practice

Subject Access Fulfilment

The operational path from a request to a complete, verified, delivered response within the statutory period, across systems that were never designed for it.

The right is straightforward to state and hard to satisfy, because personal data about one person is scattered across an operational database, a warehouse, several SaaS tools, a support ticketing system, email archives, logs and backups — and no single index knows where.

Fulfilment has four parts, and the middle two are where programmes fail. Verification of the requester's identity, which must be robust enough that responding is not itself a disclosure to an impostor. Discovery across every system, which requires a maintained inventory of where personal data lives, keyed by an identifier that resolves consistently. Assembly into an intelligible form, since raw table extracts do not satisfy the obligation. Delivery securely, within the period.

The design implication is that discovery cannot be an investigation performed per request; at any volume it must be automated, which means a data inventory with subject-identifier mapping maintained as systems change.

The recurring complication is third parties. Data pushed to a marketing platform or a partner is still in scope, and the response depends on that party's own capability and timeliness — which is a contractual matter that has to be arranged before the first request arrives.