Docs / Tutorial: Complete a Case End-to-End

Tutorial: Complete a Case End-to-End

This tutorial walks you through handling a complete Data Subject Access Request (DSAR) from receiving the request to sending the final response. Follow along in your own SAR Portal account.

Open Cases →

Cases list view - Your starting point for managing all DSARs
Cases list view - Your starting point for managing all DSARs Cases list view - Your starting point for managing all DSARs

Scenario

The Request: John Smith has submitted an access request through your public portal, asking for a copy of all personal data you hold about him.

Your Task: Gather his data, review it for third-party information, redact where necessary, and respond within 30 days.

1Review
2Gather
3Analyze
4Redact
5Review
6Close

Step 1: Review the New Case (Day 1)

When the request comes in, you’ll receive an email notification and see it in your dashboard.

1.1 Open the Case

Sidebar Cases Click on the case

View Cases →

Cases
CASE-2024-0042 Open

John Smith • john.smith@email.com

Access Request (Art. 15) • Due: 30 days

1.2 Review Case Details

Check the case summary:

1.3 Update Status

Change the status to show you’ve started working:

Status:

Step 2: Gather Data (Days 1-7)

Now collect all personal data you hold about John Smith.

2.1 Search Your Systems

Check all locations where you might have John’s data:

2.2 Export the Data

Export relevant records as documents:

2.3 Upload Documents

Case Documents section Upload
Case Documents
Drag & drop files here
or click to browse
PDF, Word, Excel, Images • Max 50MB
📄 john-smith-customer-profile.pdf 245 KB
📄 email-history-export.pdf 1.2 MB
📊 order-history.xlsx 89 KB

2.4 Add Notes

Document what you searched:

Searched the following systems for data relating to John Smith:
- Salesforce CRM: Found customer profile and order history
- Gmail: Found 23 email exchanges
- Zendesk: Found 2 support tickets
- Mailchimp: Found on marketing list (subscribed)
- Accounting system: No records found

Step 3: Analyze Documents (Days 7-14)

Use AI to identify personal data in the documents.

3.1 Run AI Analysis

For each document:

  1. Click Analyze for PII button
  2. Wait for analysis (10-30 seconds)
  3. Review detected entities
PII Analysis Results

12 entities detected in email-history-export.pdf

Email Addresses 5 found
john.smith@email.com, sarah.jones@company.com, mike.wilson@company.com...
Names 4 found
John Smith, Sarah Jones, Mike Wilson, Emma Brown
Phone Numbers 2 found
+44 20 1234 5678, +44 20 8765 4321
Addresses 1 found
123 High Street, London, EC1A 1BB

3.2 Identify Third-Party Data

Important: You must redact personal data belonging to OTHER people before sending to John.

From the analysis above, identify:

GDPR Requirement
Article 15(4): The right to obtain a copy shall not adversely affect the rights and freedoms of others. You must protect third-party personal data.

Step 4: Redact Third-Party Data (Days 14-21)

Remove other people’s personal information from the documents.

4.1 Open Redaction Editor

Click Redact on the document to open the redaction interface.

4.2 Review AI Suggestions

The AI will highlight detected PII. For each item, decide:

Redaction Review
john.smith@email.com
Email Address • High confidence
Keep Redact
sarah.jones@company.com
Email Address • High confidence
Keep Redact

4.3 Apply Decisions

Entity Decision Reason
john.smith@email.com Keep Subject’s own data
John Smith Keep Subject’s own data
sarah.jones@company.com Redact Third-party data
Sarah Jones Redact Third-party data
mike.wilson@company.com Redact Third-party data
Mike Wilson Redact Third-party data

4.4 Apply Redactions

  1. Confirm all redaction selections
  2. Click Apply Redactions
  3. A new redacted version is created
  4. Original is preserved
Redaction Complete
The redacted document now shows black boxes where third-party data was removed. The original document is safely preserved.

Step 5: Review & Approve (Days 21-28)

Before responding, have the documents reviewed.

5.1 Mark Identity as Verified

Once you’ve confirmed the subject’s identity:

Status:

5.2 Review Checklist

Before closing, verify:

5.3 Add Final Notes

Document your review:

Review completed by: Jane Admin
Date: [Today]
Documents reviewed: 3
Redactions applied: 8 third-party items
Response ready for delivery

Step 6: Close the Case (Day 28)

Finalize and send the response.

6.1 Prepare Response Package

Download the redacted documents to send to John:

  1. Click Download on each redacted document
  2. Compile into a response package
  3. Include a cover letter explaining what’s provided

6.2 Send Response to Subject

Send the documents to John via:

6.3 Close the Case

Close Case
Close Case

6.4 Confirmation

Case Closed Successfully

CASE-2024-0042 • Completed in 28 days


Summary

You’ve successfully completed a DSAR by:

  1. Reviewing the incoming request
  2. Gathering data from all your systems
  3. Analyzing documents for personal data
  4. Redacting third-party information
  5. Reviewing before sending
  6. Closing with full documentation

Time Spent

Phase Days Activities
Review 1 Open case, understand request
Gather 7 Search systems, export data
Analyze 7 Run AI analysis, identify PII
Redact 7 Apply redactions, create clean docs
Review 4 Final review, obtain approvals
Close 2 Send response, close case
Total 28 Within 30-day deadline

The Audit Trail

SAR Portal has automatically recorded:

View Audit Logs →


Next Steps

Other Request Types Batch Processing Managing Deadlines Audit Logs