Subject Access Requests, or SARs, are the most commonly used GDOR right that people have. They can place a material burden on organisations and therefore it is not uncommon for deadlines or information to be missed. However, even missing the deadline is itself a breach of GDPR, regardless of whether data is eventually provided.

The Background to Subject Access Requests
People have been able to make subject access requests since the data protection Act 1998. The GDPR incorporated an expanded this right, renaming it the Right of Access.
Under the GDPR when someone exercises this right they are entitled to:
- Confirmation their data are being processed
- Background information including the legal basis for that data processing
- A copy of the information they have requested
Organisations generally must provide this information within one calendar month of the request, free of charge. Exceptionally you may extend by up to two further months for complex or numerous requests, but must inform the requester within the first month.
Sometimes, such as verifying a requestor’s identity, you can pause the clock. This must be justified and proportionate—you cannot routinely delay requests by asking for unnecessary identification. Rarely, you can refuse to comply with a request but the bar for this is quite high e.g. the request is “manifestly unfounded or excessive”
Why Do People Makes SARs?
In our experience people rarely make requests out of idle curiosity. People tend to ask for information about themselves if they have a complaint, grievance or suspicion of wrongdoing.
Examples include:
- Dismissed employees seeking information to make a claim for unfair dismissal
- Customers who feel their data has been misused in some way
- Citizens checking what public bodies hold about them due to a lack of trust or an ongoing dispute
It is important to note that people do not need to give a reason for their request.
How Organisations Get SARs Wrong
There are a number of ways organisations get SARs wrong. Some of these are more technical, others more material.
For example organisations often fail to provide the supplementary information outlined above. While people might generally just want the information not the background, Article 15 of the GDPR requires supplementary information. A failure to provide it is a breach, even if the requester doesn’t explicitly complain.
Sometimes organisations fail to provide everything they hold about the requestor, perhaps because they have not done a thorough enough search or considered all of the identifiers a person may be known or classified by (date of birth, order number, employee number, initials etc.)
Most seriously organisations will deliberately fail to disclose information, even going so far as to delete data rather than share it. Deliberately concealing or destroying data to avoid disclosure can expose organisations to serious regulatory action and, in some circumstances, criminal liability under the Data Protection Act 2018.
The most common way organisations get this wrong is to take longer than allowed to respond.
Why Do Organisations Miss Deadlines?
There are three main reasons organisations miss statutory deadlines:
- They do not have the resources to manage requests. A lot of organisations, especially public bodies like NHS bodies, police forces or local authorities, get hundreds of requests a year
- They have too much information. Some organisations hold huge volumes of data about people. This is especially true about public sector bodies, but employers are often surprised about how much they hold about current or past workers.
- It takes a long time to review, redact and collate information for disclosure.
External Consequences: What Could Happen if We Do Not Comply?
Like all risks there are three main ways a failure to comply with people’s GDPR rights might impact you:
- Reputational: your organisation’s reputation can suffer if you do not comply with SARs, especially if you are subject to regulatory action.
- Financial: people can complain to the Information Commissioner or even take civil action if you do not comply with SARs. The Information Commissioner cannot offer compensation but he can issue financial penalties for breaching the GDPR. Civil action has its own costs whether it succeeds or fails.
- Operational: people, quite rightly, don’t just sit quietly if you do not respond in good time. Delays or gaps in responses cause complaints and ongoing communication that take time and resources to deal with. Enforcement action could lead to directions to change your systems and processes, which will also have an operational impact.
Internal Consequences: Why Does it Matter?
A failure to comply with SARs or respond in good time means you are denying people a legal right. Legally and ethically that is serious. However, the real world consequences as outlined above can be significant.
One issue that not responding properly to requests might be a symptom of is a lack of control over your personal data and the flows of personal data in your organisation. This also is potentially serious as you might find it difficult to show:
- You have a proper lawful basis for processing people’s personal data
- You might be in breach of privacy principles around data retention or security
- Core rights like the right to be informed may also not be being complied with
Therefore there are wider reputational, operational and financial risks you might be exposed to without knowing. Key things to explore if there are systematic or long standing failures to comply with SARs include:
- Whether your data mapping is adequate and complete
- Your data retention and deletion policies and practices
- system integration
- whether data protection and information governance has sufficient oversight

How Can You Get SARs Right?
The main ways you can employ to ensure you can comply with subject access requests include:
- Ensure that you recognise when people are exercising this right. They do not need to quote the GDPR or even put their request in writing. You can avoid delays by acting speedily as soon as a request is received
- Minimise the data you hold. The GDPR requires organisations to hold the minimum necessary data about individuals. You will be more operationally efficient and save costs if you delete data you don’t need. It will also make it easier to find and share data about people if a request is made
- Have appropriate compliance systems. You can use free resources like our SAR request checklist and response template to help track process and ensure you respond fully and in a timely manner.
- If things go wrong ensure you understand why, and implement reasonable steps to avoid a recurrent.
Key elements to put in place to fulfil your statutory duties when people make subject access requests include:
- SAR workflow tracking
- central request logging
- search protocols
- redaction standards
- templates like those you can find on our GDPR resource page.
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: