Responding to Subject Access Requests: A Step By Step Guide

Responding to a subject access request can feel difficult and time consuming for businesses. Most will be happy to comply with people’s rights but fear the burden it places on them or the risks of getting them wrong.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

What is a Subject Access Request?

A Subject Access Request (SAR) is a request made by an individual to an organisation to access their personal data. It’s a fundamental right under data protection law, allowing individuals to know what information organisations hold about them.

Under the GDPR this right is known as the “right of access” but the right to see what data an organisation holds about an individual has been in place since at least 1995.

 

What Does the GDPR Say?

Legal Basis:

  • UK GDPR Article 15 (Right of Access): This article grants individuals the right to obtain:

    • Confirmation as to whether or not personal data concerning them is being processed.

    • Access to that personal data.

    • Information about the processing, including the purposes, categories of data, recipients, and retention periods.

  • Data Protection Act 2018 (DPA 2018): The DPA 2018 supplements the UK GDPR, providing further details and clarifications on the right of access. It also covers exemptions and specific provisions related to certain types of processing (e.g., law enforcement, national security).

GDPR

 

Key Aspects of a Subject Access Request

  • Scope: Individuals can request access to all their personal data held by an organisation, whether in electronic or physical form.

  • Information Provided: Organizations must provide the requested data in a clear and understandable format.

  • Supplementary Data: To be fully compliant they must also provide information about the purposes of processing, the categories of data, and the recipients of the data.

  • Time Limit: Organizations generally have one month to respond to a SAR, although this can be extended in complex cases.

  • Exemptions: There are certain exemptions to the right of access, such as when providing the information would prejudice national security or law enforcement.

  • Verification: Organizations may need to verify the identity of the person making the request.

In summary, a subject access request is a core GDPR right for individuals to access their personal data and ensure that organisations are processing it lawfully and transparently.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Responding to a Subject Access Request

Although requests do not need to be in writing the you can ask the requestor to prove their identity. If the requestor has not provided one they will need to give you a postal or email address to send the information you have and can disclose.

There is no harm in asking the requestor if there is anything in particular he wants or if he wants everything you hold.

 To comply with the request you will need to:

 

Search

First, do a search of your paper and electronic systems for anything that contains information that identifies the requestor. This will include contact information like telephone number, email and address as well as name. It will also include any identifiers like passport number or NI number if you use them.

 

Collate

Make a list of this in a table or spreadsheet. You will need to come back to the table later. The table should have the columns set out below:

Purpose data was used for

Category of data

Source of data

Who the data have been shared with

Retention Period of the data

Subject to automated decision making

Shared

If No why not?

Financial

Requestor

Bank

10 years

Yes

Yes

N/A

Personal

Third party

Referee

End of lease

No

No

Contains personal data of other people

Etc.

Exempt because…

 

Redact

Strip out anything that should not be disclosed

  • Anything the requestor has provided to you as he will have a copy of that already

  • Anything you have previously sent the requestor, for the same reason

Also remove anything that falls within the following categories:

  • Identify anything in what is left that contains the personal data of other people like colleagues, family members or referees

    Remember to look for anything that identifies people indirectly via context e.g. “I met with Mr X on the 17th January” as he will be able to identify the person from that information

  • Consider redacting that information, and if you cannot, remove those items and add them to the list under item 3

Review what is left and see if there is an exemption to disclosure. Exemptions apply to a range of activity, but in the private sector this is limited to activities that would be prejudiced if the information were released under the headings of:

  • Preventing crime such as fraud or tax evasion

  • References given in confidence relating to employment or the provision of a service e.g. entering into a lease

Anything exempt should be added to the list under item 3

 

Get Ready to Respond

Complete the table discussed above, listing all the information you hold, including anything you will not disclose and why

Send the information you are going to disclose (anything not under “3” above) along with the completed table. You response should also include:

Close the Request

That process will complete and close the request. You should keep the request and your response on file so, if the requestor makes a further request, you only need to provide anything that has been created or received after this request was responded to.

 

Conclusion

Responding to a Subject Access Request need not be a big burden if you engage with requestors, have a good handle on your data processing, and have the right processes in place to handle requests.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial