What to do with a Subject Access Request

What to do with a Subject Access Request

A Helpful Guide

💭 Ask yourself...

"If someone asked to see all the personal information I hold about them today, would I know where to find it?"

 

Short answer

A Subject Access Request gives individuals the right to ask whether you hold personal information about them and, if you do, to receive a copy of that information together with certain additional details.

Most requests are straightforward, but it's important to recognise them, respond within the required timescales and provide the information you're required to disclose.

 

Does it have to be in writing?

No.

A Subject Access Request can be made in almost any way.

For example, someone might:

  • send you an email; 
  • complete a contact form; 
  • write a letter; 
  • speak to you over the phone; 
  • ask in person; 
  • contact you through social media. 

The important thing isn't how they ask.

It's whether they're asking for their personal information.

If you're unsure, it's always worth asking a few questions to confirm what they're need rather than ignoring the request.

 

How long do I have to respond?

In most cases, you must respond within one calendar month of receiving the request or, where appropriate, receiving any information needed to confirm the individual's identity.

For particularly complex requests, or where multiple requests have been made, you may be able to extend the deadline by up to a further two months.

If you need more time, you should let the individual know within the first month and explain why the extension is necessary.

The key is not to wait until the deadline approaches before reviewing the request.

 

Do I have to give them everything?

Not always.

Your starting point should be to provide the personal information you're required to disclose.

However, there are situations where you may need to:

Clarify the scope

If a request is particularly broad, you can ask the individual to help narrow down what they're looking for.

Remember, asking for clarification doesn't automatically stop the clock unless you genuinely need that information to identify the personal data requested.

Protect other people's information

If documents contain information about other individuals, you may need to redact that information before disclosure.

Consider exemptions

Some information may be exempt from disclosure, depending on the circumstances.

Examples can include:

  • legally privileged information; 
  • confidential references in certain circumstances; 
  • information relating to crime prevention or detection; 
  • management forecasting or negotiations in limited situations. 

Exemptions should be considered carefully and applied only where they genuinely apply.

The default position should always be disclosure unless there is a lawful reason not to provide the information.

 

Can I charge a fee or refuse the request?

Most Subject Access Requests must be dealt with free of charge.

However, you may be able to charge a reasonable fee or refuse to act where a request is manifestly unfounded or manifestly excessive.

These are high thresholds.

A request shouldn't be refused simply because:

  • it takes time; 
  • it involves a large amount of information; 
  • the individual has made complaints about your organisation. 

If you decide to refuse a request or charge a fee, you should be able to clearly explain and document your reasoning.

 

Unfortunately, you can’t choose which pieces of data you have to share.

One of the biggest misconceptions is that organisations can decide which information they think the individual should see.

That's not how Subject Access Requests work and it can be difficult sharing information that doesn’t show you in a good light.

If the information falls within the scope of the request and no exemption applies, it should generally be disclosed.

A Subject Access Request isn't about deciding what is convenient to share.

It's about giving individuals access to their own personal information while protecting the rights of others where appropriate.

 

Common Misconceptions

"If they don't use the words 'Subject Access Request' or mention GDPR, I don't have to respond."

Not correct.

A Subject Access Request doesn't need to mention GDPR or use any legal terminology. If someone asks for the personal information you hold about them, you should consider whether they are making a Subject Access Request, regardless of how they phrase it.

 

"I should automatically send everything I hold, even if they haven't asked for it."

Not necessarily.

You should provide the personal information that falls within the scope of the request, together with the information required under UK GDPR. If the request is particularly broad, you may be able to seek clarification to help identify the information being requested.

A Subject Access Request is about providing the individual's personal information—it isn't an opportunity to send every document you hold without considering relevance or the rights of others.

 

"I can leave out emails, Teams messages or internal conversations because the individual wasn't meant to see them."

Not necessarily.

If emails, Teams messages, handwritten notes or other internal communications contain the individual's personal information, they may fall within the scope of a Subject Access Request.

The fact that a document is internal doesn't automatically exclude it from disclosure. You should consider whether any exemptions apply and whether information relating to other individuals should be redacted before responding.

 

"If it's embarrassing or could lead to a complaint, I don't have to disclose it."

No.

A Subject Access Request isn't about deciding what is comfortable to disclose. If the information falls within the scope of the request and no exemption applies, the starting point should generally be that it is disclosed.

 

"I can refuse the request because it's going to take too much time."

Not usually.

Subject Access Requests often require time and effort. A request isn't manifestly excessive simply because it involves a large amount of work. If you're considering refusing a request or charging a fee, you should be able to justify your decision based on the circumstances rather than the inconvenience involved.

 

 

Practical steps

  1. Recognise the request. 
  2. Record the date it was received. 
  3. Verify identity where appropriate. 
  4. Locate the relevant information. 
  5. Consider whether clarification is needed. 
  6. Review the information for third-party data and any applicable exemptions. 
  7. Respond within the required timescale. 
  8. Keep a record of how you handled the request. 

 

🤝 Need a little support?

Most Subject Access Requests can be managed successfully with a structured process and good record keeping.

If you're dealing with a particularly large request, considering whether an exemption applies or simply want someone to sense-check your response before you send it, we're here to help.

Sometimes having a second pair of eyes can give you the confidence that you've reached the right decision.

Do I Need to Register with the ICO? 

I Can Collect Personal Data... Now What? 

Reasons for Collecting Personal Data 

Someone Has Asked Me to Delete Their Information. Do I Have To?

Information icon

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.