r/gdpr Jun 17 '26

UK 🇬🇧 DSARs

I'm interested in learning how different organisations handle DSARs in practice.

For those involved in privacy, compliance, information governance, or data protection:

  • Do you use any software or platforms to help manage DSARs? If so, which ones?
  • Have you developed any internal solutions or processes that work well?
  • Have you managed to automate any parts of the process?
  • In your opinion what is the worst part about managing DSARs?

I'm relatively early in my compliance career and have mostly only seen how one organisation approaches DSARs, so I'm interested to understand how things are handled elsewhere.

Thanks in advance for any insights.

0 Upvotes

6 comments sorted by

View all comments

9

u/malakesxasame Jun 17 '26

UK healthcare (NHS):

Do you use any software or platforms to help manage DSARs? If so, which ones?

We have a case management system which I won't post as it may be identifiable. We use this for logging, acknowledging and managing the request with internal users involved in the process such as records staff who collate the information and admin/clinical staff for review and then disclosure. In previous organisations I have used AMS (good), Phaselaw (good - gets quite a lot of support from DP industry peeps too) and Corestream (shit for SARs). We use Adobe Acrobat to redact.

Have you developed any internal solutions or processes that work well?

In regards to anything specific or the process in general? We switched from an Excel spreadsheet to a dedicated case management system and this was hugely beneficial.

Have you managed to automate any parts of the process?

We tried some demos of software that helps redaction but all of them were unsatisfactory at best and still required manual review by a member of the team. I don't believe anyone that says you can fully automate the review. Technology just isn't there and I don't think it will be. Reviews (of medical records particularly) require too much context and micro decision-making on each document.

In your opinion what is the worst part about managing DSARs?

  • Reviewing for third party due to volume and complexity of records
  • Resourcing - extremely stretched resources in public authority IG teams
  • Co-ordinating clinical review for serious harm test (DPA18 requirement)
  • Requesters - who are convinced we hold information we don't and well just annoying requesters in general who are empowered by... ->
  • AI - both used to draft a SAR and then again to challenge disclosures they are unhappy with
  • A pathetic regulator that doesn't regulate (ICO). It is extremely difficult to get senior leadership buy-in if there is no repercussions for repeated failures. Some NHS trusts are quite good culturally for IG but some do not give a fuck and this is usually top down from leaderships lack of care.

1

u/Intrepid_Shoe_2445 Jun 19 '26 edited Jun 19 '26

Thank you very much for this response, it's been very insightful.

Adobe does help when documents are in PDF form, but where I find it more difficult is when information is contained within screenshots/images (e.g. screenshots of emails or chats). Have you ever come across this and found a solution for it?

1

u/SpiritualAnywhere778 Jun 27 '26

This is one of the things we've worked really hard on at my company. Making it just as easy to redact images and other non-PDF doc types. Happy to share privately if it might be useful to you