How Fisar Works

From first request to final response

Every request follows the same controlled route. A person stays in command at the start and the end; intelligent automation does the heavy lifting in between – querying systems, removing duplicates, working out whose data is whose, then proposing redactions for your team to approve. The result is faster handling without surrendering judgement.

A school reception desk – where requests arrive

The eight-stage pipeline

A person in command at both ends

Automation in the middle; your DPO at the start and the end. Scroll the route a request takes below – every stage runs inside one protected environment.

1

Log & verify

DPO

The request is logged in minutes – who is asking, on whose behalf, what data and over what date range. Before anything is collected, Fisar guides identity verification, then the statutory clock starts automatically with a live, shared status.

2

Discovery & mapping

Automated

Personal data rarely sits in one place. Fisar scans every connected system to find which ones actually hold data about the requester, classifies what it finds by sensitivity, then builds a collection plan – all in read-only mode.

3

Parallel retrieval

Automated

Instead of working through systems one by one, Fisar queries them all at once, so total collection time is set by the slowest source – not the sum of them. Data arriving in different shapes is normalised into one structure.

4

De-duplication

Automated

The same email forwarded around, a letter saved in three folders, a screenshot of a message – compiled blindly, these bloat the response and double the review. Fisar removes duplicates intelligently, keeping the best copy so reviewers see each item once.

5

Attribution

Automated

Fisar identifies every person and reference in a document, maps the relationships between them, then decides item by item whether each belongs to the requester or a third party – working across text, images, audio and video, not just names.

6

Redaction

Automated

Crude redaction destroys meaning. Rather than black-barring everything, Fisar picks the right protection for each item – masking a face, replacing a name with [TEACHER], or removing a section entirely – and routes anything high-risk to a human.

7

Human review & approval

DPO

Fisar never sends anything out by itself. Everything lands in a review workspace where your DPO sees what was found, what was redacted and why. The riskiest, least-certain items come first; routine material is one-click. Every redaction can be accepted, adjusted or overridden – professional judgement always wins.

8

Secure delivery & proof

Secured

The approved response is compiled and delivered encrypted, with confirmation, well inside the deadline. Throughout, Fisar has fingerprinted every action into a tamper-evident certificate – cryptographic proof of compliance. Then it cleans up: working copies are destroyed 30 days after the case closes.

Under the bonnet

The engineering behind the pipeline

The heart of a SAR is separating the requester's own data – which must be disclosed – from other people's, which must be protected. Simple tools match on names and fail the moment a record says "his teacher" or "the visitor she signed in with". Fisar reads documents in context instead.

Deadline management

The 30-day due date is computed from the recorded date of receipt, with escalating alerts as it approaches. Identity documents are checked, the outcome recorded, then the documents are destroyed immediately afterwards.

A teacher working at a computer with paperwork to one side

Parallel distributed retrieval

Up to 50 concurrent workers per request, fault-isolated per source. Fisar learns each system's typical response time, sets timeouts accordingly, then retries slow sources automatically.

Three levels of de-duplication

Exact matching catches identical files, perceptual matching catches near-copies like rescans, then semantic matching catches paraphrased or reformatted content.

Stacks of paper case files – the manual workload Fisar removes

Graduated redaction

Attribution is driven by a model trained on 50,000 expert-labelled SAR documents. Redaction applies four graduated levels – mask, replace, remove, pseudonymise – scored by risk; critical or low-confidence items always escalate to a person.

See the pipeline live

Nothing is released until a DPO has reviewed and approved it.

Watch a request travel all eight stages – live, in a sandbox, with dummy data.