Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. How Do We Answer a Subject Access Request When the Person's Data Is Spread Across a Dozen Systems?
Problems We Solve

How Do We Answer a Subject Access Request When the Person's Data Is Spread Across a Dozen Systems?

A subject access request that needs data from many systems turns into a week of searching. SpiderHunts builds a search and export across your systems.

Updated 3 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Subject access requests are painful when personal data sits in a CRM, inbox, helpdesk, accounts package, shared drives and old spreadsheets, and someone has to search each by hand. SpiderHunts builds a request tool that searches your connected systems by name, email and account ID, gathers the results into one review screen and produces an export for a person to check and redact before it is sent.

An email arrives asking for everything you hold

A former customer, an unhappy employee or someone in a dispute sends a subject access request. Under UK GDPR they are entitled to a copy of their personal data, and the clock is running. Whoever handles data protection opens a checklist and starts logging into systems.

The CRM, the helpdesk, Xero, the email archive, the HR system, the booking tool, the marketing platform, a shared drive full of spreadsheets, and a call recording system nobody has opened in a while. Each search uses a different screen and a different way of finding a person. Some results are exports, some are screenshots, and the pile grows in a folder on someone's desktop.

Why every request is a scavenger hunt

Most businesses never mapped where personal data lives, because each system was adopted separately. The person handling the request has to remember every place a customer's name might appear, and search each one with whatever identifiers that system uses.

SystemWhy it is awkward to search
CRM and helpdeskPerson may appear under several emails or as a contact on another record
Email and shared mailboxesMentions in other people's messages, attachments
Accounts packageStored under a company or billing name
Shared drives and spreadsheetsNo search by person, files scattered
Old or retired systemsData still exists but access is clumsy

Then comes the hard part: deciding what to include, what belongs to other people and needs redacting, and what is exempt. That needs human judgement. The searching and gathering does not.

What a manual process costs

  • Staff time pulled from normal work for every request
  • Risk of missing a system and giving an incomplete response
  • Risk of including someone else's personal data by mistake
  • Pressure on the statutory deadline when requests arrive together
  • No consistent record of what was searched and why

Requests often arrive when relationships have already gone wrong, such as during an employment dispute or a complaint. An incomplete or careless response can make the dispute worse and draw a complaint to the ICO.

The same scattered data also makes erasure requests hard. If you cannot find everything to disclose it, you cannot reliably find everything to delete it either.

How we build a subject access request tool

  1. We map where personal data lives with you: every system, what it holds, and how a person can be identified in it. This map is useful in its own right for your records of processing.
  2. We connect to each system that has an API, such as HubSpot, Salesforce, Zendesk, Xero, Microsoft 365 or Google Workspace, with read-only access.
  3. A request screen lets the handler enter the person's known identifiers: names, emails, phone numbers, account numbers. The tool searches every connected system and lists what it finds, grouped by source.
  4. For systems without an API, the tool shows a checklist item with instructions, so manual searches are recorded alongside the automatic ones.
  5. The handler reviews each result, marks it include or exclude, and records the reason. Suggested redactions of other people's names and emails are highlighted for a person to accept or reject.
  6. The tool produces a structured export and a log of what was searched, when and by whom, which you keep as your record.
  7. The same search can support an erasure request, listing where the person's data sits so each deletion can be actioned and recorded.

The tool helps gather and organise. Decisions about exemptions and what to disclose stay with your team and your legal advisers. This is general guidance, not legal advice.

A request that is a task, not a crisis

When a request arrives, the handler logs it, runs one search and works through a single review screen. Nothing depends on remembering every system. The export is consistent, the log shows what was checked, and the handler's time goes on the judgement calls rather than on logging into a dozen tools.

Adding a new system to the business means adding it to the map and the connector list, so requests stay complete as your tools change.

Is this how requests feel for you?

  • Each subject access request means searching many systems by hand
  • Nobody is certain every system has been checked
  • Requests have come close to the deadline
  • There is no record of what was searched for past requests
  • Erasure requests are handled with the same uncertainty

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Does the tool decide what to disclose?

No. It finds and organises data. Decisions about exemptions, redaction and what to send stay with your team and advisers.

Which systems can it search?

Any system with a usable API, which covers most modern CRMs, helpdesks, accounts packages and Microsoft 365 or Google Workspace. Systems without one are handled as recorded manual steps.

Is it risky to connect a tool to all our systems?

It uses read-only access, restricted to named staff, with every search logged. We design access controls with you before connecting anything.

What affects the cost?

The number of systems, whether they have APIs, and how much redaction support and logging you need.

Keep reading

More on Problems We Solve

Start here

Dreading the next subject access request?

Tell us which systems hold personal data and how you handle requests today. We will say what a search and export tool would involve. We do not give legal advice, and if a clearer internal process would solve it, we will tell you that.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →