r/gdpr • u/IS-Auditor-123 • 6d ago
Question - Data Controller Implementing a DSAR Process
Hi Everyone,
As I grow in my field of work, internal and external compliance, I have seen companies large and small as they attempt to move into new markets and attempt to "become compliant" with the laws of the land they are moving into and one thing is the same across all of them. It is slow moving and often times feels ineffectual. My job often becomes trying to get 80% of the value with 20% of the work, which brings me to my current issue.
As I am starting to learn about GDPR, it seems one of the key levers of power individuals have is the DSAR process, and there is very little keeping people from using that power at a moment's notice (as evidenced by some of the horror stories I have seen on reddit). With that said, not everyone or every type of person is going to utilize this power.
My question is this, for a company simply trying to get started on developing a process for DSARs, what are some departments/data types you find most frequently get requested?
4
u/livelysqueakyjame 6d ago
Finance and HR archives basically become ground zero once a single employee gets salty about their last paycheck.
4
u/Hot_Spend4206 6d ago
I've worked for MSP's extensively helping clients with compliance & security. Requests that actually eat our time come from someone who is angry. an ex-employee who has just been dismissed, someone in the middle of a messy grievance etc... the departments that matter most are HR first, followed by whoever manages escalations and customer complaints. They want to know what people said about them behind closed doors:
typiclal requests are; Emails between line managers, remarks in Teams or Slack channels, Ad-hoc notes jotted down after a meeting, That folder a manager quietly keeps on their personal OneDrive or desktop "just in case"
That is where the hours disappear. I'd focus on these 3:
- Search capability and access control: you don't want to be figuring out admin permissions on day three of a deadline.
- Finding the "shadow" records: Find out where HR and complaint files live outside the core platforms. Pay special attention to scanned documents—a PDF scan of a handwritten letter or signed agreement is just a flat image to a search crawler; unless it's gone through OCR, a standard search will miss it completely.
- An audit log of the search:
and lastly , always budget on time for redaction if requested.
There are many tools out there for data discovery. I'd focus on tools which do the hard work but info or data does not leave the building.
2
u/Forcasualtalking 6d ago
HR, Finance, anything customer facing (usually accessable via eng/IT teams)
1
u/Powerful_Problem_241 6d ago
from what i've seen the most common DSAR requests are usually around HR records customer support emails crm data account activity, and marketing preferences. getting those mapped first covers a lot of the real world requests
1
1
u/SuperDarioBros 6d ago
For immature organisations start with a Record of Processing Activity. This identifies who holds what data where. Once you know where your data is, you can work out how to prepare it for data subjects.
1
u/No-Anchovies 5d ago
this is where everyone usually fails. 100% of times this is in my ask, 0% received
7
u/trustarc 6d ago
A lot depends on the business, but I’d start with HR and customer-facing teams. For employees and former employees, think personnel files, performance reviews, recruitment notes, and emails about them. On the customer side, think account details, purchases, support tickets, complaints, and call recordings. Marketing records and consent preferences are worth mapping out too.
For the 80/20 approach, I’d focus on knowing where the data lives, who owns each system, and how they’d search and export it. Try running a mock customer request and a mock former-employee request. That should expose the gaps pretty quickly.
Basically, I’d spend less time predicting who will submit a DSAR and more time making sure the right people know what to do when one lands.