Can it preserve the original request?
Channel, wording, received time, request type and later scope changes should remain visible.
DSAR software · Buyer guide
DSAR software should do more than open a ticket. It should show what was requested, where the data was found, what remains uncertain, who approved the response and what evidence was retained.
What is DSAR software?
DSAR software helps manage the lifecycle of a data subject access request: intake, identity checks, finding the requester’s data across systems, human review and a recorded response. A buyer should compare it with three alternatives — a manual internal process, a consultancy and a managed service. None transfers the controller’s responsibility for the answer.
A practical definition
It connects a legal request to the operational evidence and decisions needed for a response. The best buying test is not the number of rights or connectors on a feature grid. It is whether one real request can move from intake to approved output without losing context.
DSAR is commonly used for a data subject access request. Some products use it more broadly for data subject rights requests. Trace names the right explicitly in each case so an access request is not confused with erasure, rectification or another right.
The GDPR gives individuals a right of access in Article 15. Article 12 sets general conditions for facilitating rights and responding. A tool may structure that work, but the controller remains accountable for the response and any case-specific decisions.
Eight buying questions
Ask these eight questions using one representative request. A polished portal is useful only if the underlying case can survive source gaps, reviewer questions and a later audit.
Channel, wording, received time, request type and later scope changes should remain visible.
Identity state, rationale and customer action should be explicit—not a generic “verified” switch.
The case should show which sources were checked, which identifiers were used and what each search could not establish.
An unsupported source should become an owned, visible task—not disappear from the final export.
Third-party data, exemptions, retention and final wording need a documented approval boundary.
Ask about read-only methods, customer-run queries, time limits, revocation and where request data is processed.
Get the internal hours, integrations, testing, change management and exception work—not only the subscription or project fee.
Evidence needs source context, open issues, an approval history, a response draft, secure delivery and agreed retention.
Four operating models
The right model depends on who owns the case, who implements the workflow, who retrieves the data and who can make the final decisions. Compare the work left with your team, not the number of boxes ticked in a feature list.
| Dimension | Manual internal process | Enterprise privacy platform | Privacy consultancy | Managed service |
|---|---|---|---|---|
| Operational owner | Your named case owner coordinates every team | Your privacy or operations team runs the configured platform | Defined by the engagement: advice, overflow or full matter support | The provider coordinates the agreed workflow; your owner enables access |
| Implementation | Inbox, case log, source map, templates and internal procedure | Workflow, identifiers, integrations, permissions, testing and ongoing changes | Scope, search brief, secure transfer and working protocol per engagement | Request scope, sources, roles, access, exceptions and delivery window |
| Retrieval | Your source owners search and export | Mapped integrations automate some sources; unsupported sources need another path | Varies materially; confirm whether collection is included | Provider and customer follow the agreed source-by-source retrieval plan |
| Review and judgement | Your own staff or adviser | Your own staff, using the platform record | Advisory or legal review can be included when explicitly contracted | The provider prepares the case; an authorised privacy professional decides and approves |
| Hidden costs | Coordination, engineering interruption, missed context and repeated discovery | Implementation, security review, integration maintenance, modules and internal operators | Data preparation, transfer, document volume, seniority and out-of-scope work | Security onboarding, extra sources, unstructured volume and scope exceptions |
| Best fit | Low volume, few known sources and a capable internal owner | Repeated volume, a broader privacy programme and named operators | Contested, unusual or judgement-heavy matters | An active operational problem across fragmented sources without platform capacity |
| Controller responsibility | The controller remains responsible for the response in every model | |||
Public product documentation supports the distinction above. OneTrust and DataGrail describe request workflows and integrations on their product pages. Transcend documents automated actions across connected systems. MineOS explicitly documents automatic, manual and coworker-assigned handling per source.
Lighter platforms including Ketch and Enzuzo publish platform tiers, while service providers document different commercial shapes: The DPO Centre describes pay-as-you-go and retained support, and Shoosmiths SmartSAR describes a fixed-fee quote after scope and data assessment. These are provider-reported pages, not Trace product tests or recommendations. Capabilities, limits and prices should be verified directly.
Compare the same scope across models: intake, implementation, source mapping, retrieval, unsupported sources, review, secure delivery, retention and ongoing maintenance. A monthly platform price is not comparable with a per-matter service quote until the work left with your team is included.
Trace’s model under validation: a paid Readiness Sprint maps up to three systems and rehearses one synthetic request. Planned ongoing operations would prepare evidence and open decisions for an authorised privacy professional; production availability is not implied.
Sources
Legal statements use official EU sources. Vendor capabilities are described from provider documentation and are not Trace endorsements or product tests.
Before the shortlist
Use one real workflow to compare coverage, internal effort and the decisions that stay with your team.
Founding design partners
The proposed Readiness Sprint maps up to three systems and rehearses one synthetic request. Any paid work begins only after scope, capacity, roles and data handling are agreed in writing.