Transparent technology and pay-as-you-go handling, with an experienced Data Protection Officer available to help you work out what you actually need. Most organisations arrive one of three ways — pick the one that sounds like you.
Someone has asked for their data and the clock is already running. We can take a single request off your hands — no contract, no software to install, and no commitment beyond this one.
Get help with this requestYou handle these regularly, volumes are climbing, and the people doing the work usually have a different day job. Start by finding out what it's genuinely costing — including the parts that never reach a budget line.
See what they're really costingManaged handling end to end, with legal sign-off before anything is released. Start with a free consultation with an experienced DPO — we'll tell you honestly whether outsourcing is the right answer for you.
Book a free DPO consultationSix steps, and it's clear at every one whose move it is. You keep the decisions that have to be yours — what's in scope, and what gets released — and we take the work around them.
Not an ambiguous email in a general inbox. The requester's identity has been checked before it left our platform, and the request states plainly which categories of data it covers — so you can start work instead of starting a conversation.
You review what's being asked for and confirm it, or narrow it with a reason. If clarification is genuinely needed the clock pauses and both sides can see that it has — which protects you, because a pause you can evidence is very different from a delay you can't.
Before anything is reviewed or processed, identical files and the quoted history inside email chains are removed, so the same paragraph isn't read forty times. This happens first deliberately: it cuts the volume needing review, and it means less of your data goes through any processing step at all.
Names, contact details, reference numbers and third-party information are located automatically and presented to you as suggestions — highlighted, with a reason, for you to accept or reject. Nothing is redacted or released silently on your behalf.
A paralegal or solicitor from our legal partner reviews the package, and you approve the release. Where an exemption is being applied, it's recorded against the specific material and the basis for it.
The requester receives it securely through their own dashboard. You keep a dated record of what was disclosed, what was withheld and why, and when each step happened. If a response is ever challenged, that record is what you'll be asked for first.
The difference isn't how much work gets done. It's who owns the process. All three are available pay-as-you-go per request, or on a fixed term of 3, 6 or 12 months — no software licence, no per-seat fees, no credit bundles, and nothing that expires.
For experienced teams who have the process and the people, and just want better tooling without signing a multi-year licence.
Someone off sick or on long leave. A resignation with a gap before the backfill. One tribunal case swallowing the team. You know exactly what needs doing and haven't got the hands.
For organisations with no privacy function, or one already past capacity — and anyone whose current answer is "send it to the solicitor".
From £250 for a routine request. Anything larger or more complex is quoted before we start, never after — instead of the £1,500–£3,000 businesses tell us a single request typically costs them through a lawyer or an external DPO.
A routine request might take four or five hours end to end. A genuinely complex one runs to forty or more. But the shape is the same either way: locating and collating records, stripping duplicates, finding third-party data, deciding what's withheld, and drafting the response — and only the deciding needs your judgement.
So that's how we split it. The technology does the locating, the de-duplication and the first pass at identifying personal data, and puts it in front of a person to confirm. Scoping and professional review stay with a qualified reviewer, because they should. Nothing is redacted or released without someone deciding it should be.
There's no software to license or maintain, and no per-seat charge. You pay for requests handled, when you actually have one.
We sit between you and the requester as a neutral party, so the same record of what was asked, what was provided, and what was withheld is visible to both sides. For an organisation that handles data properly, that visibility is an asset — it's the difference between saying you were reasonable and being able to show it.
It's the right thing to ask, and the answer is in how we're paid. We make nothing from the volume of requests. Handling them is free for individuals, and the identity check they pay for is a cost we pass on, not a margin — so a thousand junk requests would earn us nothing while destroying the only thing that makes us useful to you. Our revenue comes from organisations that want requests handled well. That means our interest is in fewer, better-formed requests — genuine ones, correctly scoped, from people who are who they say they are.
Every request that reaches you has had its requester identity-checked by a certified third party. You are not the one deciding whether an anonymous email is genuine, and you are not paused waiting to find out.
Repeat submissions of the same request are caught before they reach you, and the verification step deters the casual and vexatious traffic that makes an open inbox unmanageable.
Requests arrive naming the categories of data they cover. Most disputes about a response are really disputes about what was asked for — settling that at the start is what stops a request becoming a complaint.
| Dimension | Manual Handling | Data Defenders |
|---|---|---|
| Average turnaround time | Often near statutory limit | Tracked against deadline, faster review |
| Who does the review | Whoever is available — often senior or clinical staff | Only scoping and review need a qualified person |
| Data put through processing | Everything gathered, reviewed in full | Reduced by de-dup, de-threading and scoping first |
| Who decides what's withheld | You | Still you — proposed, never applied silently |
| Audit trail | Assembled after the fact, if at all | Recorded as you go, and yours to keep |
| Technology cost | Licensed platform + internal cost | No licence, no per-seat — pay-as-you-go |
Reduced DSAR handling time significantly against a small in-house team.
Cut annual spend versus legacy tooling while meeting FOI obligations.
Processed multi-TB requests within statutory deadlines.
Illustrative, anonymised examples by organisation type — not named clients.
Most businesses don't sign up in advance — walk through the first email and login a DPO actually sees.
Five questions on who actually does this work in your organisation, and what it's costing you that never reaches a budget line.
A free 45-minute conversation about your process — including an honest answer on whether you need us at all.
See exactly how request packages are encrypted, verified, and processed on our dedicated Trust & Security page.
Not a sales call with a technical specialist on the line. A conversation with someone who has actually run this function, about what your process looks like now and where the time is really going.
One conversation, about 45 minutes, with an experienced Data Protection Officer. No obligation to buy anything afterwards, and no pressure if the answer is that you're fine as you are.
Book Your Free ConsultationWe'll ask for your sector and rough request volume when you book, so the conversation starts somewhere useful.
We're deliberately technology-agnostic. We use whichever tools are genuinely best for the job and we change them when something better arrives — which means we aren't reselling a vendor's licence, and we've no reason to push your data through a particular system just because we're committed to it. That matters more than it sounds.
Most AI-based compliance tooling is metered on data ingested and exported. Which means your bill is set by whoever on your team uploads the least carefully — and it's the one cost you can neither forecast nor police.
Our answer isn't a discount, it's a different order of operations. Duplicates, repeated email threads and out-of-scope material come out before anything is processed, and the people doing it are trained not only in what can and can't be withheld, but in keeping the volume that reaches any processing step as small as it legitimately can be. Knowing what's legally out of scope is the volume reduction — which is a lever a pure-software vendor doesn't have, because excluding material is a legal judgement, not a setting.
Less data ingested costs less. It's also more defensible, and it's better data protection practice — putting 50GB of unfiltered material through any system is itself a processing decision you'd have to justify. One decision paying off three ways.
You don't buy an allowance up front and race to use it before it lapses. You pay for requests handled, when you have one to handle — so there's no unused balance, and no cliff edge when it runs out.
If a request is large enough to change what it costs, you hear about it before anything is processed — with an estimate — and you decide whether to proceed. Surprises arrive in the invoice on other people's platforms, not on ours.