A data subject request is not a legal problem, it is an operational one. The law says what has to happen and by when; everything hard about it is finding where the data is and proving afterwards that you looked. These are the six steps, in the order they happen, with the trap in each.
Log it, on the day it arrived
The receipt date is the only figure in the whole process you cannot reconstruct later, and every deadline runs from it. A request does not have to say data subject request, cite a law, or arrive at a special address. If a person asks what you hold about them, the clock has started, wherever they asked.
Identify the person, proportionately
You have to be reasonably sure you are not handing somebody's data to a stranger, and you must not use identity checks as a delaying tactic. Matching against the account the request comes from is usually enough; demanding a passport scan for a mailing-list enquiry is both disproportionate and a new pile of sensitive data you now hold.
Scope the ask
Access, deletion, correction, portability and opt-out are different requests with different work behind them. Ask which if it is not clear, and note that asking does not stop the clock in most regimes. Write the scope down: it is what you will be judged against.
Search, and write down where you searched
The list of systems is the deliverable nobody expects. CRM, helpdesk, mailing tool, billing, backups, the spreadsheet on somebody's drive. The value of the list is not the answer, it is that six months later you can show what was in scope of the search rather than asserting it.
Decide what does not go out
Other people's personal data in the same records, material subject to legal privilege, and information that would reveal a trade secret are the usual exclusions. Withholding is allowed; withholding silently is not. Say that something was withheld and on what basis.
Answer, and keep the record
What went out, when, and who approved it. California Civil Code section 1798.130(a)(2) requires the business to disclose and deliver, correct or delete within 45 days of receipt, extendable once by another 45 with notice inside the first period. Article 12(3) of the GDPR gives one month from receipt, extendable by two further months.
Questions people ask about data subject request
Does a request have to be in writing?
Not under the GDPR, where a verbal request counts. That is the strongest argument for logging one the moment it arrives, because a phone call with no record is a deadline you will miss without knowing.
Can we charge for it?
Generally no for the first request. Both regimes allow a fee or a refusal only where a request is manifestly unfounded or excessive, and repetition alone does not make it so.
What if the data is in backups?
Say so. A deletion request generally reaches live systems immediately and backups on their normal rotation; the honest answer is the retention period after which the backup copy goes, and that is a figure you should know.