Here’s a practical, step-by-step guide to handling a Subject Access Request (SAR) under UK GDPR / GDPR within statutory timescales, plus a downloadable checklist is at the end. We’ll start by explaining the legal background, before taking you through the key steps – and why they are important – to full GDPR compliance for this key data right.
The Legal Background
- You must respond “without undue delay” and at the latest within one month of receipt of a valid Subject Access Request.
- You may extend by up to two further months if the request is complex or you have multiple requests from the same individual, but you must tell them within the first month and explain why.
- The one-month period usually runs from the date you receive the request (not the next day).
- The clock can be paused (“stopped”) where you genuinely need ID, clarification or a fee (where allowed); time runs from when you receive what you asked for. (Information Commissioner’s Office)
- ICO guidance is currently flagged as under review following the Data (Use and Access) Act 2025, so always double-check the latest ICO pages for any changes to detail.
Step-by-step Subject Access Request Compliance Process
1. Recognise the SAR and route it correctly
- Treat any request for “all information you hold about me” or similar as a SAR, whatever the format (email, letter, portal, social media, etc).
- Ensure staff know how to spot a SAR and where to send it (DPO / privacy lead / central inbox).
- Remember, requests do not need to be in writing or quote the Data Protection Act or the GDPR.
2. Log the request and assign an owner
Set up or update a SAR log capturing the request and setting out at least:
- Requester’s name and contact details
- Date received and method of receipt
- Whether it’s made on behalf of someone else (and with the necessary evidence of authority if it is)
- Responsible owner/handler
- Statutory deadline and any potential extension date
This log is your audit trail if the ICO ever asks questions. it is also useful if you get duplicate requests, as you can either only release information that has been received or created since the last request or refuse the request as being excessive (see more on this below).
3. Check validity & identify the requester
- If you have doubts about identity, request ID that is proportionate to the risk.
- Check if you have received a similar request from the requestor recently. If you have you may be able to threat the request as unfounded or excessive (see below)
- It is worth at this stage checking if you do have any personal data about the individual – often people make requests to organisations that never ha,d or have no retained, personal data about them.
- Timescale: the one-month deadline does not start until you have the information you reasonably need to identify the requester (and any fee, where applicable).
4. Assess scope and whether clarification is needed
- If you process a large amount of information about the individual and the request is vague (“everything you hold on me”), you may ask them to clarify the information or processing activities they are interested in.
- Under ICO guidance, where clarification is genuinely necessary, you can pause the clock until they respond, but you should still provide any supplementary information you can within one month.
- Be careful not to demand narrowing of scope as a condition; they are still entitled to “all the information you hold”, you are only entitled to clarify.
5. Consider fees and “manifestly unfounded or excessive” requests
- Responses to Subject Access Request are normally free.
- You may charge a reasonable fee or refuse only if a request is manifestly unfounded or excessive (e.g. repetitive, intended to harass, or completely disproportionate).
- If refusing or charging, document your reasoning and inform the requester of:
- Why you are refusing/charging
- Their right to complain to the supervisory authority (typically the Information Commissioner) – although if people are concerned they should complain to the data controller in the first instance
6. Calculate response timelines, including approvals
For a valid SAR (including if ID, clarification, or the relevant fee have been received):
- The typical statutory response time is one calendar month from the date you received the valid request.
- If you foresee complexity or multiple simultaneous rights requests, consider whether you may need the +2-month extension and note that you must tell the individual within the first month.
- Remember you will need time to collate and review the relevant data, make redactions or apply exemptions, and seek necessary approvals before sending the information out – all within statutory timescales.
7. Acknowledge the request
Send an acknowledgement email/letter:
- Confirm you have received the Subject Access Request
- State the standard deadline and, if likely, that the request may require up to an additional two months (with reasons)
- Note any ID or clarification requested and confirm that the timescale runs from when you receive that
- Provide a contact point for questions
Sign Up Here:
Map out where the person’s data is likely to be: Send internal notices: Keep a record of: Go through the collected material and: In some instances, such as requests for data from current or former employees, you may find a large volume of data like emails. These can be time consuming to go through, especially as in many instances they will only contain the person’s name and/or email address. Fortunately the ICO’s guidance on this is: You do not have to provide the employee with a copy of each email. Since the only personal information that relates to them is their name and email address, it is sufficient to: However, if any content within any of the emails relates to the employee, you must provide them with a copy of those particular emails, redacted if necessary. You can read the ICO’s full guidance here. A compliant SAR response is not just the raw data. You also need to include the supplementary information required by GDPR Art. 15, such as: You can provide this in a cover letter or structured document that accompanies the disclosed data. You can also find a template for this supplementary information here. If the requestor asks for data in a particular format you should provide it in that format where possible, and it is of course appropriate to take into account any needs the requestor has made you aware of. Before sending: When sending: After sending: Complete the form below to get a template checklist direct to your inbox – and remember to check your junk folder. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.8. Identify data sources and place holds
9. Collect data from all relevant systems
10. Review relevance and apply exemptions
11. Redact third-party and confidential information
12. Prepare the Article 15 information
13. Choose the format and method of delivery
14. Send the response within the statutory timescale
15. Record-keeping and lessons learned
Download Your Subject Access Request Checklist here

- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: