Skip to content

Subject access requests

How to export everything Certaria holds about one person, what to check before you release it, and the folder permission you must set first.

Audience: ISMS Admin responding to a subject access request under UK GDPR.

What this does: for a named individual, exports every Certaria record linked to them as a set of CSV files in your SharePoint site, and records that the request was fulfilled.

You will also need the individual’s record in Certaria, and their record identifier.

  1. Open the ISMS Management Hub app.
  2. Go to Persons and open the individual’s record.
  3. Copy the value of the id= parameter from your browser’s address bar. It is a 36 character identifier.
  1. Go to Solutions, then Certaria, then Cloud flows.
  2. Open Certaria: Export Subject Access Request.
  3. Select Test, choose Manually, then Save and Test.
  4. Paste the identifier from Step 1 into TargetPersonId.
  5. Select Run flow, and wait for the run to finish.

The run’s response gives you the folder location, the number of tables exported, the number of rows, and an error count.

Step 3: check the export completed cleanly

Section titled “Step 3: check the export completed cleanly”

Open the folder from the response. It contains two kinds of file:

  • Structured records. One file per table, holding rows where the individual is directly linked.
  • Free text matches, each named REVIEW-REQUIRED. These hold rows where the individual’s name appears in a free text field, such as an external trainer or external auditor name.

If the error count is above zero, the response names which tables failed. The usual causes are a permission change or a table being briefly unavailable. Re-running is safe and does not duplicate data.

This step is not optional, and it is the one that needs your judgement.

Each REVIEW-REQUIRED file was built by searching free text fields for the individual’s name. A match is not proof that the row is about them.

  1. Open each file.
  2. Read every row, and confirm it genuinely refers to the data subject rather than to someone else with the same name.
  3. Delete any row that turns out to be a different person.
  4. A file with no rows can be deleted, or kept as evidence that the field was searched and produced nothing relevant.
  1. Download the folder from SharePoint. Right click the folder, then Download, and SharePoint gives you a ZIP.
  2. Open each file and check it reads sensibly: headings should be readable labels, choices should show words rather than numbers, and dates should be legible.
  3. Add a covering note explaining the individual’s rights and how to read the pack.
  4. Deliver it by whatever channel your privacy notice specifies.

The export automatically creates a task recording that the request was fulfilled: what was exported, when, where it was put, and the counts.

Find it under ISMS Tasks, filtering on the task name SAR Export. This is your documented evidence that the request was answered, and it is what you show if the response is ever questioned.

SymptomCauseFix
A free text file is empty when you expected matchesThe name may genuinely not appear in free text, or the individual’s record is anonymised, in which case free text searching is skippedOpen the run history and check whether the name resolved
”Folder already exists”A request was already exported for this person todayRe-run. The second run replaces the files
A choice column shows a number instead of a wordThat row did not return its readable labelNote which table, and report it
The run fails on a free text searchThe name contains an apostropheSee the caution above, and search those fields manually