How Organisations Should Design Their DSAR Operating Model
August 19, 2026
discovery legal operations artificial intelligence
The Industry Is Solving the Wrong Problem
For much of the past decade, the conversation around Data Subject Access Requests (DSARs) has centred on regulation. Privacy professionals have rightly focused on interpreting individual rights, meeting response deadlines, and ensuring that disclosures satisfy regulatory expectations. That work remains fundamental. But as privacy programmes mature, it is no longer the whole challenge.
For many enterprise organisations, DSARs have become a recurring operational challenge. The questions confronting senior leaders are therefore beginning to change. The greatest concern is whether an organisation has designed an operating model capable of meeting those obligations repeatedly without creating unsustainable costs, operational bottlenecks, or unnecessary legal risk.
Compliance defines the outcome. The operating model determines whether that outcome can be achieved at scale.
Why Complexity Matters More Than Volume
Volume is visible, easy to measure and often blamed when performance begins to deteriorate. Yet two organisations with similar request volumes can experience very different levels of pressure. The more useful measure is the approach to complexity within the caseload.
Consider a customer request relating to a recent purchase. Relevant information may sit in a customer relationship management platform, transaction records and a limited set of service interactions. The likely systems are known, the data is structured and the review questions are familiar. With a defined workflow and proportionate quality assurance, the request can be processed efficiently.
Now consider a request from a former senior executive following a contentious departure. Relevant information may extend across years of email, collaboration platforms, document repositories, performance materials, investigations, mobile communications, archives and business applications. The review may also need to address legal privilege, third-party personal data, confidential business information, multiple jurisdictions and active litigation.
The requests originate from the same statutory right, but they have entirely different risk profiles. Complexity affects everything from the number of data sources, the breadth of collection, the review strategy, the seniority of decision-makers, through to the level of quality control and the likelihood of escalation.
You may not be able to reduce the volume, but embedding risk profiles in your operating model is critical to reducing effort.
The Limits of a One-Size-Fits-All Model
Many DSAR programmes have evolved incrementally. A process is established for the first requests, additional controls are added in response to difficult cases and more reviewers are introduced as demand grows. Over time, every request can inherit the same steps, approvals and level of scrutiny, regardless of its actual risk profile.
That uniformity appears controlled, but it creates two problems. First, routine requests receive more manual input and specialist review than they need. Second, complex requests compete for the same resources and follow a workflow that was not designed for their scale or sensitivity. The result is avoidable cost at the lower end and insufficient focus at the higher end.
Adding headcount may provide temporary capacity, but it also reproduces the same hand-offs and inconsistencies across a larger team. Technology alone has similar limits. Search, analytics, workflow and redaction tools can materially improve delivery, but only where responsibilities, decision points and escalation routes are already clear.
The better approach is controlled differentiation. Routine requests move through standardised playbooks, repeatable searches, clear review rules and proportionate quality assurance. Complex requests should move into an enhanced pathway that brings privacy judgement, eDiscovery expertise and senior governance together at the outset.
Designing the Next Generation of DSAR Operations
The next generation of DSAR delivery should be designed as a service, not assembled as a sequence of disconnected tasks. That means defining how work enters the process, how complexity is assessed, who owns each decision, which technology is used and how quality and performance are measured.
1. Start with structured intake and triage
A strong intake process captures the information needed to validate the request, clarify scope and identify likely sources. A consistent complexity assessment then determines the delivery route. This creates a common language for privacy, operations and eDiscovery teams and allows capacity to be planned around the work that is actually arriving.
2. Create distinct but connected delivery pathways
A standard pathway can handle repeatable requests using documented procedures, trained delivery teams and risk-based quality control. An enhanced pathway can address broad, sensitive or contentious matters through tailored collections, advanced processing and analytics, specialist review protocols and closer legal oversight. Movement between pathways should remain possible as new facts emerge.
3. Bring operations and eDiscovery together
The objective is not to apply full eDiscovery treatment to every DSAR. It is to make that capability available when the data landscape and risk profile justify it.
Operations teams provide the disciplined execution required for recurring delivery: intake and ongoing workflow management, with scalable response for low complexity/high volume requests. This creates a funnel, narrowing specialist input to where it delivers value. eDiscovery teams bring expertise in complex data identification, defensible collection, processing, search, analytics and large-scale review. Connecting those capabilities avoids the common break between the teams that manage the request and the teams that handle the data.
4. Make technology part of the operating model
Technology should support each stage of the service, from intake and workflow tracking to data discovery, processing, review, redaction and production. Automation should remove repetitive effort and improve consistency, while preserving human review where context and legal judgement matter.
5. Govern the service through evidence
A mature programme measures more than whether a deadline was met. Useful operational insight includes where requests wait, which sources generate the greatest effort, how often searches are repeated, where quality issues arise, which matters escalate, and how effort varies by complexity. These insights support better resource allocation, targeted process improvement, and more informed technology investment.
Governance should also create a feedback loop. Lessons from complex requests can refine intake questions, search protocols, review guidance and training. Recurring issues can be escalated into wider improvements in records management, retention and data governance. In this way, DSAR delivery becomes a source of organisational insight rather than a stand-alone compliance burden.
From Compliance Process to Scalable Service
The future of DSAR delivery will not be determined by regulatory knowledge, operational capacity or review technology in isolation. It will depend on how effectively those capabilities are combined within one coherent model.
For enterprise organisations, the target state is clear: routine work follows a repeatable and cost-effective pathway; complex work receives early specialist attention; legal judgement is applied where it adds the most value; and every stage is supported by appropriate technology, quality control, and governance.
This model is more than an efficiency exercise. It improves consistency, protects specialist capacity and strengthens the defensibility of decisions. It also gives organisations the flexibility to respond as data environments, request profiles, and regulatory expectations continue to evolve.
Learn more about our Discovery Services


