DSAR consultancy · Buyer guide

DSAR Consultancy vs Managed DSAR Operations

A DSAR consultancy can provide advice, overflow support or a fully outsourced matter. The useful question is not the label; it is which retrieval, review and delivery responsibilities are in scope.

What does a DSAR consultancy do?

A DSAR consultancy can provide advice, overflow capacity, redaction or an outsourced response process. Commercial models include scoped projects, fixed fees, pay-as-you-go work and retainers. Confirm who retrieves, reviews, drafts and delivers; the controller remains responsible for the response.

Match the model to the problem

When is a DSAR consultancy the right choice?

Start with the risk and the missing capability. A qualified adviser is a strong fit when a request does not fit the standard procedure: it is contested, litigation-adjacent, spans legal entities, may involve exemptions or privilege, or has already reached a regulator. A delivery consultancy can also add temporary capacity for collection, review and redaction when that work is explicitly in scope.

If the recurring pain is coordination and retrieval across known systems, compare the consultancy with a configured platform or managed operational service. The deciding question is who owns the source-by-source work after the advice is given.

The boundary question to ask first: “Does your scope include pulling the requester’s data out of our systems, or does it start once we hand you the export?” The answer determines whether the engagement solves your actual problem.

What do current providers publicly offer?

The category is broader than hourly advice. The DPO Centre describes advice, partial work or full outsourced support on pay-as-you-go or retainer terms. Data Driven Legal describes a lawyer-led fixed-fee service after assessment. Shoosmiths SmartSAR describes technology-assisted processing and a fixed-fee quote after data assessment. Ametros separates targeted advice, managed support and embedded support.

These are provider-reported propositions checked on 4 August 2026, not Trace endorsements or capability tests. Ask each provider for current scope, qualifications, security controls, price basis and delivery terms.

Consultancy, software, managed service

How does consultancy compare with the alternatives?

Each model leaves different work with the customer. Compare the operating boundary before comparing the headline price.

Scope, implementation and customer responsibilities in each model
DimensionDSAR consultancySelf-serve softwareManaged service
What you buyAdvice, delivery capacity or both, as scopedA licence and a workflow your team operatesAn agreed operational outcome
Who retrieves the dataVaries; name every source and owner in scopeConnected sources automate; your team handles gapsProvider and customer follow an agreed retrieval plan
ImplementationSearch brief, secure transfer and matter protocolWorkflow, integrations, permissions, testing and maintenanceScope, sources, roles, access, exceptions and delivery window
ReviewQualified advice can be included; check credentials and jurisdictionYour own staff decideAn authorised privacy professional decides and approves; the operations provider prepares
Maintained source mapUsually scoped to the matter unless a retainer says otherwiseYour team configures and maintains itCan be maintained inside an explicitly scoped operating boundary
Reusable workflowProject learning may remain in matter filesConfigured workflow can be reused by trained operatorsCase method, evidence manifest and exceptions can be reused across accepted work
Recurring readinessDepends on retainer scope and capacityDepends on internal ownership and testingCan include periodic source-map checks when explicitly contracted
Client ownershipYour adviser may own the matter relationshipYour team owns the requester and internal stakeholdersThe privacy firm retains judgement and the client relationship
Pricing modelHourly, fixed-fee, pay-as-you-go or retainerLicence plus implementation and internal operationReadiness, coverage and per-request preparation can be separately scoped
Cost driversData volume, scope, seniority, review, redaction and exceptionsLicence, implementation, modules, operators and maintenanceSource count, access, unstructured volume, security and exceptions
Best fitContested, unusual or judgement-heavy mattersRepeatable volume and an internal operating ownerFragmented operational work without platform capacity
Legal accountabilityStays with you as controller in every model

Models can combine

Can you use a consultancy and a service together?

Yes. The models can divide along the line described on the DSAR automation page: intake, deadline tracking, mapped retrieval, evidence assembly and delivery records can follow a repeatable workflow, while identity doubt, third-party data, exemptions, privilege and final wording need authorised judgement.

One possible arrangement is an adviser for defined judgement calls plus an operational route for agreed preparation work, with a written escalation rule. Whether that split is suitable depends on the controller’s circumstances and the contracts in place.

What should the escalation rule cover?

  • Requests arriving through a lawyer, a regulator or a formal complaint.
  • Requests where identity doubt cannot be resolved proportionately.
  • Exports containing another identifiable person’s data that cannot be cleanly separated.
  • Any case where a limitation or exemption is being considered.
  • Requests spanning multiple legal entities or jurisdictions.

Trace’s proposed operating model uses this boundary: Trace prepares agreed case materials and records legal questions for an authorised privacy professional rather than answering them. See how a request moves through the workflow and how a case pack is prepared for review.

The constant across all three

Who stays legally responsible?

The controller remains accountable for the response and the decisions inside it, whichever operating model supports the work.

Article 12 requires the controller to act without undue delay and in any event within one month of receipt, extendable by two further months where necessary with notice and reasons. Article 15 sets out the right of access. The European Commission also describes the one-month and identity-confirmation framework. A processor acts on documented instructions and carries its own obligations, but the controller’s responsibility does not move to a tool or service provider.

This is why every model above needs an explicit approval boundary. Advice can inform the decision. Software and services can make the work easier to coordinate and evidence. In Trace’s proposed model, Trace prepares the evidence and open questions; an authorised privacy professional retains legal judgement and approval.

Sources

Official law and provider descriptions used.

Provider pages describe their own service propositions. They are not Trace endorsements, capability tests or legal advice.

Common questions

DSAR consultancy questions, answered

General operational guidance. Trace does not provide legal advice and does not act as your adviser.

What is a DSAR consultancy?
A DSAR consultancy is a privacy advisory or delivery provider that helps an organisation handle data subject access requests. Public services range from advice and oversight to overflow support, redaction and full outsourced matter handling. The label alone does not define what is included, so the retrieval, review, delivery and legal-advice boundaries must be written into scope.
When should you hire a DSAR consultancy instead of buying software?
A qualified adviser is a strong fit when a request is contested, litigation-adjacent, crosses legal entities or raises exemptions, privilege or regulatory questions. Software is a stronger candidate when the workflow is repeatable, volume supports implementation and your team can operate and review the system. Some buyers combine both.
How much does a DSAR consultancy cost?
There is no comparable public market price. Current public service pages show pay-as-you-go, retainer and fixed-fee-after-scope models, while other providers quote privately. Compare data volume, retrieval, hosting or transfer, review, redaction, seniority, response drafting, delivery and exception work before comparing the headline fee.
Does a consultancy handle the data retrieval too?
It depends on the provider and engagement. Some public services include collection coordination, processing and redaction; advice-only work may start after your team produces the records. Confirm who searches each system, who exports the data, where it is transferred, which formats are included and what happens when the search scope changes.
Can a consultancy take over legal responsibility for the response?
No. Under the GDPR the controller remains accountable for the response and the decisions in it. Advice can inform those decisions and can be evidence of diligence, but accountability does not transfer to an adviser, a processor or a tool.
What is the difference between a DSAR consultancy and a managed service?
The difference is contractual scope, not the label. A consultancy may sell advice, delivery or both. A managed service is judged by the operational outcome it owns. Ask who retrieves, who reviews, who drafts, who delivers and which decisions remain with the customer.
Is Trace a consultancy?
No. Trace does not provide legal advice or representation. It is validating managed data-rights operations that prepare source maps, evidence and open questions for an authorised privacy professional. The professional retains legal judgement, approval and the client relationship.

Founding design partners

Separate the operational work from the legal decision.

The proposed Readiness Sprint maps up to three systems and rehearses one synthetic request. Trace does not provide legal advice, and no live personal data should be sent through the public site.