Skip to content
DSARTracker

Never miss a SAR deadline again

Most SMEs handle SARs with email chains, Word docs, and guesswork — no audit trail, no exemption records, no proof of a reasonable search.

dsartracker walks you through every step and documents everything the ICO would ask for.

No spam. Unsubscribe any time. Privacy policy

Free SAR deadline calculator at launch. Full workflow from £29/month.

Built by a UK software team for HR managers handling employee SARs. Crocker Digital Ltd — Company No. 17008789.

16,000+ SAR complaints to the ICO in a single year. 23% up from the year before.

UK SMEs are one SAR away from an ICO complaint

Most failures come from the same preventable mistakes — and most employers don't realise until the ICO gets involved.

Missed deadlines with no system to track them

A SAR arrives via email on a Friday. By Monday, nobody remembers. The 1-month clock is already ticking — with no tracker, the deadline passes in silence.

No audit trail when the ICO investigates

The ICO asks: "What search did you conduct? Which exemptions did you apply and why?" With Word docs and email chains, you have no documented answer.

Third-party data accidentally disclosed

An employee SAR contains emails mentioning colleagues by name. Without a structured redaction process, other people's personal data gets sent to the requester.

Exemptions misapplied — or not applied at all

Legal privilege, management forecasting, negotiations — DPA 2018 exemptions exist to protect employers, but most HR managers don't know they apply or how to document them.

Get early access to the SAR tracker that logs deadlines, exemptions, and searches for you.

Know exactly where every SAR stands

dsartracker replaces the Word docs and email chains with a guided workflow that walks you through each step — and documents everything for the ICO.

Never miss a deadline

Log a SAR and the 1-month clock starts. Extensions, stop-the-clock events, and DUAA 2025 provisions are calculated automatically.

Apply exemptions without a law degree

A plain-English picker maps to DPA 2018 Schedule 2, Part 4 exemptions. Apply the right exemptions with documented justification — no legal training required.

Prove your search to the ICO in one click

Every search conducted, exemption applied, and decision made is logged. Export a compliance pack that documents your reasonable and proportionate search.

Cut SAR handling from days to hours

A structured workflow replaces the back-and-forth of emails, shared drives, and guesswork. What takes 10-20 hours in Word takes a fraction with a guided process.

How dsartracker handles a subject access request

1

Log the incoming SAR

Enter the requester details and the date received. dsartracker calculates the deadline, accounting for identity verification delays and stop-the-clock events.

2

Follow the guided workflow

Work through each stage: verify identity, define search scope, gather data from your systems, check exemptions using the plain-English picker, and redact third-party information.

3

Generate your response

Choose from built-in letter templates — acknowledgement, verification request, response cover letter, extension notice. Each template follows ICO best practice.

4

Export the audit trail

Download a compliance pack documenting every search, exemption decision, and action taken. If the ICO investigates, you have the evidence ready.

Frequently asked questions about subject access requests

How long do you have to respond to a subject access request?

Under UK GDPR, you must respond to a subject access request within one calendar month of receiving it. If the request is complex or you receive multiple requests from the same person, you can extend by a further two months — but you must tell the requester within the first month and explain why. The Data (Use and Access) Act 2025 also introduces a "stop the clock" mechanism where the deadline pauses if you need to request identity verification or clarification.

What exemptions apply to subject access requests for employers?

The Data Protection Act 2018 contains several exemptions employers can rely on when responding to SARs. Schedule 2, Part 4 covers the key employer exemptions — paragraph 19 protects legal professional privilege (documents covered by legal advice in tribunal proceedings), while paragraphs 22-24 cover management forecasting, negotiations, and references. Each exemption must be assessed on a document-by-document basis with written justification for your audit trail.

Can an employer charge a fee for a subject access request?

In most cases, no. Under UK GDPR, subject access requests are free. You can only charge a "reasonable fee" if the request is manifestly unfounded or excessive — for example, if the same person submits repeated identical requests. You can also charge for additional copies beyond the first. The ICO expects most requests to be handled at no cost, and rejecting or charging for a straightforward SAR is a common basis for ICO complaints.

What is a DSAR and how does it differ from a SAR?

DSAR (Data Subject Access Request) and SAR (Subject Access Request) refer to the same thing: a request by an individual to see the personal data an organisation holds about them. "SAR" is the term used in the Data Protection Act 2018 and by the ICO. "DSAR" is more common in the privacy technology industry. Both carry the same legal obligations — a one-month response deadline and the right to receive a copy of personal data in a commonly used electronic format.

Can a subject access request be made verbally?

Yes. A SAR does not need to be in writing. If an employee says "I want to see my personal data" in a meeting, by phone, or in any other verbal exchange, that counts as a valid SAR. The ICO confirms that requests can be made verbally, by email, by letter, or through social media. The one-month response clock starts from the moment anyone in your organisation receives the request — even if it was never put in writing.

How do you redact third-party data in a subject access request?

When responding to a SAR, you must not disclose personal data about other identifiable individuals unless they have consented or it is reasonable to disclose without consent. Redact names, contact details, and any information that could identify a third party. Use consistent redaction methods — black bars in PDFs, "[REDACTED]" markers in text — and log each redaction decision with your reasoning. This audit trail protects you if the requester complains to the ICO.

What happens if you miss a subject access request deadline?

Missing a SAR deadline is a breach of UK GDPR Article 12. The requester can complain to the ICO, which can issue reprimands, enforcement notices, or fines up to £17.5 million (or 4% of annual turnover). In practice, the ICO issued over 8 reprimands and enforcement notices for SAR handling failures in recent years. SAR complaint volumes rose 23% year-on-year. Beyond regulatory action, a missed deadline in an employment tribunal context can damage your position and credibility with the tribunal.

Who is behind dsartracker?

dsartracker is built by Crocker Digital Ltd (Company No. 17008789), a UK software company. We identified that UK SMEs have no practical tools for handling SARs — enterprise platforms cost £10,000+ per year while SMEs cobble together responses in Word and email. dsartracker fills that gap with a step-by-step tracker built specifically for employers without a dedicated DPO.

How much will dsartracker cost?

The free SAR deadline calculator and exemption checker will always be free. The full SAR workflow — deadline tracking, guided exemptions, document storage, and audit export — starts at £29 per month or £249 per year. Enterprise privacy platforms typically start at £10,000+ per year. dsartracker is built for SMEs, not enterprise privacy departments.

Is my data secure if I sign up to the waitlist?

Your email address is the only data we collect at signup. It is stored securely and used solely to notify you about the dsartracker launch. We do not share your data with third parties. Our analytics use GoatCounter, which collects no personal data and uses no cookies. You can request deletion of your email at any time by contacting hello@crockerdigital.co.uk.

Do I need dsartracker if I only get one or two SARs a year?

Even a single SAR can take 10-20 hours to handle properly when you factor in searching for data, checking exemptions, redacting third-party information, and drafting a compliant response. Without a structured process, you risk missing the deadline, over-disclosing sensitive information, or failing to document your search. dsartracker guides you through each step and creates the audit trail automatically — valuable whether you handle 1 SAR or 100.

Be the first to try the SAR tracker built for UK employers

Join the waitlist for early access to deadline tracking, exemption checks, and audit-ready response packs.

No spam. Unsubscribe any time. Privacy policy

One launch-day email. No spam. Unsubscribe any time. Privacy policy