Subject Access Request Response Template

Most people understand a Subject Access Request (SAR) as a request for a copy of personal data. That’s true—but it’s also incomplete. Article 15 of the GDPR requires organisations to provide not only the personal data itself, but also a package of supplementary information that explains how and why the organisation processes that data.

  • You can read a step-by-guide to handling a subject access request here

This matters because access without context can be meaningless. A spreadsheet of records or a bundle of emails tells someone what you hold, but not what it means, what you do with it, or what rights they can exercise next.

Download Your Subject Access Request Response Template Here

Alongside this article we have produced an Article 15 compliant response template you can adapt and use. Download it here:

Name(Required)
We will send the information you have asked for by email, so please ensure you put the correct email in the field below. We may also send you follow up emails to showcase some of our products and services, but you can unsubscribe from these at any time.
Would you like to sign up to our newsletter?
Get articles like this, the latest news and exclusive offers direct to your inbox with our regular newsletter. This is separate from out other emails and we won't use your data for anything else and you can unsubscribe at any time

 

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

The legal requirement in plain terms

When an organisation receives a valid subject access request, it must confirm whether it processes the requester’s personal data and, if it does, provide:

  1. A copy of the personal data, and
  2. Supplementary information that supports transparency and accountability.

This supplementary information aligns closely with what people typically see in privacy notices, but Article 15 requires it to be provided as part of the SAR response (unless the person already has it).


What counts as “supplementary information”?

Article 15 sets out the information that must accompany the disclosure. In practice, SAR responses should include:

  • Purposes of processing
    Why the organisation uses the data (e.g., payroll administration, service delivery, safeguarding, marketing suppression).
  • Categories of personal data
    The types of data involved (e.g., contact details, employment records, health information, financial details).
  • Recipients or categories of recipients
    Who receives the data—internal teams, processors (like payroll providers), partner organisations, regulators.
  • International transfers
    If data goes outside the UK/EU, the organisation must explain where and what safeguards it uses (such as adequacy decisions or standard contractual clauses).
  • Retention periods
    How long the organisation keeps the data, or how it decides retention (e.g., “six years after contract end,” or “in line with our retention schedule”).
  • Rights available to the individual
    Including rights to rectification, erasure, restriction, objection, portability (where relevant), and the right to complain to the regulator.
  • The source of the data (where it wasn’t collected from the individual)
    For example, referrals, third-party agencies, public sources, previous employers, or shared systems.
  • Automated decision-making and profiling (where used)
    If decisions occur solely by automated means with legal or similarly significant effects, the response must include meaningful information about the logic and likely consequences.

That’s the “context layer” Article 15 demands.


Why this requirement exists

GDPR’s broader aim is to give people control and understanding, not just visibility. Supplementary information helps individuals:

  • interpret what they receive,
  • identify inaccuracies,
  • challenge unfair processing,
  • exercise other rights confidently.

For organisations, it also demonstrates accountability. A response to a subject access request that includes clear Article 15 information looks competent and defensible. A response that dumps data with no explanation often invites follow-up complaints.

 

Periodic Table of the GDPR

 


Common pitfalls to avoid

A few mistakes appear again and again in SAR handling:

  • Providing data but omitting Article 15 information entirely.
  • Using generic wording that doesn’t match the individual’s context or processing activity.
  • Failing to describe recipients properly, especially processors and partner organisations.
  • Overlooking international transfers, particularly via cloud services.
  • Missing the “source of data” requirement, which often applies in HR, healthcare, and safeguarding contexts.

The best approach is to use a structured SAR template that always includes an “Article 15 Supplementary Information” section.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 


Practical tip: treat Article 15 like a Subject Access Request “cover letter”

A strong SAR response usually has two parts:

  1. Cover letter / schedule containing the Article 15 information
  2. Disclosure pack with the personal data (with redactions/exemptions applied where lawful)

This structure improves clarity, reduces disputes, and supports consistency across cases.


Closing thought

Subject access is not simply a data export exercise. Article 15 turns SAR handling into a transparency obligation. Providing supplementary information is how organisations prove they respect the right of access in substance—not just in form.

If you want SAR processes to run smoothly, build Article 15 into the workflow from day one.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial