DSAR handling and retention evidence: ISO 27001 for credit and collections
Regulators and ISO 27001 auditors both want to see the same things when it comes to DSAR handling and data retention in credit and collections: an audit trail, a working schedule, and destruction evidence. This guide covers what that looks like in practice.
By Kellwick Team · August 9, 2026 · 7 min read
A data subject access request in a credit and collections context is not like a DSAR at a retailer or a software company. The data held by a collections firm about a data subject is extensive, spans multiple systems, includes third-party data from credit bureaus and original creditors, and may include records the data subject actively wants to challenge. The DSAR arrives, frequently, from a data subject who is in dispute with the firm about a debt - which means the response will be scrutinised by the subject, their representative, and potentially the FCA or the Financial Ombudsman Service.
ISO 27001 does not mandate DSAR handling procedures directly. But it does require a systematic approach to personal data processing as part of the ISMS, and any ISO 27001 assessor with a financial services background will examine the DSAR and retention evidence carefully. More practically, the ICO's enforcement record in credit and collections includes cases arising from DSAR handling failures - responses that were late, incomplete, or that failed to apply the correct exemptions. The same failures that generate ICO enforcement also generate ISO 27001 findings.
The DSAR audit trail: what an auditor and a regulator both want
The core requirement for DSAR evidence is a log. The log should be a contemporaneous record of each DSAR received, the steps taken to respond, and the outcome. An audit trail reconstructed from email threads after the fact is not equivalent to a log maintained in real time, and both an auditor and an ICO investigator will notice the difference.
A DSAR log in a collections environment should capture: the DSAR reference, the date received (which starts the one-month response clock), the data subject's name and account reference where known, the systems searched and the data categories identified, any exemptions applied and the reason, the response date, whether an extension was taken and on what grounds, and the date of any follow-up correspondence or complaint arising from the response.
The log serves multiple functions simultaneously. It is the ISO 27001 evidence that the process is operating. It is the FCA audit trail for Consumer Duty compliance. It is the ICO documentation that the firm can produce if a DSAR complaint is made. Building it once and maintaining it serves all three.
Scope of a DSAR in collections: the multi-system problem
Collections firms typically hold data about a subject across a larger number of systems than any other financial services category. There is the collections management system (the primary account record), the telephony system (call recordings), the SMS and email platform, credit bureau query logs, affordability assessment records, the original creditor's data if the account was purchased, internal notes added by agents, quality assurance or compliance notes, complaint records, and litigation documents if legal action was taken.
Each of these systems is a separate search requirement under a DSAR. The process documentation that an ISO 27001 auditor wants to see includes: a system inventory for DSAR purposes (which systems hold personal data that may be in scope for a DSAR response), a search procedure for each system, and evidence that searches were conducted as part of the DSAR response.
The practical gap in many collections firms is that the system inventory for DSAR purposes has never been formally documented. Individual staff know which systems to check because they have done it before, but there is no written procedure and no record of which systems were searched for a given DSAR. When a data subject complains that their call recordings were not included in a DSAR response, the firm cannot demonstrate that the telephony system was searched.
Exemptions and third-party data: the evidence of considered decisions
A DSAR in a credit context will frequently surface data about third parties - details of a guarantor, notes about a conversation with a debt advice charity, information provided by the original creditor that relates to another individual on the account. That data may need to be withheld or redacted before disclosure.
The evidence of applying exemptions correctly is a note on the DSAR record: "recording of 14 March 2025 withheld - contains personal data of third party, redaction not practicable." That note is the documentation that a considered decision was made rather than that data was withheld arbitrarily. Without it, the DSAR response cannot be defended to the ICO or to the data subject.
Legal professional privilege is another common exemption in collections DSAR responses, where correspondence with solicitors about enforcement action is withheld. The evidence requirement is the same: a note on the DSAR record identifying the material withheld and the basis for the exemption.
Retention schedules: the document and the evidence that it works
A retention schedule in a collections firm needs to address at least the following data categories: account records (including the history of the debt), payment records, affordability assessment data, call recordings, written correspondence, complaint records, litigation files, and credit bureau query logs. Each category should have a defined retention period with the legal or regulatory basis for that period noted.
The regulatory landscape for retention in credit and collections includes: the FCA's CONC rules, which require certain records to be retained for defined periods after the end of the customer relationship; GDPR's storage limitation principle; and the Limitation Act, which defines the period within which legal claims can be brought and is frequently used to justify retention of account records.
An auditor reviewing a retention schedule will look for three things beyond the document itself: evidence that the schedule was approved at an appropriate level, evidence that it has been reviewed within the last 12 months, and evidence that it is implemented rather than aspirational.
The implementation evidence is the part most often missing. A retention schedule document approved two years ago and filed on a SharePoint site is not evidence of a working retention programme. The evidence of implementation includes: automated deletion rules configured in the collections management system and the telephony platform; a deletion or archive log showing records were processed in accordance with the schedule during the last review period; and a review note confirming that the schedule was assessed against any regulatory changes in the last 12 months.
Destruction evidence: closing the loop
When data is deleted or destroyed in accordance with the retention schedule, the destruction event needs to be recorded. This is not a heavy administrative burden - a system-generated deletion log or a quarterly archive and purge report from the collections platform is typically sufficient - but without it there is no way to demonstrate to an auditor that the retention schedule is being followed rather than ignored.
For physical records - paper debt files, printed affordability assessments - destruction evidence means a certificate of destruction from the secure document destruction provider, retained and filed against the destruction event in the asset register.
The destruction record also matters for erasure requests under GDPR Article 17. Where a data subject requests erasure and erasure is confirmed, the record of what was deleted, when, from which systems, and whether any data was retained under a legal hold needs to exist and be findable if the data subject or the ICO asks for confirmation.
The overlap between audit evidence and regulatory evidence
The single most practical thing a collections firm can do with DSAR and retention evidence is to build it so that it is usable by both the ISO 27001 audit team and the compliance team responding to regulatory enquiries. That means keeping all DSAR records in one system, keeping retention schedule documentation in the ISMS document set, and making the deletion logs accessible to compliance without requiring an IT ticket.
The convergence is real. An ICO investigation into a DSAR complaint will ask for the same evidence that an ISO 27001 auditor asks for during a certification assessment: the log, the search records, the exemption notes, and the response. Building a single, well-maintained record that answers both sets of questions is more efficient than maintaining parallel documentation for each compliance framework.
For collections firms approaching ISO 27001 certification, the DSAR and retention evidence is rarely the hardest control area to address - but it is one of the most frequently under-documented. The controls usually exist in some form. The evidence that they operate systematically is what is missing.
Where Kellwick fits
Kellwick provides independent ISO 27001 readiness advisory to credit and collections firms, working through DSAR processes and retention schedules as part of a structured ISMS gap assessment. Kellwick reviews the full evidence picture - log, schedule, implementation, destruction - against what both a certification auditor and a regulator would expect to find. If your firm needs a structured readiness review before a certification assessment or an FCA visit, our credit and collections readiness service is the right place to start.
Need a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.