Purview DSAR guide

Running a DSAR case
with Microsoft Purview

The five steps of a case, in order: exporting from Microsoft Purview, setting up the case and subject details, processing, review, and producing the disclosure. Each step stands alone, so you can forward the part that applies to whoever operates it.

Before you start

  • Your account is activated. Sign-in details come from whoever set your account up. Depending on how it was created you will either have an invitation email that lets you set your own password, or a password sent to you directly which you can change once signed in. If neither has arrived, ask your account contact before your export lands.
  • The Data Processing Agreement is in place before the first upload. It means your organisation is covered for putting live SAR material into the system before a single file moves. For organisation accounts we execute it with you during onboarding and record it against your organisation.
  • You know who operates each step. The Purview export is often done by IT or an eDiscovery admin rather than the case owner. This page is written to be forwarded; each numbered section stands alone.
  • You have a machine that can stay awake. Processing runs in your browser, which is what keeps your files on your own hardware, and it needs the tab open for the length of the run.

What the machine needs

  • A desktop or laptop, not a phone or tablet. A current Chromium browser is the recommended choice, meaning Microsoft Edge or Google Chrome; Firefox and Safari also work. Whatever you use, keep it up to date and close other memory-heavy tabs before a large case, because the working set for the case is held in the tab.
  • 16 GB of memory for cases above roughly 10,000 documents. The 8 GB standard-issue laptop is fine for a few thousand documents and will struggle across an overnight run at full volume. If your fleet is mixed, run large cases on the better machine.
  • Sleep disabled and power connected for the duration of the run. A laptop that suspends when the lid closes will pause the case.
  • No forced restart in the window. This is the one that catches people. If your device management enforces overnight patching or a reboot schedule, either exclude the machine for that night or run the case across working hours instead. A restart mid-run is recoverable, but it costs the time it takes to get back to where you were.
  • Not a remote session that times out. If you work through VDI or a remote desktop that disconnects when idle, run the case on a local machine.
  • Free disk space for the export, plus the same again if you extract the packages rather than loading the zips whole.

Plan the timeline

A subject access request runs against a statutory clock: one month from receipt under UK GDPR, extendable by two further months where a request is complex or where several have been made together. Your DPO will confirm which applies. Work backwards from that date rather than forwards from today, because the export is usually the longest and least predictable part.

Processing time by case size

Documents in the caseProcessingIn practice
2,500about 1.5 hoursRuns comfortably inside a working morning
5,000about 2.5 hoursStart late morning, review the same afternoon
10,000about 5 hoursA working day, started first thing
20,000about 10 hoursStart at the end of the day and review the next morning
25,000about 12 hoursOvernight

Measured at 2,500 documents and scaled from there. Processing runs unattended once started, so what matters is less the number of hours than whether the machine is free for that window.

The other three parts of the schedule

  • The Purview export is the long pole. Mailbox content exports at roughly 2 GB per hour, per mailbox, and a single large mailbox cannot be parallelised. Ask whoever runs the export for the collection size in gigabytes before you commit to a date.
  • Downloading is bounded by your network. A multi-package export over a corporate connection is measured in hours rather than minutes, and it has a clock of its own: search exports are deleted 14 days after they are created.
  • Review is the part you cannot schedule from a document count. It scales with the number of distinct people and identifiers in the collection, because a decision about a person applies everywhere that person appears. A collection about a handful of people reviews quickly whatever its size; one touching hundreds takes proportionally longer. Process a single custodian first and you will have a real rate to plan from before the full volume lands.

1Export your collection from Microsoft Purview

A few minutes on export settings prevents the three problems that cost teams a day at the start of a case: an export format the browser cannot open, cloud attachments arriving as dead links, and image-only documents left out of the collection entirely. These instructions cover the current Purview eDiscovery experience; the classic experience was retired in August 2025.

Decide the export format before anything else, and choose PST. Under Export format, Purview offers Create PSTs for messages or Create .msg files for messages. Choose PSTs and set the package size to 1 GB or 2 GB rather than leaving the 5 GB default, because processing happens in your browser and browsers cap a single file at 2 GB. PST is the only mailbox format with complete attachment coverage: every message is expanded locally and each attachment is read out and scanned as a document in its own right. Individual .msg files are processed and their bodies, headers and recipients are detected, but content inside a .msg attachment is not scanned, so a spreadsheet attached to an email would go unexamined. On a subject access request that is not a risk worth taking to save one setting.

Export settings at a glance

Hand this table to whoever operates Purview. It is the whole configuration, and it exists as a standalone page you can forward: Purview export settings.

SettingChooseWhy
Export formatPSTs for messagesThe only mailbox format where attachment content is read out and scanned in its own right
Give each item a friendly nameOnKeeps SharePoint and OneDrive files under their real names rather than a GUID
Maximum .zip package size2 GBMust equal or exceed the PST size; smaller packages also download more reliably
Maximum PST package size1 or 2 GBDefault is 5 GB; the browser cannot open a file above 2 GB
Select items to includeIndexed and partially indexedPartially indexed is where scanned and image-only documents sit; the default leaves them out
Access links (cloud attachments)On, latest versionOff, files shared as links never reach your disclosure. All versions multiplies volume
Separate folders or PSTs per locationOnKeeps custodians separable in review
Include folder and path of sourceOnMailbox structure survives into review and makes navigation far easier
Condense paths to 259 charactersOnDeep SharePoint paths otherwise break extraction on Windows
Export typeItems with items reportReport-only truncates every string field at 255 characters

Four points that deserve a sentence more

  • Partially indexed items are excluded by default. That set is where scanned documents, image-only PDFs, encrypted files, unsupported types and items that hit an indexing error all sit. For a subject access request they are precisely the documents you cannot afford to have quietly missing. They arrive without a text layer, and OCR runs on them locally in your browser. Purview also never indexes images attached to an email, though they do export with the message. Note that the setting on the original search governs statistics and preview only; the decision that counts is the one made at export.
  • Cloud attachments depend on the collection, not just the export. If the original search was not scoped to include them, turning the export option on may not retrieve them and the collection itself may need re-running. Worth checking before the export rather than after.
  • Package size is not the same as export size. Purview splits results larger than 10 GB into multiple PSTs even when you ask for a single file, so a large mailbox arrives as several packages. Load them all to the same case. Setting both the PST and zip sizes to 2 GB keeps every part of the package inside the browser's limit.
  • If a mailbox has already been exported as .msg, it is not wasted. Those files process and their bodies, headers and recipients are detected. What is missing is the content of files attached inside each .msg container, so treat those attachments as unreviewed: either re-export that mailbox as PST, or collect the attachments separately and load them alongside. Flag it at the start of the case and we will help you work out which mailboxes are affected.

Timing and scale

  • Mailbox content exports at roughly 2 GB per hour, per mailbox. One large mailbox is usually the long pole in the schedule; adding custodians parallelises better than adding years.
  • Any export process cancels automatically after seven days. If a collection is anywhere near that, split it by date range or by custodian.
  • A single export is capped at 500,000 items, and individual files larger than 5 GB are not exported at all.
  • Run Generate statistics first on a wide collection. Purview then skips locations with no search hits during the export, which is a material speed-up across a large tenant.

Downloading the package

  • Download promptly. Search exports expire 14 days after creation and are then permanently deleted. Exports taken from a review set allow 30 days.
  • Extract with 7-Zip (free, 7-zip.org) rather than the built-in Windows extractor, which resets file timestamps and fails on long paths.
  • If the download stalls or crawls, suspect the network before the export. Allow pop-ups from Purview, allow the site to download multiple files automatically, save to a local drive rather than a network share, and test on a different connection. Proxy and endpoint scanning are the usual cause.

What will not be processed

SafeRedact processes PDF, Word, Excel, CSV, JSON, text, HTML, email (PST, MSG, EML) and the contents of zip archives including nested ones. Two gaps are worth knowing before you reconcile rather than after.

  • File types outside that list are not picked up. Standalone image files are the common case in a SharePoint or OneDrive collection: a photograph or screenshot exported as .jpg or .png is not currently examined, and it is not listed as a failure either. Scanned pages inside a PDF are a different matter and are OCR'd normally. To find out whether this affects your case, open the items report from the Purview export and filter it by file extension: that gives you the exact list of image files in the collection, which you can review separately and record as handled.
  • Handwriting is never machine-readable. Handwritten annotations and signatures are not detected. Where a collection is substantially handwritten, plan a manual pass over those documents.

Practical notes

  • Permissions: the person running the export needs an E3 or E5 licence and membership of an eDiscovery role group such as eDiscovery Manager. Access to Purview is not by itself enough to export. If the option is greyed out, this is usually why.
  • Non-mailbox content: SharePoint, OneDrive and Teams files export as native documents inside zip packages rather than as messages. Load those zips to the same case; they are unpacked and processed alongside the mailbox content.
  • Teams conversations arrive as HTML transcripts where Organize conversation into HTML transcript is selected. Include Teams and Viva Engage conversations collects a twelve-hour window either side of each responsive message, which increases volume noticeably.
  • Keep the process report. The report zip contains Summary, Settings, Items and Locations CSVs. Items.csv carries a per-item status with a reason for anything that failed, and Summary lists retrieval exceptions, meaning items Purview could not export at all. Those are separate from SafeRedact's own failure manifest, and a complete reconciliation at the end of the case uses both.

2Set up your case

Create a new DSAR case and give it the request details. The few minutes spent here drive the quality of everything the system suggests later.

  • The data subject. Enter the requester's name and email address in the subject fields.
  • Aliases and alternative identifiers. This free-text box is the most important field in the product. Add every variant the requester goes by: maiden names, nicknames, initials, personal email addresses, employee IDs, and the names of associated individuals who should stay visible in the disclosure. The preserve model keeps these identifiers unredacted so the disclosure remains legible to the person who asked for it.
Rule of thumb: anything the requester would recognise as "me" belongs in the aliases box. Highly specific identifiers (email addresses, IDs, full names) are preserved everywhere; ambiguous ones (a bare first name) are preserved only where the context clearly anchors them to the subject, and flagged for your judgement elsewhere.

3Upload and process

Upload the export directly to the case: the PST packages, the export zips whole, loose files, or any mix. PSTs and zips are unpacked in your browser, nested zips included, and there is no need to convert anything to PDF first.

Start with one custodian

Before loading the full collection, upload a single mailbox's PST and let it process. This confirms your export settings came through cleanly and shows you the review workflow on a manageable set, while the rest of the export downloads. Then load everything else into the same case. Keep it in one case: a case is priced once, so starting small and adding the rest does not create a second charge, and it gives you a measured review rate to plan the remainder from.

What to expect on timing

  • Processing takes about an hour and a half per 2,500 documents. The full table by case size is in Plan the timeline.
  • Processing runs from your browser tab, which is part of how your files stay on your machine. The tab must stay open while processing runs. Check the machine requirements in Before you start before a large case, particularly the forced-restart one.
  • Progress is shown per file, and each file's results are saved on your device the moment it completes. If a run is interrupted, reopen the case under the same name and re-attach the same source files: everything already processed is restored instantly and only the remainder runs.

4Review

Review effort scales with the number of unique people and identifiers in the collection, not the number of documents, because a decision made once cascades to every occurrence of the same entity. A large collection concerning few people reviews far faster than its document count suggests, and your first custodian gives you the rate for the rest.

  • Work the flags first. The queue surfaces judgement calls: low-confidence OCR text, ambiguous names, and identifiers that might belong to the subject. Everything unambiguous has already been handled.
  • Decide once, apply everywhere. Approving or rejecting a suggestion can be applied to all matching occurrences across the case in one action.
  • Scanned documents: text recovered by OCR is marked where confidence is low so you know to look. Handwriting is never reliably machine-readable; treat handwritten pages as a manual-review category.

5Price, payment, and download

You pay once, for the case. Processing and review happen first, so nothing is due until you have seen what the case produced. When processing completes the case shows a single set price, payable at download. Accounts on agreed terms are invoiced instead, in which case the price is the one in your agreement and no payment step appears at download. Either way there is no licence, no subscription and nothing recurring.

Your export pack contains:

  • The redacted documents, in their original formats and folder structure.
  • A failure manifest, a CSV naming any file that could not be processed and why. A file that failed to process is a gap in your disclosure, so it is listed conspicuously for manual handling rather than dropped silently. Unprocessed files are not charged for.
  • A full audit trail of detections and review decisions, suitable for demonstrating your process if the disclosure is ever challenged.
Reconcile before you close the case: compare Purview's items report against SafeRedact's processed count plus the failure manifest. When the numbers meet, you can state exactly what was collected, what was processed, and what was handled manually, which is the question a regulator or requester will ask.

When files can't be processed

Some files in any real collection resist processing: password-protected PSTs and PDFs, corrupt files, and formats with no extractable content. These are enumerated by name in the failure manifest with the reason, excluded from the price, and left for manual handling. If a PST itself will not open, the most common causes are password protection or an export interrupted mid-download; re-exporting that mailbox usually resolves it.

Where your data goes

  • File handling stays in your browser. PST unpacking, text extraction, and OCR run locally on your machine. Your original files are not uploaded to SafeRedact's servers as part of processing.
  • Detection uses a commercial AI API. Extracted text is sent for analysis under commercial API terms: it is never used to train AI models, and the provider deletes it from its systems within 30 days.
  • Your outputs are yours. Redacted documents, the manifest, and the audit trail belong to your organisation.
  • The DPA states all of this precisely. It is executed with you during onboarding and is in place before the first upload.

Support

Questions at any point: support@saferedact.app, answered within 24 hours, Monday to Friday.

Support is US-based and not staffed at weekends. Working in UK or European hours, the reply to a morning message usually reaches you the same day and anything sent later in your afternoon lands the following morning. A question raised after Friday lunchtime is answered on Monday.

On a case with a statutory deadline, plan around that rather than into it. Send anything that could block you before you begin rather than mid-run, and start a long processing run early in the week: a Friday-evening run that hits a problem leaves you waiting until Monday with the clock still going.

For your first case we are happy to do a 30-minute screen share to set up the subject details and walk the review workflow. It is the fastest way to get the aliases box right, and that is the field that determines how good the suggestions are.

Questions that come up mid-case are collected in the FAQ: formats, timings, resuming an interrupted run, and what the audit trail contains.