Skip to content

What Is a Subject Access Request? An EU GDPR Guide

What is a subject access request under EU GDPR? Recognise one without magic words, start the one-month clock, search completely and respond lawfully.

A layered-paper composition in which one blank request passes through five record stores and emerges as an open response packet beside a mauve clip.
By AI Priority Map Editorial

An employee emails a manager asking for “everything you hold about me, including the notes from last month's meeting”. The message never says EU GDPR or DSAR. It can still start a legal deadline because a subject access request is identified by what the person asks for, not by a form or a set of magic words 1,2.

Quick Answer. A subject access request is a person's request to use the EU GDPR right of access: confirmation that a controller processes their personal data, access to those data, and required information. It may be oral or written, needs no special wording, and normally requires a response within one month 1,2.

The right is broader than a copy of one file

A subject access request, often shortened to SAR or DSAR, exercises the right of access in Article 15 of EU GDPR (Regulation (EU) 2016/679). The person can ask whether personal data about them is being processed. Where it is, the response provides access to those data, a copy and specified information explaining the processing 1,2.

Part of the responseWhat it tells the person
ConfirmationWhether the controller processes personal data about them
CopyThe personal data within scope, supplied in a faithful and intelligible form
Purposes and categoriesWhy the data is used and the categories involved
RecipientsWho receives it, including categories where the GDPR permits that form
RetentionHow long it will be kept, or the criteria used to decide
Rights and sourceRelevant rights and, where data did not come from the person, available source information
SafeguardsRequired information about relevant transfers and automated decision-making where applicable

The right concerns personal data, not every document that happens to mention the requester. Sometimes extracts or whole documents are necessary to make the personal data intelligible. The Court of Justice has held that a “copy” must be a faithful and intelligible reproduction, with document extracts or entire documents supplied where that context is essential for effective access 3.

One email may contain the requester's personal data, another person's personal data, confidential business information and material affected by a lawful restriction. The response exercise identifies and handles those elements rather than treating the document as indivisible.

A request can arrive anywhere

The GDPR imposes no particular form. A request can be oral or written and can reach a controller through an appropriate ordinary contact channel 2. “Send me the notes you keep about my performance” may be enough. A customer asking only for a copy invoice may simply want the invoice, so context matters, but staff should not demand legal terminology before recognising a clear access request.

The wording is secondary; the substance controls.

The operational risk is routing. A request sent to a published shop inbox, a social account used for customer contact or a line manager may still reach the controller. Front-line staff need one short instruction: preserve the message, note the arrival time and send it to the responsible person immediately. An internal hand-off does not restart the external clock 2,5.

Identity checks must respond to the facts. Article 12(6) permits additional information where the controller has reasonable doubts about identity. The EDPB warns against collecting excessive identification as a default barrier 1,2,5. The controller should ask only for what is necessary to resolve the doubt and avoid using verification as a delaying tactic.

The one-month clock needs an owner

The controller must provide information on action taken without undue delay and normally within one month of receipt. Article 12(3) permits an extension by two further months where necessary because of complexity or the number of requests, but the person must be told within the first month and given the reason 1,2. An extension is a reasoned exception rather than spare time added to every difficult search.

Day one should produce an auditable control record:

Day-one fieldEntry
ReceivedDate, time, channel and exact request
RequesterKnown identity and any evidence-based verification needed
ScopePeople, systems, teams, dates and data types implicated by the request
OwnerNamed coordinator and decision authority
DeadlineNormal one-month date and an earlier internal review date
HoldInstructions preventing relevant material from routine deletion
Search planSystems, mailboxes, files, processors and paper records to check
DecisionsClarification, extension, restrictions, third-party review and response format

Clarification can make an uncertain request workable, but it should not become a ritual demand that a person narrow a request the controller already understands. The controller remains responsible for facilitating the right. Any clarification and its timing should be recorded, and clear parts should continue rather than allowing one uncertain phrase to freeze the whole response 1,2.

EU searches do not use the UK proportionality shortcut

EU GDPR has no general rule limiting an Article 15 search to what is “reasonable and proportionate”. That wording is a recent clarification in current UK law, not part of Regulation (EU) 2016/679. An EU controller should not import it as a search ceiling or stop because the easiest database produced some results 1,2.

The difference is operational, not semantic. A controller answering an EU request cannot cite the UK clarification as authority for searching only the systems that are convenient. Its search plan must follow the data within the understood scope and remain capable of showing where responsive personal data was sought 1,2.

The controller instead has to identify and retrieve personal data within the request's scope across its real information environment. Relevant data may sit in email, customer systems, HR folders, call recordings, collaboration tools, archives, devices, processor platforms and structured paper files. Search criteria should reflect names, identifiers, aliases, dates and the ways the organisation actually records the person 2.

That is not an unlimited right to every document. Article 12(5) addresses manifestly unfounded or excessive requests, Article 15(4) protects the rights and freedoms of others, and Article 23 permits restrictions through qualifying Union or Member State law. Those are defined legal controls, not a substitute “reasonable search” standard. The controller bears the burden of demonstrating a manifestly unfounded or excessive conclusion 1,2.

Processors may hold data on the controller's behalf. The contract and operating procedure should let the controller obtain it in time. The person should not be sent away to a payroll provider or software vendor merely because data is stored there; responsibility follows the controller's processing arrangements 1,2.

Review protects other people as well as the requester

Search results are not ready to send. The controller must identify the requester's personal data, consider information about other individuals, apply any valid restriction carefully, and present the result securely and intelligibly. Article 15(4) states that the right to a copy must not adversely affect the rights and freedoms of others, but that does not justify withholding the entire response automatically 1,2,3.

Third-party information requires judgement. Redaction, separation of data and the surrounding circumstances may matter. The EDPB explains that the controller should try to reconcile the competing rights instead of treating another person's presence as a complete refusal ground 2. Each material decision should be recorded.

The response channel also belongs in the risk assessment. A carefully reviewed file can become a personal data breach if sent to an unverified address or exposed through an open link. The destination should be confirmed, the package protected appropriately, and evidence retained of what was supplied and when.

“Manifestly excessive” is a demanding conclusion

A large or inconvenient request is not automatically manifestly excessive. The legal threshold is stronger than “takes significant work”. The controller should consider the request's context, including repetition and overlap, and must be able to demonstrate why Article 12(5) applies 1,2. The EDPB's coordinated enforcement action found excessive interpretations of access limits and formal barriers among the practical problems requiring improvement 5.

Where a focused conversation would locate the data more efficiently, the controller can offer it without pressuring the person to abandon valid scope. If Article 12(5) supports a reasonable fee or refusal, the response must explain the decision and inform the person about the right to complain to a supervisory authority and seek a judicial remedy 1,2.

The first copy is free in principle. The Court of Justice confirmed that national rules cannot generally require a person to pay for that first copy, even where the person intends to use it for a purpose beyond checking the processing. Fees for further copies and the manifestly unfounded or excessive route remain governed by the GDPR's own conditions 1,4.

Access-to-documents, freedom-of-information and erasure requests are different rights. An access-to-documents request is not converted into a GDPR request merely because a person made it, and an Article 15 request does not instruct the controller to delete data. One message can contain several rights; each part should be separated and answered under its applicable legal rule.

Three actions on the day it arrives

First, preserve the request exactly as received and log the external deadline. Second, confirm the owner, identity position and understood scope. Third, issue a search and preservation instruction to the systems and people likely to hold responsive personal data. Those steps create control before the volume of records becomes visible.

The quality test is simple: another responsible colleague should be able to open the record tomorrow, see what the person asked, know the deadline, repeat the search and understand every restriction, separation or redaction decision. That record is how a small organisation turns an unexpected message into a lawful and timely response.

Last updated: 26 August 2026.

Frequently Asked Questions

What is a subject access request under EU GDPR?
A subject access request is a person's request to use the EU GDPR right of access. It asks whether a controller processes their personal data and, if so, for access to those data plus specified information about the processing. The request can be oral or written and does not require a form, legal wording or the letters DSAR [1][2].
Does a subject access request need to be in writing?
No. The GDPR sets no particular form for an access request. A person may use an appropriate contact channel and staff should recognise the substance instead of waiting for a template. The controller should record the request promptly, confirm what was asked, consider whether identity verification is needed and route it to the person responsible for the response [1][2].
How long do we have to answer a subject access request?
The controller must respond without undue delay and normally within one month. The period can be extended by two further months where necessary because of complexity or the number of requests, but the person must be told within the first month and given the reason. The extension is not an automatic allowance for workload or delay [1][2].
Can we charge a fee for a subject access request?
The first copy is normally free. A reasonable fee based on administrative costs may apply to further copies, or where a request is manifestly unfounded or excessive under Article 12(5). The controller needs evidence for that conclusion. A demanding search does not automatically make a first request excessive, and national rules cannot generally shift the first-copy cost to the person [1][2][4].
Can we refuse a manifestly excessive request?
Refusal is not a shortcut for a difficult request. The controller must demonstrate that the request is manifestly unfounded or excessive, taking its context into account. Where clarification would help locate the data, the controller should discuss scope without forcing the person to abandon valid access. A justified refusal must explain complaint and judicial-remedy rights [1][2].
Is a subject access request the same as freedom of information?
No. A GDPR access request concerns the requester's own personal data. Access-to-documents or freedom-of-information regimes concern recorded information held by bodies within their scope and depend on applicable Union or Member State law. One message may engage both regimes, but the organisation should identify and handle each request under its own rules rather than forcing one label onto it [1][2].

Sources

  1. 1.Regulation (EU) 2016/679 (General Data Protection Regulation)Official Journal of the European Union · 2016
  2. 2.Guidelines 01/2022 on data subject rights - Right of accessEuropean Data Protection Board · 2023
  3. 3.Judgment of the Court in Case C-487/21Court of Justice of the European Union · 2023
  4. 4.Judgment of the Court in Case C-307/22Court of Justice of the European Union · 2023
  5. 5.Coordinated Enforcement Action: implementation of the right of access by controllersEuropean Data Protection Board · 2025

Want this run on your business?

AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.

Start your audit

You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.