them. See how a request moves through the workflow and how a case pack is prepared for review.
The constant across all three
Who stays legally responsible?
You do. Under the GDPR the controller is accountable for the response and for the decisions inside it, whichever model delivers the work.
Article 12 requires the controller to act without undue delay and in any event within one month of receipt, extendable by two further months where necessary with notice and reasons. Article 15 sets out what must be provided. A processor acts on documented instructions and carries its own obligations, but the controller’s accountability does not move.
This is why every model above ends at the same place: a named person on your side approves what is sent. Advice can inform that decision and evidence your diligence. Software can make the deadline easier to meet and the work easier to prove. Neither answers for the response.
Common questions
DSAR consultancy questions, answered
General operational guidance. Trace does not provide legal advice and does not act as your adviser.