A workflow is only useful if each state has an exit condition somebody can check. Without that it is a set of labels people move around a board. These are the five states a request actually moves through and what has to be true to leave each one.
Received: the date is recorded
Exit condition: the receipt date and the channel it arrived on are written down. Not the date somebody noticed. The whole deadline is measured from this field, so a workflow that starts at triage has already lost days it cannot get back.
Identified: you know who is asking
Exit condition: a recorded basis for believing the requester is who they say. In most cases that is the account the request came from. Note the date identification completed even where the clock does not pause, because the gap between receipt and identification is the part you will be asked about.
Scoped: you know what was asked for
Exit condition: the request is classified as access, deletion, correction, portability or opt-out, and the date range and systems in scope are stated. Vague requests get scoped by asking, and the question and answer both belong in the record.
Searched: you know where you looked
Exit condition: a list of systems searched with a date and a person against each. This is the state most workflows skip and the only one that produces evidence. It is also where the real elapsed time goes.
Answered: it went out, and you can prove it
Exit condition: what was released, what was withheld and on what basis, who approved it, and the date sent measured against the deadline. California allows 45 days from receipt with one 45-day extension on notice; the GDPR allows one month with a two-month extension.
Questions people ask about dsar workflow
Should the clock pause during identification?
Do not build on the assumption that it does. Regimes differ and the safe design counts every day from receipt, so a delay in identification eats your own slack rather than the requester's.
How many people should touch a request?
As few as possible, with one named owner. What matters more than the count is that each action is recorded against the person who took it, because that is what an audit reconstructs.
What does a good workflow look like at ten requests a year?
A logged receipt date, a named owner, a searched-systems list and a sent date. That is genuinely enough at that volume, and the reason to put it in a tool rather than a spreadsheet is that a tool cannot forget the receipt date.