- Documentation
- Help
Subject access requests
How to export everything Certaria holds about one person, what to check before you release it, and the folder permission you must set first.
Audience: ISMS Admin responding to a subject access request under UK GDPR.
What this does: for a named individual, exports every Certaria record linked to them as a set of CSV files in your SharePoint site, and records that the request was fulfilled.
Before your first request
Section titled “Before your first request”You will also need the individual’s record in Certaria, and their record identifier.
Step 1: find the person’s identifier
Section titled “Step 1: find the person’s identifier”- Open the ISMS Management Hub app.
- Go to Persons and open the individual’s record.
- Copy the value of the
id=parameter from your browser’s address bar. It is a 36 character identifier.
Step 2: run the export
Section titled “Step 2: run the export”- Go to Solutions, then Certaria, then Cloud flows.
- Open Certaria: Export Subject Access Request.
- Select Test, choose Manually, then Save and Test.
- Paste the identifier from Step 1 into TargetPersonId.
- Select Run flow, and wait for the run to finish.
The run’s response gives you the folder location, the number of tables exported, the number of rows, and an error count.
Step 3: check the export completed cleanly
Section titled “Step 3: check the export completed cleanly”Open the folder from the response. It contains two kinds of file:
- Structured records. One file per table, holding rows where the individual is directly linked.
- Free text matches, each named
REVIEW-REQUIRED. These hold rows where the individual’s name appears in a free text field, such as an external trainer or external auditor name.
If the error count is above zero, the response names which tables failed. The usual causes are a permission change or a table being briefly unavailable. Re-running is safe and does not duplicate data.
Step 4: review the free text matches
Section titled “Step 4: review the free text matches”This step is not optional, and it is the one that needs your judgement.
Each REVIEW-REQUIRED file was built by searching free text fields for the individual’s name. A match is not proof that the row is about them.
- Open each file.
- Read every row, and confirm it genuinely refers to the data subject rather than to someone else with the same name.
- Delete any row that turns out to be a different person.
- A file with no rows can be deleted, or kept as evidence that the field was searched and produced nothing relevant.
Step 5: compile and deliver
Section titled “Step 5: compile and deliver”- Download the folder from SharePoint. Right click the folder, then Download, and SharePoint gives you a ZIP.
- Open each file and check it reads sensibly: headings should be readable labels, choices should show words rather than numbers, and dates should be legible.
- Add a covering note explaining the individual’s rights and how to read the pack.
- Deliver it by whatever channel your privacy notice specifies.
Step 6: confirm the audit trail
Section titled “Step 6: confirm the audit trail”The export automatically creates a task recording that the request was fulfilled: what was exported, when, where it was put, and the counts.
Find it under ISMS Tasks, filtering on the task name SAR Export. This is your documented evidence that the request was answered, and it is what you show if the response is ever questioned.
Common failure modes
Section titled “Common failure modes”| Symptom | Cause | Fix |
|---|---|---|
| A free text file is empty when you expected matches | The name may genuinely not appear in free text, or the individual’s record is anonymised, in which case free text searching is skipped | Open the run history and check whether the name resolved |
| ”Folder already exists” | A request was already exported for this person today | Re-run. The second run replaces the files |
| A choice column shows a number instead of a word | That row did not return its readable label | Note which table, and report it |
| The run fails on a free text search | The name contains an apostrophe | See the caution above, and search those fields manually |
- Exporting your data, the bulk equivalent for offboarding or migration
- Who can see and do what, including why personal details are administrator only
- Your SharePoint site