A common scenario for Bristol's software and platform businesses: someone sends a SAR to the company because its product holds their data — but the company is only processing that data on behalf of a client. Responding directly can be as much of a mistake as ignoring the request.

We help organisations across Bristol and the South West get the role right, then handle review, redaction and the disclosure pack for requests they are responsible for.

Controller or processor — who must respond?

The controller decides why and how personal data is used, and it is the controller who must respond to a SAR. A processor acts on the controller's instructions. If you receive a SAR for data you hold purely as a processor, pass it to the relevant client promptly and help them respond, as your contract with them should require.

Most technology businesses are both: a controller for their own employees, contractors and direct customers, and a processor for client data held in their platform. The same person can appear in both — a client's user who is also a former employee — so triage at the start matters.

Data scattered across tools

In a modern software business, an employee's personal data can sit in Slack or Teams, Jira or Linear, GitHub history, Google Workspace, HR and payroll platforms and a CRM. Few of these are searched routinely, and exports often need processing before they can be reviewed.

We agree the list of systems with you at the start, so the search is proportionate and complete — and so you can explain your approach if the scope is ever questioned.

Aerospace, engineering and research

Bristol's aerospace and engineering employers, and its universities, hold personal data alongside commercially sensitive technical material. Commercial confidentiality alone doesn't justify withholding someone's personal data, but where a document mixes both, technical content that isn't personal data about the requester can legitimately be left out.

Sectors we support in the South West

Technology and SaaS

Controller and processor roles, product data and collaboration tools.

Aerospace and engineering

Personal data mixed with technical and commercially sensitive material.

Higher education

Student and staff requests across the city's universities.

Creative and digital agencies

Client data held under contract alongside the agency's own HR records.

How we handle your SAR remotely

  1. Tell us about the request — the systems involved, the date range and your deadline. We confirm a fixed fee within 24 hours.
  2. Upload the documents to an encrypted, access-controlled workspace. Nothing is emailed.
  3. Our specialists review every item and redact third-party and exempt information, logging the legal basis for each decision.
  4. You receive a finished disclosure pack, covering letter and redaction schedule, ready to send.

Every case is quoted individually on the size and complexity of your dataset, and the fixed fee is agreed before any work begins.

Received a SAR in Bristol?

Tell us the scope and your deadline, and we'll confirm a fixed fee within 24 hours. No commitment required.

Get Your Free SAR Assessment →or call 01244 261 379

Frequently asked questions

We received a SAR but we're only the processor. What should we do?

Don't respond to the substance yourself. Forward it to the controller — your client — without delay, and give them the help your contract requires to meet their deadline.

Do Slack and Teams messages count in a SAR?

Yes. Messages that contain the requester's personal data are in scope, including those in channels and direct messages, subject to the usual third-party and exemption assessments.

Can we withhold commercially sensitive information?

Commercial sensitivity alone isn't grounds to withhold the requester's personal data. But information that isn't their personal data — technical detail, for example — isn't within the scope of the SAR in the first place.