Statement of Guidance

DSAR Guidance Tool – User Guide (DPO to DPO)

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is practical, non-binding guidance from the ODPA aimed at Data Protection Officers (DPOs) and staff handling Data Subject Access Requests (DSARs), explaining how to use the Authority's optional 'DSAR Manager' spreadsheet tool and giving stage-by-stage tips for managing DSARs. It supplements the Authority's separate Guidance for Controllers and does not itself create new legal rules, but it restates and explains existing statutory requirements under Guernsey data protection law.

  • Acknowledge: Notify relevant staff and the controller's representative early; the clock for compliance is one calendar month from receipt or identity verification, not 30 days.
  • Collation: Cast a wide net for personal data sources (systems, mobile devices, third parties, archives, physical files); use and record reasonable search terms; record 'nil return' results.
  • Review: Chase up referenced but missing documents; apply redactions transparently and consistently; retain both a finalised redacted copy and a provisional/withheld-material copy; only apply exemptions where properly justified and recorded.
  • Disclosure: Advise requestors of exemptions applied (with limited exceptions); disclose securely (encryption, secure file sharing, tracked post); present material in an intelligible, organised format; if extending the deadline, notify the requestor as soon as possible.
  • Post-disclosure: Respond to follow-up queries where possible; treat further DSARs from the same requestor as new requests limited to data processed since the prior request; feed lessons learned back into internal policies.

The guidance emphasises maintaining detailed records of decisions throughout the DSAR process, both for internal administration and for accountability to the Authority, and recommends supporting internal policies and procedures and designated departmental contacts for larger organisations. Use of the DSAR Manager tool itself is explicitly optional.

Key obligations

  • A controller must comply with a DSAR within one calendar month of receipt or identity verification, not 30 days.
  • Where an extension of one or two months is applied, the requestor must be notified of the extension as soon as possible.
  • Controllers must generally advise requestors of any exemptions applied to redacted or withheld material, except in limited cases where disclosure of the exemption itself would prejudice its purpose.
  • Search terms used to locate personal data must be reasonable given the organisation's systems and processes, and the terms/rationale used should be recorded.
  • Controllers must maintain a Record of Processing Activities as legally required under the Law.
  • Disclosure of DSAR material must be made securely (e.g. encryption, secure file sharing, tracked post).

Applies to

Data Controllers, Data Protection Officers (DPOs), organisations subject to Guernsey data protection legislation

Deadlines

  • one calendar month: Statutory deadline for a controller to comply with a DSAR, running from date of receipt or identity verification.
  • one or two month extension: Additional period a controller may apply to the standard one-month DSAR deadline, with the requestor to be notified of the extension as soon as possible.

Topics

Version history

2026-07-30

source file (current)