Most people understand a Subject Access Request (SAR) as a request for a copy of personal data. That’s true—but it’s also incomplete. Article 15 of the GDPR requires organisations to provide not only the personal data itself, but also a package of supplementary information that explains how and why the organisation processes that data.
- You can read a step-by-guide to handling a subject access request here
This matters because access without context can be meaningless. A spreadsheet of records or a bundle of emails tells someone what you hold, but not what it means, what you do with it, or what rights they can exercise next.
Download Your Subject Access Request Response Template Here
Alongside this article we have produced an Article 15 compliant response template you can adapt and use. Download it here:
The legal requirement in plain terms
When an organisation receives a valid subject access request, it must confirm whether it processes the requester’s personal data and, if it does, provide:
- A copy of the personal data, and
- Supplementary information that supports transparency and accountability.
This supplementary information aligns closely with what people typically see in privacy notices, but Article 15 requires it to be provided as part of the SAR response (unless the person already has it).
What counts as “supplementary information”?
Article 15 sets out the information that must accompany the disclosure. In practice, SAR responses should include:
- Purposes of processing
Why the organisation uses the data (e.g., payroll administration, service delivery, safeguarding, marketing suppression). - Categories of personal data
The types of data involved (e.g., contact details, employment records, health information, financial details). - Recipients or categories of recipients
Who receives the data—internal teams, processors (like payroll providers), partner organisations, regulators. - International transfers
If data goes outside the UK/EU, the organisation must explain where and what safeguards it uses (such as adequacy decisions or standard contractual clauses). - Retention periods
How long the organisation keeps the data, or how it decides retention (e.g., “six years after contract end,” or “in line with our retention schedule”). - Rights available to the individual
Including rights to rectification, erasure, restriction, objection, portability (where relevant), and the right to complain to the regulator. - The source of the data (where it wasn’t collected from the individual)
For example, referrals, third-party agencies, public sources, previous employers, or shared systems. - Automated decision-making and profiling (where used)
If decisions occur solely by automated means with legal or similarly significant effects, the response must include meaningful information about the logic and likely consequences.
That’s the “context layer” Article 15 demands.
Why this requirement exists
GDPR’s broader aim is to give people control and understanding, not just visibility. Supplementary information helps individuals:
- interpret what they receive,
- identify inaccuracies,
- challenge unfair processing,
- exercise other rights confidently.
For organisations, it also demonstrates accountability. A response to a subject access request that includes clear Article 15 information looks competent and defensible. A response that dumps data with no explanation often invites follow-up complaints.

Common pitfalls to avoid
A few mistakes appear again and again in SAR handling:
- Providing data but omitting Article 15 information entirely.
- Using generic wording that doesn’t match the individual’s context or processing activity.
- Failing to describe recipients properly, especially processors and partner organisations.
- Overlooking international transfers, particularly via cloud services.
- Missing the “source of data” requirement, which often applies in HR, healthcare, and safeguarding contexts.
The best approach is to use a structured SAR template that always includes an “Article 15 Supplementary Information” section.
Sign Up Here:
A strong SAR response usually has two parts: This structure improves clarity, reduces disputes, and supports consistency across cases. Subject access is not simply a data export exercise. Article 15 turns SAR handling into a transparency obligation. Providing supplementary information is how organisations prove they respect the right of access in substance—not just in form. If you want SAR processes to run smoothly, build Article 15 into the workflow from day one. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.
Practical tip: treat Article 15 like a Subject Access Request “cover letter”
Closing thought
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: