Every step, who's responsible for it, and how each side gets confirmation of what's just happened. This is the model behind the tracker and the request wizard.
You land on Data Defenders and choose to start a request against a specific business.
e.g. "Former Employee" — this is what pulls the correct, pre-built request template rather than a generic one.
Enter the business, and confirm their Data Protection Officer or compliance contact if you know one. Where we already have one registered on file, we route straight to them — otherwise it goes to their general compliance inbox.
Review the categories we've pre-selected for your situation. Untick anything irrelevant, or add something specific to your case.
Private context only — never shared with the business. Helps us, and any legal partner you later choose, scope the case correctly.
Dashboard-only, or dashboard plus encrypted email status updates. Whichever you pick, your contact email is encrypted and used only for this request — never marketing.
A quick biometric check via our identity partner. The raw photo is deleted immediately once verification completes.
You get a timestamped confirmation and reference number the moment it's transmitted. The £10 fee is taken here (refunded in full if the business signs up to handle it themselves).
Opening the request logs a read receipt on your tracker. If nobody acknowledges within 48 hours, we send an automatic reminder — so "we never got it" isn't a valid excuse.
The statutory clock is running. They may pause it once, with a logged reason, to ask you to clarify scope.
They confirm they'll comply as scoped, and move to preparing the disclosure — using their own tools, or our AI tools.
The finished, redacted package is uploaded and released through the portal.
Download and auto-clear from our servers, or escalate to a pre-vetted legal partner if the business misses the deadline.