What Is a Subject Access Request? The UK GDPR Rules Explained
What is a subject access request under UK GDPR? Recognise one without magic words, start the one-month clock, search properly and respond lawfully.

An employee emails a manager asking for “everything you hold about me, including the notes from last month's meeting”. The message never says UK GDPR or DSAR. It can still start a legal deadline, because a subject access request is identified by what the person asks for, not by a form or a set of magic words 1,2.
Quick Answer. A subject access request is a person's request to use the UK GDPR right of access: confirmation that an organisation processes their personal data, a copy, and required information about that processing. It may be oral or written, needs no special wording, and must be answered within one month 1,2.
For access rights governed by the EU GDPR, use the EU GDPR subject-access guide.
The right is broader than a copy of one file
A subject access request, often shortened to SAR or DSAR, exercises the right of access in UK GDPR Article 15. The person can ask whether personal data about them is being processed. Where it is, the response includes a copy of that personal data and specified information that explains the processing 1,2.
| Part of the response | What it tells the person |
|---|---|
| Confirmation | Whether the organisation processes personal data about them |
| Copy | The personal data within scope, presented in an intelligible form |
| Purposes and categories | Why the data is used and the types involved |
| Recipients | Who receives it, including categories where applicable |
| Retention | How long it will be kept, or the criteria used to decide |
| Rights and source | Relevant rights and, where the data did not come from the person, available source information |
| Safeguards | Required information about relevant transfers and automated decision-making where applicable |
The right concerns personal data, not every document that happens to mention the requester. One email may contain the requester's personal data, another person's personal data, confidential business information and material that falls under an exemption. The response exercise identifies and handles those elements rather than treating the document as indivisible.
A request can arrive anywhere
No form is required. A request can be made orally or in writing and can reach an organisation through an ordinary contact channel 2. “Send me the notes you keep about my performance” may be enough. A customer asking only for a copy invoice may simply want the invoice, so context matters, but staff should not demand legal terminology before recognising a clear access request.
The wording is secondary; the substance controls.
The operational risk is routing. A request sent to a shop inbox, a social account or a line manager can still be received by the organisation. Front-line staff need one short instruction: preserve the message, note the arrival time and send it to the responsible person immediately. The internal hand-off cannot restart the external clock.
Identity checks should be proportionate. The organisation can ask for information needed to confirm identity, especially where disclosure to the wrong person would create harm. It should not collect excessive identification by default or use verification as a delaying tactic 2.
The one-month clock needs an owner
The normal response period is one month. UK GDPR permits an extension by two further months where necessary because of complexity or the number of requests, but the organisation must notify the person within the first month and explain the delay 1,2. An extension is a reasoned exception, not spare time added to every difficult search.
Day one should produce an auditable control record:
| Day-one field | Entry |
|---|---|
| Received | Date, time, channel and exact request |
| Requester | Known identity and any proportionate verification needed |
| Scope | People, systems, teams, dates and data types reasonably implicated |
| Owner | Named coordinator and decision authority |
| Deadline | Normal one-month date and an earlier internal review date |
| Hold | Instructions preventing relevant material from routine deletion |
| Search plan | Systems, mailboxes, files, processors and paper records to check |
| Decisions | Clarification, extension, exemptions, redaction and response format |
Clarification can make an uncertain request workable, but it should not become a ritual demand that the person narrow a request the organisation already understands. Record what was clarified and when. Continue with the parts that are clear rather than allowing one uncertain phrase to freeze the whole response.
Searching means following the data, not one system
Current law expressly requires only a reasonable and proportionate search for the personal data and other information in scope 2,4. Apply that standard to the request's scope and the organisation's real information flows. Relevant data may sit in email, customer systems, HR folders, call recordings, collaboration tools, archives, devices, processor platforms and paper files.
Reasonable and proportionate does not mean choosing the easiest database. Identify likely custodians and systems, preserve the search instruction, and use terms that reflect names, identifiers, aliases, dates and the way the business actually records the person. Results need deduplication and review. Record how scope was set, which people and systems were searched, the terms and date ranges used, and any reasoned limitations. That record demonstrates the scope and method rather than asserting that the search was complete 2,4.
Processors may hold data on the controller's behalf. The contract and operating procedure should let the controller obtain it in time. The person should not be sent away to a payroll provider or software vendor merely because the data is stored there; responsibility follows the controller's processing arrangements 1,2.
Review protects other people as well as the requester
Search results are not ready to send. The organisation must identify the requester's personal data, consider information about other individuals, apply relevant restrictions or exemptions carefully, and present the result securely and intelligibly. The Data Protection Act 2018 contains domestic provisions that may affect particular material 3.
Third-party information requires judgement. It should not be disclosed merely because it appears beside the requester's data, but the presence of another person does not justify withholding the whole document automatically. Redaction, consent, the reasonableness of disclosure and the surrounding circumstances may matter. Each material decision should be recorded.
The response channel also belongs in the risk assessment. A carefully reviewed file can become a breach if sent to an unverified address or exposed through an open link. Confirm the destination, protect the package appropriately and keep evidence of what was supplied and when.
“Manifestly excessive” is a demanding conclusion
A large or inconvenient request is not automatically manifestly excessive. The legal test is deliberately stronger than “takes significant work”. The organisation should consider the request's context, whether it repeats earlier requests, the overlap, the burden and the value of the information to the person, then be able to demonstrate why the threshold is met 1,2.
Where a focused conversation would resolve avoidable breadth, offer it. Do not pressure the person to abandon valid scope. If the organisation relies on the manifestly unfounded or excessive provisions to charge a reasonable fee or refuse action, the response should explain the decision and inform the person about complaint and judicial-remedy rights 1,2.
Freedom of information and erasure are different rights. A public-authority information request is not converted into a DSAR merely because a person made it. An access request also does not instruct the organisation to delete the data. One message can contain several rights; separate and answer each part under its own rule.
Three actions on the day it arrives
First, preserve the request exactly as received and log the external deadline. Second, confirm the owner, identity position and reasonable scope. Third, issue a search and preservation instruction to the systems and people most likely to hold responsive personal data. Those steps create control before the volume of documents becomes visible.
The quality test is simple: another responsible colleague should be able to open the record tomorrow, see what the person asked, know the deadline, repeat the search and understand every withholding or redaction decision. That record is how a small organisation turns an unexpected email into a lawful, timely response.
Last updated: 26 August 2026.
Frequently Asked Questions
What is a subject access request under UK GDPR?
Does a subject access request need to be in writing?
How long do we have to answer a subject access request?
Can we charge a fee for a subject access request?
Can we refuse a manifestly excessive request?
Is a subject access request the same as freedom of information?
Sources
Want this run on your business?
AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.
You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.