Legal & Compliance
List and de-duplicate the files for a DSAR response
Upload the files collected for a subject access request as a ZIP. You get a file list with duplicates and junk flagged. It does not redact or judge completeness.
or drop it here
- ZIP / CSV / XLSX
- Up to 2,000 files
1 prepared source file · 216 bytes
- Files: 2
- Unique files: 2
- Coverage claim: inventory only
file-inventory.csv · organized-source.zip · findings.csv · manifest.json
One clear job, from source to download
- 1
Add the source
Supported formats and limits are visible before the upload.
- 2
Confirm the settings
Review the exact source, options, units and access before processing.
- 3
Inspect and download
Check the preview and warnings, then unlock the complete package.
Sort the files collected for an access request
What you upload
You upload the files collected for a data subject access request, usually as a ZIP. CSV and XLSX are accepted too. One job takes up to 2,000 files. A larger set is rejected before processing, not inventoried in part. These exports often hold sensitive data from several systems. You get 3 free jobs a day without signing up, and failed jobs do not count.
Reading the inventory
You get file-inventory.csv, findings.csv, organized-source.zip and manifest.json. Each file gets a hash, a fingerprint of its content. Files with the same hash are grouped as exact duplicates, even under different names. A re-saved document has a new hash and counts as a separate file. Junk such as thumbnail caches is flagged, and untyped files are listed. Nothing is deleted. The ZIP is a copy, and your export stays unchanged.
What stays with your privacy reviewer
There are no settings. The tool does not identify the requester or decide which data belongs to that person. It does not redact, apply exemptions or say the response is complete. Those decisions stay with an authorised privacy reviewer working from the verified request scope. Identity checks and the final review before disclosure are manual steps. Treat the results as preparation for that review.
Questions before you run it
Does this tool decide whether my DSAR response is complete?
No. It inventories the files you upload and reports hashes, duplicates and untyped entries. Deciding which personal data belongs to the requester, and whether the response is complete, stays with an authorised privacy reviewer.
What counts as a junk file in the inventory?
Filesystem leftovers and container artefacts that carry no disclosure value, such as thumbnail caches and resource-fork entries. They are flagged in findings.csv so you can decide whether to drop them before disclosure, and nothing is deleted for you.
How are duplicate files detected across different systems?
Every file is hashed and files with identical hashes are grouped as exact duplicates. Two exports of the same mailbox under different filenames are still matched, but a document that was re-saved or re-exported has a different hash and is treated as a separate file.
What formats and how many files can I upload?
ZIP, CSV and XLSX, up to 2,000 files in one job. A source above that ceiling is rejected before processing rather than inventoried in part.
What is in the download and does it change my original export?
You get file-inventory.csv, organized-source.zip, findings.csv and manifest.json. The ZIP is a copy; the export you uploaded is read and never altered.