The DSAR Checklist: Every Step to Fulfill a Request on Time
Last updated July 2026 · Obtainer
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
A DSAR checklist is a step-by-step list that walks you through every action needed to fulfill a data subject access request on time: logging the request, verifying identity, tracking the deadline, discovering the data, compiling and scoping a manifest, redacting third-party and exempt data, getting human sign-off, and delivering the response securely. Working from a checklist is how teams keep requests consistent and avoid missing a step that leads to a late or leaky response.
This is general information, not legal advice. Use the checklist below as a working template and adapt it to the law that applies and your own systems.
The DSAR checklist
| # | Step | Done when |
|---|---|---|
| 1 | Log the request and timestamp it | It is recorded in one queue with a receipt date |
| 2 | Confirm it is a valid access request | You have identified the requester and the data sought |
| 3 | Verify the requester's identity | You are reasonably sure who they are |
| 4 | Set and display the deadline | The due date is visible to the team |
| 5 | Discover data across all systems | Every connected system has been searched |
| 6 | Compile a manifest and scope it | In-scope items are listed and exemptions flagged |
| 7 | Redact third-party and exempt data | Nothing about other people remains |
| 8 | Draft the response from a template | Purposes, recipients, and retention are stated |
| 9 | Get human approval | A person has signed off on the disclosure |
| 10 | Deliver securely and record it | Sent through a secure channel and logged |
1 to 4: Get the request under control
The first four steps are about not losing time. Log the request the day it arrives, because a DSAR can come by email, form, phone, or chat and does not have to use formal language to count. Timestamp it, since the deadline generally starts on receipt. Verify the requester's identity proportionately before disclosing anything, and set the due date immediately. A single point of privacy request management handles the first steps, and deadline tracking keeps step four honest.
Know your deadline
Under the GDPR you have one month; under the CCPA you have 45 days. Both can be extended in limited cases, but plan for the original date. The details are in the DSAR response deadline guide, and the verification balance is covered by identity verification.
5 to 6: Find and scope the data
This is where the real work is. A person's data is spread across your CRM, help desk, billing, email, marketing tools, product database, spreadsheets, and backups. Miss one system and the response is incomplete. Automated personal data discovery searches everything at once, then you compile the results into a manifest and decide what is in scope. This is the step most likely to blow the deadline if you leave it late, so start it early.
- Search every connected system, not just the obvious ones.
- Include backups and archived data where they hold personal data.
- Flag anything that may be exempt or under legal hold as you go.
- Mark items that will need redaction so the next step is faster.
7 to 8: Protect and draft
Redact third-party names, other people's details, and any exempt or privileged material before you attach anything. An access request covers the requester's own data only. Then draft the response from a consistent template, stating the purposes, categories, recipients, and retention. Our guide on how to redact a DSAR response explains the categories, a dedicated redaction step keeps it consistent, and response templates keep your wording accurate.
9 to 10: Approve and deliver
Before anything goes out, a person reviews and approves the response and the attached data. A human review gate catches what automation missed and keeps you in control of the disclosure. Then deliver through a secure channel and record what you sent, when, and to whom.
Common ways teams fall off the checklist
The checklist only works if you follow every line. A few steps get skipped more than others, and each skip has a predictable cost.
- Skipping the timestamp. If nobody records the receipt date, the deadline is a guess, and guesses run late.
- Verifying too slowly. Dragging out identity checks eats into your window; keep them proportionate and prompt.
- Searching only the obvious systems. The one tool nobody remembers is usually the one holding the data you miss.
- Redacting under time pressure. Rushed redaction is where third-party data leaks. Reserve time for it by starting discovery early.
- Auto-sending without sign-off. A response that goes out unreviewed is the fastest route to an accidental disclosure.
Every one of these traces back to starting the discovery-heavy steps too late. If you protect the front of the checklist, the back takes care of itself.
A quick self-check before you send
Before the response leaves your systems, run three questions past yourself. Have I found data in every system this person could appear in? Have I removed everything that belongs to someone else? Has a person actually approved this disclosure? If any answer is no, the checklist is not finished, however close the deadline is. This final pass is the cheapest safeguard you have, and it catches the mistakes that are expensive to fix after the fact.
Turn the checklist into a repeatable process
A checklist is most useful when it is the same every time. Running each request through the identical steps is what makes DSARs routine instead of stressful, and it produces a record you can point to if a regulator asks. For the reasoning behind each step, see the DSAR process guide, and for the full sequence written out, the how to respond to a data subject access request walkthrough covers each action in depth.
Want the checklist built into the workflow so nothing gets skipped? Obtainer runs each request through the same steps, from timestamped intake to a review gate, and tracks the deadline throughout. DSAR automation handles discovery and drafting while you redact and approve what gets disclosed.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.