An email arrives asking for everything you hold
A former customer, an unhappy employee or someone in a dispute sends a subject access request. Under UK GDPR they are entitled to a copy of their personal data, and the clock is running. Whoever handles data protection opens a checklist and starts logging into systems.
The CRM, the helpdesk, Xero, the email archive, the HR system, the booking tool, the marketing platform, a shared drive full of spreadsheets, and a call recording system nobody has opened in a while. Each search uses a different screen and a different way of finding a person. Some results are exports, some are screenshots, and the pile grows in a folder on someone's desktop.
Why every request is a scavenger hunt
Most businesses never mapped where personal data lives, because each system was adopted separately. The person handling the request has to remember every place a customer's name might appear, and search each one with whatever identifiers that system uses.
| System | Why it is awkward to search |
|---|---|
| CRM and helpdesk | Person may appear under several emails or as a contact on another record |
| Email and shared mailboxes | Mentions in other people's messages, attachments |
| Accounts package | Stored under a company or billing name |
| Shared drives and spreadsheets | No search by person, files scattered |
| Old or retired systems | Data still exists but access is clumsy |
Then comes the hard part: deciding what to include, what belongs to other people and needs redacting, and what is exempt. That needs human judgement. The searching and gathering does not.
What a manual process costs
- Staff time pulled from normal work for every request
- Risk of missing a system and giving an incomplete response
- Risk of including someone else's personal data by mistake
- Pressure on the statutory deadline when requests arrive together
- No consistent record of what was searched and why
Requests often arrive when relationships have already gone wrong, such as during an employment dispute or a complaint. An incomplete or careless response can make the dispute worse and draw a complaint to the ICO.
The same scattered data also makes erasure requests hard. If you cannot find everything to disclose it, you cannot reliably find everything to delete it either.
How we build a subject access request tool
- We map where personal data lives with you: every system, what it holds, and how a person can be identified in it. This map is useful in its own right for your records of processing.
- We connect to each system that has an API, such as HubSpot, Salesforce, Zendesk, Xero, Microsoft 365 or Google Workspace, with read-only access.
- A request screen lets the handler enter the person's known identifiers: names, emails, phone numbers, account numbers. The tool searches every connected system and lists what it finds, grouped by source.
- For systems without an API, the tool shows a checklist item with instructions, so manual searches are recorded alongside the automatic ones.
- The handler reviews each result, marks it include or exclude, and records the reason. Suggested redactions of other people's names and emails are highlighted for a person to accept or reject.
- The tool produces a structured export and a log of what was searched, when and by whom, which you keep as your record.
- The same search can support an erasure request, listing where the person's data sits so each deletion can be actioned and recorded.
The tool helps gather and organise. Decisions about exemptions and what to disclose stay with your team and your legal advisers. This is general guidance, not legal advice.
A request that is a task, not a crisis
When a request arrives, the handler logs it, runs one search and works through a single review screen. Nothing depends on remembering every system. The export is consistent, the log shows what was checked, and the handler's time goes on the judgement calls rather than on logging into a dozen tools.
Adding a new system to the business means adding it to the map and the connector list, so requests stay complete as your tools change.
Is this how requests feel for you?
- Each subject access request means searching many systems by hand
- Nobody is certain every system has been checked
- Requests have come close to the deadline
- There is no record of what was searched for past requests
- Erasure requests are handled with the same uncertainty