Data Access: The Painful Truth of High-Level Effort and Hidden Costs

In the age of big data, the General Data Protection Regulation (GDPR) has strengthened the rights of individuals over their personal data. One of these rights is the right of access, also known as Data Subject Access Requests (DSARs). It gives individuals the right to obtain a copy of their personal data that is being processed by organisations. However, responding to these requests can be a daunting task for businesses, requiring a high level of effort across all areas of the business. In this article, we will discuss the pain caused by the high level of effort required in processing DSARs and provide actionable tips for streamlining the process.

The Pain Caused by DSARs:

  • Cost:
    Processing DSARs is a time-consuming and costly process. The effort required can include the time spent by staff verifying the identity of the data subject, locating the relevant data, redacting third-party personal data, and responding to the request. The cost of responding to a single DSAR can vary greatly, depending on the complexity and scope of the request. These costs can add up quickly, particularly for businesses that receive a high volume of requests.
  • Time:
    Processing DSARs can be a time-consuming process, particularly for businesses that receive a high volume of requests. Staff must locate and review the relevant data, redact any third-party personal data or sensitive personal data, and respond to the request within the one-month deadline. This can take valuable time away from other tasks and lead to productivity losses.
  • Resource allocation:
    Processing DSARs requires a significant allocation of resources across all areas of the business. IT staff must locate and extract the relevant data, legal staff must review and redact any sensitive personal data, and customer service staff must respond to the request within the one-month deadline. This can strain the resources of businesses, particularly those that receive a high volume of requests.

Tips for Streamlining the Process:

  • Create a streamlined process:
    Creating a streamlined process for processing DSARs can help reduce the time and effort required. This can include automating certain aspects of the process, such as using a DSAR management tool to track and monitor requests, set reminders for deadlines, and generate standard responses. It can also involve creating a clear process for handling requests, including how to verify the identity of the data subject, how to respond to the request within the one-month deadline, and how to handle complex or voluminous requests.
  • Provide regular training:
    Providing regular training for staff on how to process DSARs can help ensure that requests are handled efficiently and effectively. This can include training on how to identify and respond to a DSAR, how to verify the identity of the data subject, and how to handle complex or voluminous requests. It can also include training on how to use any automated tools or systems that are in place.
  • Outsource:
    Outsourcing the processing of DSARs can be a cost-effective option for businesses that receive a high volume of requests. This can involve engaging a third-party service provider to handle the requests on behalf of the business. This can free up internal resources and reduce the time and effort required to process DSARs.