Back to Blog
DSARPrivacy OperationsCross-Border

How to Handle Complex DSARs Across Borders

By Robert Healey · August 26, 2026

Privacy professionals handling a cross-border DSAR with a globe, world map and padlock graphic

A complex DSAR rarely arrives as a neat request for a single personnel file. It may come from a former employee involved in a dispute, a customer requesting data held across several platforms, or an individual whose information appears in shared records, support tickets, recordings and third-party systems. Knowing how to handle complex DSARs is therefore less about locating documents quickly and more about operating a controlled, defensible process from intake to response.

For organisations operating across borders, the challenge is amplified. Different business units may own different systems, processors may hold material outside the organisation, and the request may trigger obligations under more than one privacy regime. A rushed response can create as much risk as an incomplete one. The objective is a timely, proportionate and well-evidenced response that protects both the requester’s rights and the rights of others.

Start with triage, not collection

The first operational error in DSAR handling is sending a broad request to every system owner without first defining the request. This creates unnecessary volume, inconsistent searches and difficult review work. A structured triage process establishes what must be done before data collection begins.

Confirm the requester’s identity using a proportionate method, particularly where the request is made through a channel that does not provide sufficient assurance. Then record the date received, the relevant jurisdiction or jurisdictions, the applicable response deadline, and the internal case owner. If the request is broad or unclear, consider whether clarification is appropriate. Clarification should narrow ambiguity, not discourage the individual from exercising their rights.

A useful triage record should establish four practical points:

  • the individual and their relationship with the organisation;
  • the likely data categories, business functions and systems involved;
  • any linked events, such as an HR matter, complaint, contract dispute or security incident; and
  • whether third-party, confidential, legally protected or commercially sensitive material is likely to be present.

This early assessment determines the scope of collection and review. It also allows the privacy function to identify cases requiring input from HR, legal, security, customer operations, records management or local country teams.

How to handle complex DSARs with a case plan

Complex requests need a case plan, not simply a checklist. The plan should set out the scope, search methodology, responsibilities, milestones, escalation points and quality controls. It provides a single source of truth when multiple teams are involved and creates an audit trail should the response later be questioned.

Begin by mapping the data landscape relevant to the individual. In a mature organisation, this should draw on the record of processing activities, data inventory and retention schedule. In practice, DSAR teams also need to validate those records with system owners. Platforms change, acquisitions create duplicate environments, and local teams may use approved tools differently from the central design.

Search instructions should be specific. Rather than asking a system owner to search for a name, provide known identifiers such as work and personal email addresses, customer reference numbers, employee IDs, telephone numbers, account names and relevant date ranges. Define the systems to be searched, the terms to use, the date parameters and the format in which results should be supplied.

This matters particularly for unstructured data. Emails, collaboration platforms, shared drives, call recordings and case-management notes often contain the most sensitive material and the greatest volume. A keyword search alone may be too narrow, while an unrestricted export may be impractical to review within the response period. The appropriate method depends on the individual, the data environment and the context of the request. Document why the chosen approach is reasonable.

Coordinate processors and international teams

Where a processor holds relevant personal data, the DSAR workflow must extend beyond the organisation’s own systems. Contracts should support reasonable assistance with data subject requests, but contractual wording is only useful if the supplier relationship has an operational route for activating it.

Maintain named contacts, a defined escalation path and agreed response expectations for priority suppliers. The internal case owner should communicate a focused search request, provide identifiers and dates, and track the supplier’s response against the overall deadline. Do not assume a processor’s standard export is complete or intelligible without checking it against the agreed scope.

Cross-border cases require additional discipline. The organisation may need to coordinate local HR files, regional CRM instances, country-specific retention rules and different controller or processor roles. A central privacy lead should control the case plan while local teams provide system knowledge and context. This avoids fragmented decisions and ensures the final response is consistent.

For organisations active in multiple markets, DSAR operations benefit from a clear governance model. Formiti’s three-team approach - legal expertise, privacy operations and technical operations - reflects the capability complex cases require. The work is not solely a legal interpretation exercise, nor is it merely an IT retrieval task. It requires coordinated decisions, controlled evidence gathering and practical execution.

Review material in defensible stages

Collection is only the midpoint of a DSAR. The critical work is determining what can be disclosed, what needs redaction and what should be withheld or treated separately under the relevant framework. Review should be structured in stages so that decisions are consistent and explainable.

First, remove obvious duplicates and irrelevant material. Next, identify information relating to other individuals, confidential business information, security-sensitive content and material subject to applicable protections or restrictions. Reviewers should apply documented decision criteria rather than making isolated judgement calls in different departments.

Third-party data is a frequent source of delay. A document may relate to the requester while also identifying colleagues, customers, witnesses or family members. In these circumstances, the answer is not always to exclude the entire document. Redaction, partial disclosure and contextual assessment may be more appropriate. The decision should reflect the relevant legal framework, the nature of the information, the rights and expectations of affected parties, and whether meaningful disclosure remains possible.

Quality assurance is essential before release. A second reviewer should check redactions, file metadata, hidden comments, tracked changes, attachments and export settings. Technical errors can undermine an otherwise careful process. The response package should be tested in the same way as any other sensitive external disclosure.

Communicate clearly while the work is underway

A DSAR response is not just a data transfer. The accompanying communication should explain the outcome in clear language, identify the relevant processing information required by the applicable regime, and present the material in a usable format. Avoid unexplained spreadsheets, raw system exports or bundles of documents with no context.

Where an extension is available and justified, manage it early. Record the basis for the decision, obtain the necessary internal approval and notify the requester within the required timeframe. Equally, where a request is unusually broad, repetitive or operationally difficult, do not allow the case to drift while teams debate scope. Escalate promptly, make a documented decision and maintain respectful communication.

A clear case log should capture correspondence, search instructions, systems searched, collections received, review decisions, redactions, approvals and delivery evidence. This record is operationally valuable even where no complaint follows. It enables the organisation to answer internal questions, demonstrate accountability and improve future handling.

Turn difficult requests into operational intelligence

The most effective DSAR programmes treat each difficult case as a control test. Repeated challenges finding data may indicate a weak data inventory. Heavy reliance on manual exports may point to an integration or retention issue. Delays from suppliers may reveal that contractual commitments have not been translated into working procedures.

After closing a complex case, hold a short review with the functions involved. Assess where time was lost, which systems generated disproportionate volume, whether search instructions were effective and whether decision-making authority was clear. Feed the findings into records of processing, supplier governance, retention controls, staff guidance and workflow design.

Technology can support this work, but it does not remove the need for judgement. A platform such as Privacy360 can centralise request intake, task allocation, evidence, deadlines and approvals, giving privacy teams visibility across a case. However, meaningful outcomes still depend on accurate data mapping, accountable owners and reviewers who understand the operational context.

A complex DSAR is best handled as a controlled cross-functional process, not an urgent document hunt. When ownership, data discovery, review controls and supplier coordination are designed before the next request arrives, the organisation can respond with greater confidence and less disruption.

Related Services

Need help with AI governance or data privacy compliance?

Privacy-first website: We do not use tracking cookies, advertising pixels, or third-party analytics on this site. Read our Privacy Notice.