Chapter 5
Run your first request end to end
Follow one request from submission to secure delivery, and see where each screen fits.
Run your first request end to end
The best way to learn the flow is to submit a test request yourself, to your own intake portal, using a personal email address you control.
1. Submit
Open your intake portal and submit an access request. You'll get a confirmation email with a verification link and a reference like DSAR-7K2M9QX4.
2. Verify
Click the verification link in the email. That proves control of the email address and starts the legal clock. Back in the console, the request moves out of "verifying" and any matching workflow template fires: collection tasks appear, routed to each data source's owner.
If a request needs stronger proof (or someone is asking on another person's behalf), documents can be uploaded from the tracking page, and you confirm identity manually on the request's detail page. Identity documents are deleted automatically the moment you verify, so you're never storing passports longer than needed.
3. Collect
Watch the tasks complete. Team members work from My tasks; contact owners get their email link. Uploaded extracts attach to the request as collected artifacts.
4. Package and sign off
When every task is done, build the delivery package from the request detail page. Review what's included, then record the DPO sign-off. Sign-off is required before anything can be delivered.
5. Deliver
Send the delivery. The requester gets an email with a secure link; opening it requires a one-time passcode emailed to their verified address. Downloads are available for the number of days you set in Settings (14 by default).
6. Close
Once delivered, close the request. The requester can leave feedback, and everything you did along the way is recorded in the tamper-evident audit trail.
That's the whole loop. From here, explore the Help Centre articles for the deeper features: duplicates and merging, appeals, erasure attestations, retention, and reporting.