They had found 847 records related to the data subject across these systems. The legal team reviewed the response and asked a question the privacy team could not answer with confidence: have you searched all systems that might hold personal data about this individual? The honest answer was no. The response went out with a caveat. The regulator, examining a follow-up complaint six months later, was not satisfied with the caveat.
The Architecture of Incomplete DSARs
GDPR Article 15 grants data subjects the right to receive a copy of all personal data held about them. The word 'all' is doing significant governance work in that sentence. It does not mean the personal data in the primary systems. It means the personal data in every system, every application, every data store, every backup, every log, and every third-party processor that holds data about the individual on behalf of the organization.
Most organizations have not inventoried personal data at the level of granularity that a complete DSAR response requires. They know which primary systems hold customer data. They may not know which secondary systems — analytics platforms, logging infrastructure, backup archives — also hold data about the same individuals. They certainly do not know with precision which of their vendors' systems hold data about the individual, processed on behalf of the organization.
The DSAR exposes this inventory gap directly. The request creates an obligation to find all personal data about a specific individual. The process of finding it reveals which systems were not in the data mapping. The response produced by the search reflects the systems that were searched rather than the full population of systems that might hold relevant data.
A DSAR response is only as complete as the data inventory that informed the search. Most data inventories were not built to answer the question 'which systems hold personal data about this specific individual.' Building that capability is the DSAR infrastructure investment that most organizations make reactively, after the first inadequate response, rather than proactively.
The Seven Systems That Were Searched
Each system in the DSAR search represented a governance decision made during the search process rather than a documented, maintained data inventory. The privacy team knew to search the CRM because it was the primary customer record system. They knew to search the support ticketing system because they had received DSARs before and learned from the first one that support tickets held personal data. They searched the email archive because legal required it. They searched the marketing automation platform because they knew it held email addresses and behavioral data.
What they did not search: the data warehouse that aggregated behavioral data from multiple sources for analytics, which held a more complete picture of the individual's interactions than any single source system. The A/B testing platform that had logged the individual's responses to interface variations. The session recording tool that had captured the individual's interaction sessions on the customer portal. The customer success platform used by account management to log interactions. Each of these held personal data about the individual. None were in the search scope because none were in the data inventory.
What Complete DSAR Infrastructure Requires
System-Level Data Inventory
A record of processing activities that identifies data categories and legal bases is necessary for GDPR compliance. It is not sufficient for DSAR completeness. DSAR completeness requires a system-level data inventory that identifies every system capable of holding personal data about individuals — including systems that are not primary personal data processors but that may hold personal data as a byproduct of their primary function: logging systems, analytics platforms, session recording tools, A/B testing platforms, and customer engagement tools.
Defined Search Protocol
A documented DSAR search protocol that specifies which systems are searched, in what order, using what search methods, and what constitutes a complete search reduces the inconsistency of DSAR responses that depend on the knowledge of the individual conducting the search. The protocol embeds the institutional knowledge of what systems hold personal data in a documented process rather than in the memory of privacy team members.
Third-Party Processor Coordination
Personal data held by third-party processors on behalf of the organization is the organization's personal data for DSAR purposes. A complete DSAR response requires either searching third-party systems or receiving confirmation from processors that the individual's data is not present in their systems. Most DSAR processes do not have a systematic mechanism for coordinating with processors. The processor coordination step is either absent or is an ad hoc email to selected vendors rather than a defined process covering all processors.
Backup and Archive Handling
Personal data in backups is personal data subject to DSAR. Whether the DSAR response should include data held only in backup — as opposed to in production systems — is a question with legal nuance. Whether the organization knows what personal data its backups contain about the individual is a question with a simpler answer: most organizations do not. Building an honest position on backup data in DSAR responses requires legal analysis and an understanding of backup architecture that most privacy teams have not completed.
The Regulator's Perspective
Regulators assessing DSAR compliance look at completeness, accuracy, and timeliness. Incomplete responses that result from inadequate data inventories are findings, not excuses. The ICO's enforcement guidance is explicit that organizations are expected to have sufficient internal processes to respond to DSARs fully within the statutory timeframe. An organization that consistently produces partial DSAR responses because it has not built the inventory infrastructure to support complete responses is an organization that is not meeting its Article 15 obligations.
Build the inventory before the DSAR reveals the gaps. The infrastructure investment is the same either way. Making it proactively is significantly less expensive.
Know what your systems hold before the data subject asks. The DSAR is the test. Pass it by building the infrastructure, not by caveating the response.
Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.
