Subject Access Request Checklist

Here’s a practical, step-by-step guide to handling a Subject Access Request (SAR) under UK GDPR / GDPR within statutory timescales, plus a downloadable checklist is at the end. We’ll start by explaining the legal background, before taking you through the key steps – and why they are important – to full GDPR compliance for this key data right.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

The Legal Background

  • You must respond “without undue delay” and at the latest within one month of receipt of a valid Subject Access Request.
  • You may extend by up to two further months if the request is complex or you have multiple requests from the same individual, but you must tell them within the first month and explain why.
  • The one-month period usually runs from the date you receive the request (not the next day).
  • The clock can be paused (“stopped”) where you genuinely need ID, clarification or a fee (where allowed); time runs from when you receive what you asked for. (Information Commissioner’s Office)
  • ICO guidance is currently flagged as under review following the Data (Use and Access) Act 2025, so always double-check the latest ICO pages for any changes to detail.

Step-by-step Subject Access Request Compliance Process

1. Recognise the SAR and route it correctly

  • Treat any request for “all information you hold about me” or similar as a SAR, whatever the format (email, letter, portal, social media, etc).
  • Ensure staff know how to spot a SAR and where to send it (DPO / privacy lead / central inbox).
  • Remember, requests do not need to be in writing or quote the Data Protection Act or the GDPR.

2. Log the request and assign an owner

Set up or update a SAR log capturing the request and setting out at least:

  • Requester’s name and contact details
  • Date received and method of receipt
  • Whether it’s made on behalf of someone else (and with the necessary evidence of authority if it is)
  • Responsible owner/handler
  • Statutory deadline and any potential extension date

This log is your audit trail if the ICO ever asks questions. it is also useful if you get duplicate requests, as you can either only release information that has been received or created since the last request or refuse the request as being excessive (see more on this below).

3. Check validity & identify the requester

  • If you have doubts about identity, request ID that is proportionate to the risk.
  • Check if you have received a similar request from the requestor recently. If you have you may be able to threat the request as unfounded or excessive (see below)
  • It is worth at this stage checking if you do have any personal data about the individual – often people make requests to organisations that never ha,d or have no retained, personal data about them.
  • Timescale: the one-month deadline does not start until you have the information you reasonably need to identify the requester (and any fee, where applicable).

4. Assess scope and whether clarification is needed

  • If you process a large amount of information about the individual and the request is vague (“everything you hold on me”), you may ask them to clarify the information or processing activities they are interested in.
  • Under ICO guidance, where clarification is genuinely necessary, you can pause the clock until they respond, but you should still provide any supplementary information you can within one month.
  • Be careful not to demand narrowing of scope as a condition; they are still entitled to “all the information you hold”, you are only entitled to clarify.

5. Consider fees and “manifestly unfounded or excessive” requests

  • Responses to Subject Access Request are normally free.
  • You may charge a reasonable fee or refuse only if a request is manifestly unfounded or excessive (e.g. repetitive, intended to harass, or completely disproportionate).
  • If refusing or charging, document your reasoning and inform the requester of:

6. Calculate response timelines, including approvals

For a valid SAR (including if ID, clarification, or the relevant fee have been received):

  • The typical statutory response time is one calendar month from the date you received the valid request.
  • If you foresee complexity or multiple simultaneous rights requests, consider whether you may need the +2-month extension and note that you must tell the individual within the first month.
  • Remember you will need time to collate and review the relevant data, make redactions or apply exemptions, and seek necessary approvals before sending the information out – all within statutory timescales.

7. Acknowledge the request

Send an acknowledgement email/letter:

  • Confirm you have received the Subject Access Request
  • State the standard deadline and, if likely, that the request may require up to an additional two months (with reasons)
  • Note any ID or clarification requested and confirm that the timescale runs from when you receive that
  • Provide a contact point for questions

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

8. Identify data sources and place holds

Map out where the person’s data is likely to be:

  • Core systems (HR, marketing systems like a CRM, email, ticketing, finance, product or sales databases, backups, archives, etc.)
  • Shared drives, collaboration tools, messaging systems
  • Processors / suppliers who hold data and process data on your behalf

Send internal notices:

  • Instruct teams to search, preserve and not delete potentially relevant data.
  • Inform processors to search and return personal data relating to the requester.

9. Collect data from all relevant systems

  • Run searches using names, IDs, email addresses, usernames, reference numbers etc.
  • Export data in a reviewable format (e.g. PDFs, spreadsheets, msg/eml, logs).
  • Ask processors to return any data they hold in reasonable time so you can still meet the deadline.

Keep a record of:

  • Where you searched
  • Date of each search
  • Any systems that couldn’t be searched and why (e.g. corrupted archive)

10. Review relevance and apply exemptions

Go through the collected material and:

  • Remove non-personal data or data clearly outside the scope of the request.
  • Apply legally permitted exemptions (examples, depending on jurisdiction and sector):
    • Data subject to legal professional privilege
    • Confidential references you have given for employment
    • Certain management forecasts or negotiations if disclosure would prejudice the business
    • Some regulatory, crime or taxation-related exemptions
  • Where you rely on exemptions, keep an internal note of what you withheld and why. You should also explain any exemptions to the requestor in most instances

In some instances, such as requests for data from current or former employees, you may find a large volume of data like emails. These can be time consuming to go through, especially as in many instances they will only contain the person’s name and/or email address.

Fortunately the ICO’s guidance on this is:

You do not have to provide the employee with a copy of each email. Since the only personal information that relates to them is their name and email address, it is sufficient to:

  • advise them that you identified their name and email address on 2,000 emails; and
  • disclose to them the name (e.g. John Smith) and email address (eg JohnSmith@org.co.uk) contained in those emails.

However, if any content within any of the emails relates to the employee, you must provide them with a copy of those particular emails, redacted if necessary.

You can read the ICO’s full guidance here.

11. Redact third-party and confidential information

  • Redact or anonymise third-party personal data unless:
    • You have their consent, or
    • It is reasonable to disclose without their consent.
  • Redact confidential business information where disclosure would adversely affect rights and freedoms of others, but don’t over-redact.
  • Ensure redaction is forensically sound (not just black boxes over text in Word that can be removed).

12. Prepare the Article 15 information

A compliant SAR response is not just the raw data. You also need to include the supplementary information required by GDPR Art. 15, such as:

  • Confirmation that you process their personal data
  • The purposes of processing
  • The categories of personal data concerned
  • The recipients or categories of recipients (including international transfers and appropriate safeguards)
  • Retention periods or criteria used to determine them
  • Existence of rights to rectification, erasure, restriction, objection, portability
  • The right to complain to the ICO or other supervisory authority
  • Where the data didn’t come from the data subject, the source (and whether it came from publicly accessible sources)
  • Details of automated decision-making, including profiling, and the logic/significance of such processing

You can provide this in a cover letter or structured document that accompanies the disclosed data. You can also find a template for this supplementary information here.

13. Choose the format and method of delivery

  • If the SAR was made electronically, you should usually respond in a commonly used electronic form (e.g. PDF, CSV, secure portal), unless they request otherwise.
  • Ensure the method is secure:
    • Encrypted email with password sent separately
    • For larger files consider a secure portal with login
    • Registered/recorded post for physical media
  • Consider accessibility needs (large print, alternative formats).

If the requestor asks for data in a particular format you should provide it in that format where possible, and it is of course appropriate to take into account any needs the requestor has made you aware of.

14. Send the response within the statutory timescale

Before sending:

  • Double-check that:
    • All systems were searched
    • Redactions are correct
    • The Article 15 information is included
    • You are within the one-month deadline (or clearly within the extended three-month limit, if invoked)

When sending:

  • Explain clearly:
    • What you are providing
    • Any information withheld and the legal basis (at least at category level)
    • The data subject’s rights (including to complain to the ICO)

15. Record-keeping and lessons learned

After sending:

  • Update your Subject Access Request log with:
    • Date response sent
    • Method of delivery
    • Summary of data sources searched
    • Any exemptions relied upon
    • Whether deadlines were met / extended and why
  • Note any process improvements (e.g. need for better data mapping, templates, or tools).

Download Your Subject Access Request Checklist here

Complete the form below to get a template checklist direct to your inbox – and remember to check your junk folder.

Name(Required)
We will send the information you have asked for by email, so please ensure you put the correct email in the field below. We may also send you follow up emails to showcase some of our products and services, but you can unsubscribe from these at any time.
Would you like to sign up to our newsletter?
Get articles like this, the latest news and exclusive offers direct to your inbox with our regular newsletter. This is separate from out other emails and we won't use your data for anything else and you can unsubscribe at any time

 

Subject Access Request Timeline

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial