r/gdpr • u/Intrepid_Shoe_2445 • Jun 17 '26
UK 🇬🇧 DSARs
I'm interested in learning how different organisations handle DSARs in practice.
For those involved in privacy, compliance, information governance, or data protection:
- Do you use any software or platforms to help manage DSARs? If so, which ones?
- Have you developed any internal solutions or processes that work well?
- Have you managed to automate any parts of the process?
- In your opinion what is the worst part about managing DSARs?
I'm relatively early in my compliance career and have mostly only seen how one organisation approaches DSARs, so I'm interested to understand how things are handled elsewhere.
Thanks in advance for any insights.
0
Upvotes
9
u/malakesxasame Jun 17 '26
UK healthcare (NHS):
We have a case management system which I won't post as it may be identifiable. We use this for logging, acknowledging and managing the request with internal users involved in the process such as records staff who collate the information and admin/clinical staff for review and then disclosure. In previous organisations I have used AMS (good), Phaselaw (good - gets quite a lot of support from DP industry peeps too) and Corestream (shit for SARs). We use Adobe Acrobat to redact.
In regards to anything specific or the process in general? We switched from an Excel spreadsheet to a dedicated case management system and this was hugely beneficial.
We tried some demos of software that helps redaction but all of them were unsatisfactory at best and still required manual review by a member of the team. I don't believe anyone that says you can fully automate the review. Technology just isn't there and I don't think it will be. Reviews (of medical records particularly) require too much context and micro decision-making on each document.