A Subject Access Request (SAR) allows someone whose personal data you process - whether they’re an employee, customer, supplier, or anyone else - to ask whether you’re using their personal data and receive a copy of it. They’re also entitled to information explaining how and why you process it.
A SAR can arrive anywhere in your organisation. It can be made verbally, in writing, or electronically, and the person doesn’t need to mention data protection law or explain why they want the information. It may be as simple as someone saying, ‘I want all the information you have about me since I started working here.’
You’ll usually need to provide this information free of charge. However, you can charge a reasonable fee for your administrative costs if the request is manifestly unfounded or excessive, or if the person asks for further copies of information you’ve already provided in response to their request. Handling SARs can still take considerable time and effort.
Getting the right process in place will help you meet those strict UK GDPR deadlines and avoid individuals escalating the matter by complaining to the Information Commissioner’s Office (ICO). If you're looking for support, our data protection solicitors are here to help you handle SARs correctly and efficiently.
What should you do first?
As a first step, you should act fast to:
- Recognise, log and action the SAR: Requests can be made orally, in writing, or electronically e.g. via social media - it could be as simple as someone saying, "I want all the information you have on me since I started." Train all staff to identify these priority requests and establish clear processes for immediate escalation to the appropriate teams or individuals. As soon as you receive a SAR, make sure you record the date you receive it as it will help you track and meet the response deadlines.
- Check identity: Make sure you’re satisfied about the requester’s identity, but don’t automatically ask everyone for formal identification. If you have reasonable doubts, ask only for the information you need to confirm their identity and use existing authentication methods where possible. If someone is acting for another person, ask for evidence that they’re authorised to do so.
- Note the timelines: You must respond without undue delay and at the latest within one month of receipt of the request. You’re able to get an extension of this period of up to two months, if the request is complex or if you’ve received multiple requests from the individual. Within one month of receiving the request, notify the individual about the extension and explain why more time is needed.
Triage the request
Before responding to a SAR, consider:
- Who made the request? Identify whether it's from an employee, client, or another party.
- What's the backstory? Review relevant files for context.
- Is the request clear enough? If you hold a large amount of information about the person, or the request is unclear, you can ask for further information where this is reasonably required to identify the information or processing activities covered by the request. You can’t force the person to narrow their request. The response period stops on the day you ask for clarification and starts again on the day after you receive it.
- What are the technical implications? Assess whether your IT team can conduct the necessary searches within the timeframe. Plan and document a reasonable and proportionate search of the locations that are reasonably likely to contain the requested personal data. Depending on the request, this may include HR systems, email accounts, messaging platforms, shared drives, archives, and personal devices or accounts used for business purposes.
Response to the request
When responding, ensure you:
- Provide the correct information: Securely provide the person with a copy of their personal data in a concise, transparent, intelligible, and easily accessible form. Where the request was made electronically, you should usually provide the response in a commonly used electronic format unless the person asks for something different.
You should also provide relevant supplementary information about:- whether you process their personal data
- the purposes for which you process it
- the categories of personal data involved
- the recipients, or categories of recipients, to whom it has been or will be disclosed
- how long you expect to keep it, or the criteria used to decide the retention period
- the source of the data, where it wasn’t collected directly from the person
- their rights to request rectification, erasure, or restriction, and to object to processing
- their right to make a complaint directly to your organisation
- their right to make a complaint to the Information Commissioner’s Office
- the safeguards used where personal data has been transferred outside the UK
- whether you use automated decision-making, including profiling, together with meaningful information about the logic involved and its significance and envisaged consequences
- Review exemptions carefully: Some personal data may be exempt from disclosure. For example, an exemption may cover information protected by legal professional privilege.
- Exemptions: Review the information carefully and apply exemptions only to the extent that they genuinely cover particular personal data. Legal professional privilege may protect some information, but it shouldn’t be treated as a blanket exemption. Where information also identifies another person, consider whether they consent to disclosure or whether it is reasonable to disclose without consent. Where possible, redact the other person’s information rather than withholding the requester’s information altogether.
Build a practical SAR strategy
To manage SARs efficiently, put these measures in place:
- Assign responsibility: Nominate a person or team to oversee the SAR process.
- Implement efficient processes: Create digital systems for quick data searches and streamlined handling.
- Draft clear SAR response procedures: Create a robust procedure for responding to SARs that all relevant teams can easily follow.
- Train your staff: Provide ongoing training about recognising SARs, quickly escalating them to the right teams, and updates to data protection laws and ICO guidance.
- Evaluate exemptions: Understand when and why you might refuse a request (e.g. if it is excessive or manifestly unfounded). If you refuse one, record your justification carefully and inform the requester without undue delay and at the latest within one month of receipt. Explain their right to complain to the ICO and enforce their rights.
- Provide a data-protection complaints process: Give people an accessible way to complain about how you have used their personal data or handled their SAR. You must acknowledge a data-protection complaint within 30 days, take appropriate steps to investigate it without undue delay, keep the person informed, and communicate the outcome without undue delay.
- Maintain records: Keep detailed documentation to demonstrate compliance.
The ICO can take enforcement action against organisations that don't comply with data protection laws. If you need support handling a SAR, our expert data protection law team can provide practical advice on both SARs and wider UK GDPR matters. For more detailed guidance, including what counts as personal data and specific response timelines, see our comprehensive guide to subject access requests.