Statement of applicability: the one ISO 27001 document auditors read first
The SoA lists every Annex A control, whether you apply it, and why. It is the map between your risk assessment and everything else in the certificate.
A DSAR is not a support ticket. The clock starts on receipt, the scope is everything, and the exemptions are narrower than most teams assume.
A data subject access request — a DSAR — is a person asking what personal data you hold about them, why, who you share it with, and for a copy of it. Under the GDPR and the UK equivalent it must normally be answered within one month, free of charge, and it can arrive in any form: an email, a phone call, a sentence at the end of a complaint.
That last point causes most of the failures. There is no required wording and no form the requester must use. A message saying "send me everything you have on me" is a valid DSAR, and the month starts when it reaches any part of your organisation — not when it reaches the person who knows what to do with it.
Personal data is broader than a record with their name on it. Emails discussing them, meeting notes mentioning them, CCTV, call recordings, internal messages about a complaint they raised — all of it is in scope if it identifies them and you still hold it.
The one-month deadline may be extended by two further months where the request is complex or there are several — but you must tell the requester within the original month, and say why. An extension taken silently is a breach even if the eventual response is complete.
Three patterns recur. The request sits in a shared inbox for three weeks because nobody recognised it. The search misses email, which is where most of the relevant material actually is. And third-party data is disclosed in a rush to meet the deadline, turning a routine request into a personal data breach of somebody else.
A fourth is less obvious: treating a DSAR as adversarial. Many arrive from ex-employees or during a dispute, and the temptation is to minimise. Regulators look at whether the search was reasonable and the reasoning documented — not at whether the answer suited you.
Because a DSAR ends in an evidence question — what did you search, what did you withhold, when did you respond — it belongs in a record rather than in an email thread. Ettex Records holds the request log, the searches performed, the redaction decisions and the response, so the file that answers a regulator exists as a by-product of doing the work. The data retention policy matters here too: data you no longer hold is data you do not have to disclose.
One month from receipt, extendable by two months for complex or numerous requests, provided you inform the requester of the extension and the reason within the first month.
Not normally. A reasonable fee may be charged for manifestly unfounded or excessive requests, or for further copies — and the bar for calling a request excessive is high.
Only in limited circumstances: manifestly unfounded or excessive requests, or where an exemption applies. Refusal has to be explained, with the person told of their right to complain.
Yes, where they identify the person — including emails about them rather than to them. Excluding mailboxes from the search is one of the most common reasons a response is later found inadequate.
The SoA lists every Annex A control, whether you apply it, and why. It is the map between your risk assessment and everything else in the certificate.
Sarbanes-Oxley is short. What consumes a finance team is proving that controls operated all year — and proving it with records made at the time.
Access accumulates. A user access review is the periodic check that every permission still has a reason — and the record proving someone looked.