What Is a Subject Access Request? An EU GDPR Guide
What is a subject access request under EU GDPR? Recognise one without magic words, start the one-month clock, search completely and respond lawfully.

An employee emails a manager asking for “everything you hold about me, including the notes from last month's meeting”. The message never says EU GDPR or DSAR. It can still start a legal deadline because a subject access request is identified by what the person asks for, not by a form or a set of magic words 1,2.
Quick Answer. A subject access request is a person's request to use the EU GDPR right of access: confirmation that a controller processes their personal data, access to those data, and required information. It may be oral or written, needs no special wording, and normally requires a response within one month 1,2.
The right is broader than a copy of one file
A subject access request, often shortened to SAR or DSAR, exercises the right of access in Article 15 of EU GDPR (Regulation (EU) 2016/679). The person can ask whether personal data about them is being processed. Where it is, the response provides access to those data, a copy and specified information explaining the processing 1,2.
| Part of the response | What it tells the person |
|---|---|
| Confirmation | Whether the controller processes personal data about them |
| Copy | The personal data within scope, supplied in a faithful and intelligible form |
| Purposes and categories | Why the data is used and the categories involved |
| Recipients | Who receives it, including categories where the GDPR permits that form |
| Retention | How long it will be kept, or the criteria used to decide |
| Rights and source | Relevant rights and, where data did not come from the person, available source information |
| Safeguards | Required information about relevant transfers and automated decision-making where applicable |
The right concerns personal data, not every document that happens to mention the requester. Sometimes extracts or whole documents are necessary to make the personal data intelligible. The Court of Justice has held that a “copy” must be a faithful and intelligible reproduction, with document extracts or entire documents supplied where that context is essential for effective access 3.
One email may contain the requester's personal data, another person's personal data, confidential business information and material affected by a lawful restriction. The response exercise identifies and handles those elements rather than treating the document as indivisible.
A request can arrive anywhere
The GDPR imposes no particular form. A request can be oral or written and can reach a controller through an appropriate ordinary contact channel 2. “Send me the notes you keep about my performance” may be enough. A customer asking only for a copy invoice may simply want the invoice, so context matters, but staff should not demand legal terminology before recognising a clear access request.
The wording is secondary; the substance controls.
The operational risk is routing. A request sent to a published shop inbox, a social account used for customer contact or a line manager may still reach the controller. Front-line staff need one short instruction: preserve the message, note the arrival time and send it to the responsible person immediately. An internal hand-off does not restart the external clock 2,5.
Identity checks must respond to the facts. Article 12(6) permits additional information where the controller has reasonable doubts about identity. The EDPB warns against collecting excessive identification as a default barrier 1,2,5. The controller should ask only for what is necessary to resolve the doubt and avoid using verification as a delaying tactic.
The one-month clock needs an owner
The controller must provide information on action taken without undue delay and normally within one month of receipt. Article 12(3) permits an extension by two further months where necessary because of complexity or the number of requests, but the person must be told within the first month and given the reason 1,2. An extension is a reasoned exception rather than spare time added to every difficult search.
Day one should produce an auditable control record:
| Day-one field | Entry |
|---|---|
| Received | Date, time, channel and exact request |
| Requester | Known identity and any evidence-based verification needed |
| Scope | People, systems, teams, dates and data types implicated by the request |
| Owner | Named coordinator and decision authority |
| Deadline | Normal one-month date and an earlier internal review date |
| Hold | Instructions preventing relevant material from routine deletion |
| Search plan | Systems, mailboxes, files, processors and paper records to check |
| Decisions | Clarification, extension, restrictions, third-party review and response format |
Clarification can make an uncertain request workable, but it should not become a ritual demand that a person narrow a request the controller already understands. The controller remains responsible for facilitating the right. Any clarification and its timing should be recorded, and clear parts should continue rather than allowing one uncertain phrase to freeze the whole response 1,2.
EU searches do not use the UK proportionality shortcut
EU GDPR has no general rule limiting an Article 15 search to what is “reasonable and proportionate”. That wording is a recent clarification in current UK law, not part of Regulation (EU) 2016/679. An EU controller should not import it as a search ceiling or stop because the easiest database produced some results 1,2.
The difference is operational, not semantic. A controller answering an EU request cannot cite the UK clarification as authority for searching only the systems that are convenient. Its search plan must follow the data within the understood scope and remain capable of showing where responsive personal data was sought 1,2.
The controller instead has to identify and retrieve personal data within the request's scope across its real information environment. Relevant data may sit in email, customer systems, HR folders, call recordings, collaboration tools, archives, devices, processor platforms and structured paper files. Search criteria should reflect names, identifiers, aliases, dates and the ways the organisation actually records the person 2.
That is not an unlimited right to every document. Article 12(5) addresses manifestly unfounded or excessive requests, Article 15(4) protects the rights and freedoms of others, and Article 23 permits restrictions through qualifying Union or Member State law. Those are defined legal controls, not a substitute “reasonable search” standard. The controller bears the burden of demonstrating a manifestly unfounded or excessive conclusion 1,2.
Processors may hold data on the controller's behalf. The contract and operating procedure should let the controller obtain it in time. The person should not be sent away to a payroll provider or software vendor merely because data is stored there; responsibility follows the controller's processing arrangements 1,2.
Review protects other people as well as the requester
Search results are not ready to send. The controller must identify the requester's personal data, consider information about other individuals, apply any valid restriction carefully, and present the result securely and intelligibly. Article 15(4) states that the right to a copy must not adversely affect the rights and freedoms of others, but that does not justify withholding the entire response automatically 1,2,3.
Third-party information requires judgement. Redaction, separation of data and the surrounding circumstances may matter. The EDPB explains that the controller should try to reconcile the competing rights instead of treating another person's presence as a complete refusal ground 2. Each material decision should be recorded.
The response channel also belongs in the risk assessment. A carefully reviewed file can become a personal data breach if sent to an unverified address or exposed through an open link. The destination should be confirmed, the package protected appropriately, and evidence retained of what was supplied and when.
“Manifestly excessive” is a demanding conclusion
A large or inconvenient request is not automatically manifestly excessive. The legal threshold is stronger than “takes significant work”. The controller should consider the request's context, including repetition and overlap, and must be able to demonstrate why Article 12(5) applies 1,2. The EDPB's coordinated enforcement action found excessive interpretations of access limits and formal barriers among the practical problems requiring improvement 5.
Where a focused conversation would locate the data more efficiently, the controller can offer it without pressuring the person to abandon valid scope. If Article 12(5) supports a reasonable fee or refusal, the response must explain the decision and inform the person about the right to complain to a supervisory authority and seek a judicial remedy 1,2.
The first copy is free in principle. The Court of Justice confirmed that national rules cannot generally require a person to pay for that first copy, even where the person intends to use it for a purpose beyond checking the processing. Fees for further copies and the manifestly unfounded or excessive route remain governed by the GDPR's own conditions 1,4.
Access-to-documents, freedom-of-information and erasure requests are different rights. An access-to-documents request is not converted into a GDPR request merely because a person made it, and an Article 15 request does not instruct the controller to delete data. One message can contain several rights; each part should be separated and answered under its applicable legal rule.
Three actions on the day it arrives
First, preserve the request exactly as received and log the external deadline. Second, confirm the owner, identity position and understood scope. Third, issue a search and preservation instruction to the systems and people likely to hold responsive personal data. Those steps create control before the volume of records becomes visible.
The quality test is simple: another responsible colleague should be able to open the record tomorrow, see what the person asked, know the deadline, repeat the search and understand every restriction, separation or redaction decision. That record is how a small organisation turns an unexpected message into a lawful and timely response.
Last updated: 26 August 2026.
Frequently Asked Questions
What is a subject access request under EU GDPR?
Does a subject access request need to be in writing?
How long do we have to answer a subject access request?
Can we charge a fee for a subject access request?
Can we refuse a manifestly excessive request?
Is a subject access request the same as freedom of information?
Sources
- 1.Regulation (EU) 2016/679 (General Data Protection Regulation) — Official Journal of the European Union · 2016
- 2.Guidelines 01/2022 on data subject rights - Right of access — European Data Protection Board · 2023
- 3.Judgment of the Court in Case C-487/21 — Court of Justice of the European Union · 2023
- 4.Judgment of the Court in Case C-307/22 — Court of Justice of the European Union · 2023
- 5.Coordinated Enforcement Action: implementation of the right of access by controllers — European Data Protection Board · 2025
Want this run on your business?
AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.
You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.