EU GDPR Data Subject Access Request Flowchart
[Company Name] / [job title] receives a Data Subject Invite data subject to submit the
Record the DSAR
Access Request (DSAR) from a data subject DSAR in prescribed form
Ask the relevant Department
Contact the relevant departments YES
(HR, Marketing, IT etc.) to
for the requested data. The 30 Pass the ID verification?
complete a Data Disclosure
days period begin.
Form within 10 calendar days
ID verification:
NO Ask the Requestor to
provide 2 forms of
Data Disclosure Form identification:
completed by the relevant Verify the Requestor s identity: (1) photo identity;
Departments? (data subject or authorized (2) confirmation of
representative of data subject?) address
NO
Data Protection Officer meets
with the relevant Department YES
to review the DSAR.
No response within 10 working days
Transfer of the data from the
relevant Department
YES
YES Data Protection Officer will confirm the
Check if exemption applies or
exception or obtain consent to disclose 3rd
3rd party data exists?
party data
NO
Data Protection Officer to finalizes the response and sends Close the case and record the DSAR
the data to the data subject by secure means. response
Courtesy of: EUGDPRAcademy.
See other templates for GDPR compliance in the EU GDPR Documentation Toolkit.
Copyright © 2017 Advisera Expert Solutions Ltd.