Operations checklist · 10 min read
A review-ready DSAR response checklist
Use this checklist to control the case from receipt to approved delivery. It is designed to expose missing sources and open decisions—not to turn a legal response into a box-ticking exercise.
What should a DSAR response cover?
A defensible DSAR response records eight things: the original request, the right and scope, a proportionate identity decision, a source-by-source discovery plan, assembled records with provenance, a human review of third-party data and exemptions, secure delivery, and an audit trail of what was done and why.
Before you begin
What this checklist is for.
A data subject access request engages the right in Article 15 GDPR and the general conditions in Article 12. The controller must assess the actual request and processing context. This checklist covers the operational record needed to support that assessment; it does not determine what the law requires in a particular case.
A useful case has three qualities:
- coverage: the source map explains what was checked and what was not;
- provenance: every output can be traced to a system, retrieval step and time; and
- decision ownership: identity, third-party information, scope and final response have named reviewers.
Review-ready does not mean legally complete. A pack can be organised and still contain open identity questions, unavailable sources or decisions that must be resolved before a response is sent.
01 / Intake and ownership
Preserve the request before interpreting it.
The original message is part of the evidence. Keep it intact while the organisation decides which right or rights are being exercised.
- Store the original wording, attachments and channel.
- Record the received timestamp and the entity or service that received it.
- Assign a case ID and accountable owner.
- Calculate and independently review the response target.
- Record related requests, previous responses and scope changes.
- Send an acknowledgement where appropriate without implying it resets the legal clock.
Article 12 requires action without undue delay and generally within one month. Read the operational deadline guide and the official EDPB explanation.
02 / Right, scope and identity
Classify without narrowing by accident.
Record what the individual asked, what the organisation understands and any clarification separately. Access, erasure, rectification and other rights are not interchangeable.
- Name each right that may be engaged and the reviewer who confirmed it.
- Identify products, accounts, date ranges and legal entities plausibly in scope.
- Record the known identifiers and how they were validated.
- Assess whether there are reasonable doubts about requester identity.
- If more information is necessary, document the doubt, requested fields and secure channel.
- Keep clarification messages and resulting scope changes in the timeline.
Use the proportionate identity-verification guide. Article 12(6) is available in the official GDPR text.
03 / Source discovery
Create the search plan before collecting files.
The source inventory is the control surface. It connects identifiers, systems, owners and retrieval methods while making gaps impossible to hide.
Name the source
Environment, project, workspace, account or database—not only the vendor name.
Assign access
Who can approve and execute retrieval, and who validates the result?
Define the lookup
User ID, customer ID, email, tenant key, object path or reviewed join.
Choose the narrow path
Customer-run query, controlled export, read-only API or time-limited scoped access.
State the limitation
Unavailable history, deleted accounts, archived data, unlinked records or manual systems.
Follow relevant copies
Billing, support, CRM, storage, warehouse and custom backend relationships in scope.
Integration status matters. Trace currently labels Firebase, Supabase and Stripe as Pilot mapping—not live one-click connectors. See the integration-readiness directory.
04 / Evidence assembly
Keep context attached to every record.
A pile of exports is not a response pack. Organise records so a reviewer can understand their source, meaning, limits and relationship to the request.
- Record query, export or retrieval time and responsible operator.
- Preserve source names and stable record identifiers.
- Separate original fields from normalised labels or commentary.
- Reconcile duplicate identities and explain unresolved ambiguity.
- Flag third-party information, secrets, credentials and internal security material.
- Document missing, failed or partial retrievals.
- Create a readable index for non-technical reviewers.
Under Article 15 GDPR, the access response includes more than a copy of personal data; it also includes specified information about the processing. The final content and format require case-specific review.
05 / Human review
Put every judgement call on the record.
Trace is designed to assemble and flag. An authorised reviewer decides what is disclosed, withheld, corrected, retained or acted on.
- Confirm identity state and whether disclosure may proceed.
- Check the source inventory against the scope and known data map.
- Review third-party information and the rights and freedoms of others.
- Review any applicable limitations, retention questions and legal grounds.
- Confirm the Article 15 information is complete and intelligible.
- Review response language, secure delivery route and requester instructions.
- Name the approver, decision time and any remaining condition.
No autonomous legal decision: a generated draft is a starting point. It must not be sent merely because a workflow status changed to “ready.”
06 / Delivery and retention
Close the operational loop.
- Use the approved delivery channel and verify the destination.
- Record exactly which files and response version were sent.
- Store delivery time, result and evidence of transmission.
- Record follow-up questions, corrections or failed access.
- Revoke temporary source access and rotate credentials where required.
- Apply the approved retention schedule to working files, identity evidence and the final case record.
- Confirm deletion of temporary copies where the procedure requires it.
Retention is not one universal number. It must be set by the controller after legal, security and operational review and reflected in the accepted service terms and DPA before Trace handles a live case.
The minimum review-ready pack
- case summary and request classification;
- identity state and rationale;
- source inventory and known gaps;
- organised evidence export;
- draft response and required processing information;
- exception, third-party and retention notes;
- decision checklist and named reviewer; and
- timestamped event timeline.
Official EU references
Sources used for legal statements.
- EUR-Lex — Regulation (EU) 2016/679, Article 12
- EUR-Lex — Regulation (EU) 2016/679, Article 15
- European Data Protection Board — Guidelines 01/2022 on the right of access
- European Commission — Dealing with individuals’ requests
Editorial method: legal statements are paraphrased from official EU sources. Checklist items are operational guidance, not a substitute for qualified legal, privacy or security review.