For Data Protection OfficersInternal Individual SAR

Internal Individual SAR

Run a request for someone inside your organisation - an employee, student or volunteer - against a connected system.

Use this route when the person whose data is being requested is a current member of your organisation.

Watch the full walkthrough

Before you start

  • You must be logged in to a DPO account, not the organisation dashboard
  • The system you want to search must be connected - see Connecting Your Systems
  • You need the requester's name and email address

Step by step

Click New SAR

Then choose Create a SAR, then Internal individual.

Enter the requester's details

Name and email address of the person making the request.

Select the individual

Choose the person inside your organisation whose data is being requested. This may or may not be the same person as the requester.

Set a date range (optional)

Narrow the search to a specific period if the request calls for it.

Add keywords (optional)

Add names, phrases or identifiers to guide the search and control what stays unredacted.

Confirm verification

Confirm you have obtained and checked everything needed to run the request.

Review the connection

Fisar shows what it is connected to - for example drive files, email, SharePoint and chats - in green.

Set a password

Create the password for the secure archive. This will be shared with the requester, so do not reuse a password you use elsewhere.

Proceed

The request is created and starts running.

Internal individual SAR form showing requester details and individual selection
Internal individual SAR form showing requester details and individual selection
Second page of the internal individual SAR form showing verification and password fields
Second page of the internal individual SAR form showing verification and password fields

Keywords and name variants

Keywords are how you tell Fisar what belongs to the requester.

If the individual is recorded in different ways across your systems - "Joe Bloggs" in one place and "Joseph Michael Bloggs" in another - Fisar will generally detect the variants itself. Adding keywords makes this more reliable.

The requester's own name should remain unredacted in the response. Everyone else's should not. Keywords are what draw that line.

What happens next

Open SAR Monitoring to watch progress. The request moves through acknowledgement, ID verification, data gathering, transformation and redaction.

When it reaches Redaction Completed, it is waiting for you. Continue to Reviewing & Delivering.