Why Small Businesses Benefit from an Outsourced Data Protection Officer (DPO)

Introduction

Over the past two months alone, GRC Hub has helped clients process more than 40 Data Subject Access Requests (DSARs). While every request is different, we consistently encounter the same challenges and inefficiencies.

With increasing awareness of privacy rights, the rise of AI-assisted requests, and the introduction of the Data (Use and Access) Act 2025, organisations can no longer afford to treat DSARs as an occasional administrative task.

Here are the five most common DSAR mistakes we see businesses making and, more importantly, how to avoid them.

1. Conducting Searches That Are Too Broad

One of the most common mistakes occurs at the very beginning of the DSAR process.

Many organisations perform overly broad searches within tools such as Microsoft Purview, Google Vault, email archives, file shares, and collaboration platforms. While the intention is often to ensure nothing is missed, the result is frequently thousands of unnecessary records requiring manual review and redaction.

This significantly increases:

  • Review times
  • Redaction effort
  • Operational costs
  • The risk of human error

The introduction of the Data (Use and Access) Act 2025 reinforces the requirement for organisations to undertake reasonable and proportionate searches, rather than unlimited searches across every possible location.

Before conducting searches, organisations should:

  • Understand what the individual is actually requesting
  • Identify likely data sources
  • Apply relevant date ranges
  • Use targeted search terms
  • Exclude clearly irrelevant repositories

A well-planned search strategy can reduce review volumes dramatically while still ensuring compliance.

Key takeaway: More data isn’t always better. The objective is to conduct a reasonable and proportionate search, not generate the largest possible review set.

2. Failing to Engage With the Data Subject

Many organisations mistakenly believe they should fulfil a request exactly as submitted without any further dialogue.

In reality, communicating with the requester is often one of the most effective ways to reduce complexity and improve outcomes for everyone involved.

Since the rise of Large Language Models (LLMs) and AI-assisted drafting tools, we have observed a significant increase in broad, generic, and unusual DSAR requests.

One growing trend is requests for technical information such as metadata. In many cases, when organisations seek clarification, the requester does not fully understand what metadata is or how it relates to their original concern.

Constructive dialogue often leads to:

  • The request being withdrawn
  • The scope being narrowed
  • Additional search criteria being provided
  • Greater clarity regarding what information is actually sought

This approach benefits both parties and often reduces the time and resources required to fulfil the request.

Key takeaway: Early communication can significantly reduce the burden of a DSAR while improving the quality of the response.

3. Having No Documented or Mapped DSAR Process

Surprisingly, one of the most significant weaknesses we identify during discovery calls is the absence of a documented DSAR process.

This is understandable for organisations that have never received a request before. However, we regularly see businesses handling multiple DSARs each year with little or no documented process in place.

This creates several risks.

Dependency on Individuals

Many DSAR processes rely heavily on one person within legal, compliance, HR, or IT. If that individual is unavailable, the organisation may struggle to respond within statutory deadlines.

Inconsistent Outcomes

Without documented guidance, two reviewers may make different decisions regarding:

  • Relevance
  • Redactions
  • Exemptions
  • Third-party information

Consistency is critical to demonstrating accountability.

Operational Inefficiencies

A mapped process enables organisations to identify:

  • Bottlenecks
  • Duplicate activities
  • Unnecessary approval stages
  • Resource constraints

An effective process map should clearly show:

  • Roles and responsibilities
  • Data sources
  • Data transfers
  • Technology platforms
  • Decision points
  • Review and approval stages

We typically recommend maintaining process maps at Level 0, Level 1 and Level 2 to ensure both strategic visibility and operational detail.

Key takeaway: If your DSAR process only works when one person is available, it is not a resilient process.

4. Using the Wrong Tools

Closely linked to process design is tool selection.

While specialist DSAR technology has become increasingly accessible, many organisations continue to rely on highly manual approaches.

On occasion, we still encounter organisations printing digital documents and using correction fluid or marker pens before rescanning files. While this may work for a small annual volume of requests, it becomes unsustainable very quickly.

Modern redaction and review platforms can provide:

  • Automated redaction assistance
  • OCR (Optical Character Recognition)
  • Deduplication
  • Advanced search capabilities
  • Keyword analytics
  • Metadata management
  • Identification of personal data (UK/EU GDPR) and PII
  • Audit trails and reporting

Not every organisation requires an enterprise-grade DSAR platform. The appropriate solution depends on factors such as:

  • Annual DSAR volume
  • Data complexity
  • Regulatory risk
  • Internal resourcing

However, even relatively inexpensive tools can significantly reduce manual effort and improve consistency.

Key takeaway: The right technology can reduce response times, lower costs, and improve compliance outcomes.

5. Underestimating What’s Involved

This is perhaps the most common issue among organisations receiving their first DSAR.

Many businesses assume a DSAR simply involves exporting emails and sending them to the requester.

In reality, fulfilling a DSAR often requires:

  • Identifying multiple data sources
  • Collecting information from different systems
  • Reviewing thousands of documents
  • Assessing applicability of exemptions
  • Protecting third-party information
  • Performing redaction
  • Conducting quality assurance checks
  • Preparing the final response pack

Even a seemingly straightforward request can consume significant time and resources.

Organisations that underestimate the complexity of DSARs often find themselves scrambling to meet deadlines, involving multiple teams at short notice, and introducing unnecessary compliance risk.

Having documented procedures, trained personnel, and appropriate tooling in place before a request arrives can make the difference between a smooth response and a major operational disruption.

Key takeaway: A DSAR is not simply an IT task or an HR task. It is a cross-functional compliance process that requires planning, coordination, and expertise.

Final Thoughts

Data Subject Access Requests are becoming more common, more complex, and increasingly influenced by AI-generated submissions. Organisations that continue to approach DSARs with manual processes, undocumented procedures, and broad search strategies will find themselves facing rising costs and operational burden.

By focusing on:

  • Proportionate searches
  • Effective communication
  • Documented processes
  • Appropriate technology
  • Staff awareness and training

organisations can significantly improve both compliance and efficiency.

If your organisation is struggling with DSAR fulfilment, process mapping, redaction, or response reviews, seeking specialist advice early can help avoid costly mistakes and ensure requests are handled consistently and compliantly.

Need a Better DSAR Process?

To help organisations improve their DSAR readiness, GRC Hub provides a free outline DSAR process template to new contacts. This practical resource can help you establish a consistent approach to handling Data Subject Access Requests and identify opportunities to improve efficiency.

If you’d like a copy, contact us today.

If you’re currently dealing with a complex request, require independent review support, or need specialist redaction and fulfilment assistance, explore our DSAR Support Services.

The Governance Risk & Compliance Hub - Data Protection and Cybersecurity Specialists Logo.

Governance Risk & Compliance Hub LIMITED

© 2026 All rights reserved