Set expectations first
The gym is the data controller. We supply a preparation tool; they decide what is disclosed and they respond to the member. Use the agreed wording: Bliply has gathered personal information held within Bliply that may be relevant to this request, and the gym must review it for third-party information, exemptions, completeness and information held outside Bliply before disclosing.
Steps
- Log the request against the member with the date it was received. The one-month deadline is shown from that date — if the gym is relying on an extension, record it explicitly.
- Gather. The pack is assembled across every category we hold. Expect hundreds of records for a long-standing member; volume is normal.
- Review with the gym. Walk them through Include, Redact and Exclude, and stop on anything flagged as third-party information. Do not make those calls for them.
- Approve. This builds the ZIP, including the template listing the response information only the gym can supply — purposes, categories, recipients, retention, sources and automated decision-making.
- Hand over. The gym downloads and delivers it themselves. Bliply never sends the pack to the member.
- Close the request once they confirm they have responded.
Things that go wrong
| Symptom | Cause |
|---|---|
| Approval fails with "Bucket not found" | The SAR storage bucket does not exist in that environment — create it and retry; review decisions are preserved |
| Download link has expired | Links are short-lived by design; generate another |
| Pack has disappeared | Packs expire after thirty days. The request record and audit trail remain — re-gather if it is still needed |
Never
Never edit or delete records to tidy a request, never describe the pack as everything the member is legally entitled to, and never disclose on the gym's behalf.