Playbook: Helping a Gym With a Subject Access Request

Set expectations first

The gym is the data controller. We supply a preparation tool; they decide what is disclosed and they respond to the member. Use the agreed wording: Bliply has gathered personal information held within Bliply that may be relevant to this request, and the gym must review it for third-party information, exemptions, completeness and information held outside Bliply before disclosing.

Steps

  1. Log the request against the member with the date it was received. The one-month deadline is shown from that date — if the gym is relying on an extension, record it explicitly.
  2. Gather. The pack is assembled across every category we hold. Expect hundreds of records for a long-standing member; volume is normal.
  3. Review with the gym. Walk them through Include, Redact and Exclude, and stop on anything flagged as third-party information. Do not make those calls for them.
  4. Approve. This builds the ZIP, including the template listing the response information only the gym can supply — purposes, categories, recipients, retention, sources and automated decision-making.
  5. Hand over. The gym downloads and delivers it themselves. Bliply never sends the pack to the member.
  6. Close the request once they confirm they have responded.

Things that go wrong

SymptomCause
Approval fails with "Bucket not found"The SAR storage bucket does not exist in that environment — create it and retry; review decisions are preserved
Download link has expiredLinks are short-lived by design; generate another
Pack has disappearedPacks expire after thirty days. The request record and audit trail remain — re-gather if it is still needed

Never

Never edit or delete records to tidy a request, never describe the pack as everything the member is legally entitled to, and never disclose on the gym's behalf.