Data-subject rights

How SMBs track GDPR DSAR deadlines without a case tool

Access and erasure requests have a one-month clock (extendable in limited cases). This checklist shows how a small team logs DSARs, fans them out to vendors, and proves what they did.

Published 2026-08-24

A DSAR (data subject access request), or an erasure request, is not hard because the law is obscure. It is hard because the data is scattered and the calendar is not. SMBs miss deadlines when the request sits in a founder’s inbox while someone is on leave.

The clock is the product requirement

You need a due date the moment the request is logged — not after you finish debating whether it is “complex.” Default to one month. If you extend, document the reason on the same record. A board that sorts by due date beats a shared mailbox.

Identity checks belong on the same card

Do not start exporting customer data until you have a reasonable identity check. Note what you asked for and when it arrived. That note protects you if someone later claims you disclosed too quickly — or too slowly.

Vendors are why the register matters

Erasure is “delete me everywhere.” Without a vendor list tagged by data type, “everywhere” is a guess. Processors also have their own timelines; asking them on day 25 is how you blow the month. The DSAR board in PrivyLedger sits next to the vendor register for that reason.

What this is not

This is not automated fulfilment across Google Workspace, Slack, and HubSpot. Those products exist and cost more. If you have fewer than a handful of requests per quarter, a deadline board plus a register is the honest SMB setup.

Deadlines summarised here follow GDPR as applied in the EEA. Local labour or sector rules may add duties. This is not legal advice.

Questions

How long do I have to answer a DSAR?

Under GDPR, without undue delay and in any event within one month of receipt. You may extend by two further months for complex or numerous requests, but you must inform the person within the first month and explain why.

Do I need to ask every vendor?

You need to know which processors actually hold that person’s data. A vendor register with data-type tags is how you avoid emailing your entire SaaS stack “just in case.”

Is PrivyLedger a DSAR fulfilment product?

No. It is a deadline board plus vendor context. You still identify the person, retrieve records, and send the response. The board exists so the clock is visible.

Related guides