Obtainer
Blog / Checklists 9 min read

The DSAR Checklist: Every Step to Fulfill a Request on Time

Last updated July 2026 · Obtainer

Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

A DSAR checklist is a step-by-step list that walks you through every action needed to fulfill a data subject access request on time: logging the request, verifying identity, tracking the deadline, discovering the data, compiling and scoping a manifest, redacting third-party and exempt data, getting human sign-off, and delivering the response securely. Working from a checklist is how teams keep requests consistent and avoid missing a step that leads to a late or leaky response.

This is general information, not legal advice. Use the checklist below as a working template and adapt it to the law that applies and your own systems.

The DSAR checklist

#StepDone when
1Log the request and timestamp itIt is recorded in one queue with a receipt date
2Confirm it is a valid access requestYou have identified the requester and the data sought
3Verify the requester's identityYou are reasonably sure who they are
4Set and display the deadlineThe due date is visible to the team
5Discover data across all systemsEvery connected system has been searched
6Compile a manifest and scope itIn-scope items are listed and exemptions flagged
7Redact third-party and exempt dataNothing about other people remains
8Draft the response from a templatePurposes, recipients, and retention are stated
9Get human approvalA person has signed off on the disclosure
10Deliver securely and record itSent through a secure channel and logged

1 to 4: Get the request under control

The first four steps are about not losing time. Log the request the day it arrives, because a DSAR can come by email, form, phone, or chat and does not have to use formal language to count. Timestamp it, since the deadline generally starts on receipt. Verify the requester's identity proportionately before disclosing anything, and set the due date immediately. A single point of privacy request management handles the first steps, and deadline tracking keeps step four honest.

Know your deadline

Under the GDPR you have one month; under the CCPA you have 45 days. Both can be extended in limited cases, but plan for the original date. The details are in the DSAR response deadline guide, and the verification balance is covered by identity verification.

5 to 6: Find and scope the data

This is where the real work is. A person's data is spread across your CRM, help desk, billing, email, marketing tools, product database, spreadsheets, and backups. Miss one system and the response is incomplete. Automated personal data discovery searches everything at once, then you compile the results into a manifest and decide what is in scope. This is the step most likely to blow the deadline if you leave it late, so start it early.

  • Search every connected system, not just the obvious ones.
  • Include backups and archived data where they hold personal data.
  • Flag anything that may be exempt or under legal hold as you go.
  • Mark items that will need redaction so the next step is faster.

7 to 8: Protect and draft

Redact third-party names, other people's details, and any exempt or privileged material before you attach anything. An access request covers the requester's own data only. Then draft the response from a consistent template, stating the purposes, categories, recipients, and retention. Our guide on how to redact a DSAR response explains the categories, a dedicated redaction step keeps it consistent, and response templates keep your wording accurate.

9 to 10: Approve and deliver

Before anything goes out, a person reviews and approves the response and the attached data. A human review gate catches what automation missed and keeps you in control of the disclosure. Then deliver through a secure channel and record what you sent, when, and to whom.

Common ways teams fall off the checklist

The checklist only works if you follow every line. A few steps get skipped more than others, and each skip has a predictable cost.

  • Skipping the timestamp. If nobody records the receipt date, the deadline is a guess, and guesses run late.
  • Verifying too slowly. Dragging out identity checks eats into your window; keep them proportionate and prompt.
  • Searching only the obvious systems. The one tool nobody remembers is usually the one holding the data you miss.
  • Redacting under time pressure. Rushed redaction is where third-party data leaks. Reserve time for it by starting discovery early.
  • Auto-sending without sign-off. A response that goes out unreviewed is the fastest route to an accidental disclosure.

Every one of these traces back to starting the discovery-heavy steps too late. If you protect the front of the checklist, the back takes care of itself.

A quick self-check before you send

Before the response leaves your systems, run three questions past yourself. Have I found data in every system this person could appear in? Have I removed everything that belongs to someone else? Has a person actually approved this disclosure? If any answer is no, the checklist is not finished, however close the deadline is. This final pass is the cheapest safeguard you have, and it catches the mistakes that are expensive to fix after the fact.

Turn the checklist into a repeatable process

A checklist is most useful when it is the same every time. Running each request through the identical steps is what makes DSARs routine instead of stressful, and it produces a record you can point to if a regulator asks. For the reasoning behind each step, see the DSAR process guide, and for the full sequence written out, the how to respond to a data subject access request walkthrough covers each action in depth.

Want the checklist built into the workflow so nothing gets skipped? Obtainer runs each request through the same steps, from timestamped intake to a review gate, and tracks the deadline throughout. DSAR automation handles discovery and drafting while you redact and approve what gets disclosed.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.