Use case
Data subject access requests, end to end.
Every modern privacy regime — UK & EU GDPR, CCPA / CPRA, LGPD, PIPEDA, APPI and more — gives individuals the right to a copy of the personal data you hold about them, with a regulated deadline and a defensibility expectation. Smartbox handles the workload underneath that right: identity verification, multi-source collection, multilingual classification, bulk redaction, secure disclosure, and the audit trail every regulator expects.
The challenge
Same right, every regime. Different names, same workload.
Subject access requests go by many names — SARs and DSARs under UK GDPR, right-to-know requests under California's CCPA / CPRA, access requestsunder Brazil's LGPD or Canada's PIPEDA, disclosure requests elsewhere. The framework varies; the workload is similar. Deadlines range from 15 days (LGPD) to 30 days (PIPEDA, CCPA generally) to one calendar monthunder UK and EU GDPR (extendable to three for complex matters). Every regime expects you to verify identity, find the requester's data wherever it lives, redact third-party content, deliver on time, and stand behind every redaction decision if challenged.
The hard part isn't the law — it's the work underneath the law. Sweeping email accounts, document stores, recorded calls, scanned notes and dictation audio; detecting personal data accurately across multiple languages; redacting third-party identifiers in bulk; producing a disclosure bundle that survives regulator scrutiny. Smartbox automates that work end to end, so the same response process runs whether the request lands under UK GDPR, CCPA, LGPD or any of the other regimes.
Different requesters, same workflow
Five access-request types. One platform.
Whoever the requester is and whichever regime they're invoking, the workflow inside Smartbox is the same. The volumes, source types, and sensitivity differ — the platform absorbs that.
Employee access requests
HR files, performance and disciplinary records, manager comms, payroll, recorded interviews. UK GDPR, EU GDPR and employment-privacy regimes worldwide.
Patient / service-user requests
Medical records, clinician correspondence, scanned handwritten notes, dictation audio, safeguarding case files. UK NHS, EU healthcare regimes, HIPAA-adjacent requests in the US.
Customer requests
Account statements, transactional records, call recordings, complaint correspondence, KYC evidence. CCPA / CPRA right-to-know, LGPD access, GDPR Article 15 — handled from the same workflow.
Citizen requests to public authorities
Cross-service-area requests touching children's services, housing, social care, planning. Information-barriered review keeps service boundaries enforced by the platform.
Pupil / student requests
Academic records, safeguarding notes, disciplinary cases, parent communications. Trauma-aware review reduces reviewer exposure on sensitive content.
How Smartbox handles it
End-to-end on one platform.
Eight steps. Every step is a Smartbox capability working against the regime's clock, recording as it goes what a regulator would ask you to produce.
- STEP 01
Receive
The request lands in a central Smartbox inbox. The platform stamps receipt and sets the deadline to whichever clock applies — UK / EU GDPR's one month, CCPA's 45 days, LGPD's 15. Identity verification is the gate before unlock; that gate itself is logged.
- STEP 02
Triage
Assign owner. Categorise requester (employee, customer, patient, citizen, pupil) and regime invoked. Smartbox routes the case to the right workspace; information barriers prevent cross-matter exposure from the first click.
- STEP 03
Collect
Pull data from any source the requester's records live in: email, document stores, recorded calls, scanned notes, dictation audio, third-party drives, forensic extracts. If a regulated organisation produces it, Smartbox ingests it.
- STEP 04
Dedupe
Exact and near-duplicate removal automatically. Customers typically see file volume drop by up to 60% before review begins — proportional savings in reviewer time, classification cost, and storage.
- STEP 05
Classify
14 entity categories detected across text, tables, scans, and audio / video transcripts. Multilingual: English, French, German, Spanish, Portuguese plus additional languages on request — important for global organisations and cross-border requests.
- STEP 06
Review
Reviewers approve, override or annotate each classification. Information-barriered workspaces enforce matter-level isolation. Risk indicators flag content (trauma-sensitive history, privileged material, regulated-category data) for careful handling.
- STEP 07
Redact
One-click bulk redaction across the dataset. Apply by entity, pattern, or saved rule. Every redaction logged with the reviewer, time, rule applied or override given, and the document hash — defensible to any regulator's review.
- STEP 08
Disclose
Share the redacted bundle via a secure, time-bound link. Disclosed documents are flattened images — redactions are irreversible. Export the audit log for the ICO, CNIL, BfDI, CPPA, ANPD or any other DPA: it reconstructs who did what, when, on which file.
Proof
Up to 80% faster, on a review set 63% smaller.
Most of a subject access dataset is the same information several times over — email chains where content has been forwarded, replied to, and quoted back. Smartbox identifies and culls that duplication automatically, typically reducing the dataset by 63% before a reviewer opens the first file.
With the review set that much smaller and classification and bulk redaction automated, organisations handle requests up to 80% faster than a manual workflow. In healthcare, where a single request can take 52.5 hours to process by hand, one customer reduced a 36,000-file dataset to the 374 files that were actually relevant.
Every redaction decision stays reconstructable: which reviewer applied which rule, at what time, on which file hash — exportable for the ICO or any other supervisory authority.
With Smartbox.ai, we reduced our SAR response time from weeks to just a couple of days.
See access-request response on your own files.
A 30-minute demo with a product expert. We'll walk through your actual workflow — intake to disclosure, under whichever regime applies.