Updated for the Data (Use and Access) Act 2025 & the ICO's 2026 right-of-access guidance

How to respond to a subject access request

A plain-English guide for UK organisations. No login, no paywall — the whole process is on this page.

The short answer

You have one calendar month from the day the request arrives. In that time you must run a reasonable and proportionate search of the places the person's data is likely to be, remove or withhold other people's personal data, and send them a copy along with the supplementary information the law requires. The clock pauses while you wait for proof of identity or for the requester to clarify what they actually want. If the request is genuinely complex, you can take up to two extra months — but you have to tell them, and explain why, inside the first month.

Want this as a PDF — with the response-letter template?

The SAR Response Kit: this whole process, a search checklist you can work through, and a letter template you can adapt. Free.
Free, no spam. We may email you once or twice about SARequest — unsubscribe anytime. See privacy.
1 calendar month
to respond, counted from the day the request arrives
Normally free
a fee is only allowed if the request is manifestly unfounded or excessive, or for extra copies
+2 months
available for complex or multiple requests — but you must tell them within month one
Any format
no special form is required; a SAR can even be made verbally
The process

The eight steps, in order

This is what a defensible SAR response looks like from the moment it lands to the moment you close the file.

1

Recognise it, and log the date it arrived

There is no such thing as an invalid channel. A SAR can arrive by email, letter, web form, social media — or be said out loud to any member of your staff. It doesn't have to use the words "subject access request", cite the UK GDPR, or explain why.

That makes the most valuable habit a cultural one: front-line staff need to know that anything resembling "send me what you hold on me" gets forwarded the same day. Record the date received, the channel, and who it came from.

Why it matters: the clock starts on the day it arrives, not the day it reaches the right desk. Requests that sit unnoticed in a shared inbox are the single most common reason organisations blow the deadline.
2

Confirm it really is a subject access request

A SAR is a person asking for their own personal data. It is not a Freedom of Information request (which applies to public authorities and covers any recorded information), it is not disclosure in litigation, and it is not a general "explain your decision" complaint — though it often arrives bundled with one.

If someone is asking for data about a third party, they need that person's authority. Classify it correctly on day one, or you'll spend a month answering the wrong question.

3

Verify who you're dealing with

Where you have genuine doubt about the requester's identity, ask for proof — and the clock pauses from the day you ask until the day after you receive it. This is the "stop the clock" mechanism, now on a statutory footing under the Data (Use and Access) Act 2025.

Treat it as a safeguard, not a delaying tactic. Handing someone's HR file to an impersonator is a data breach in its own right. Ask only for what's proportionate, and ask immediately — not in week three.

4

Narrow the scope — if it's genuinely broad

If you process a large amount of information about the person, you're entitled to ask them to specify what they're actually after. The clock pauses here too, on the same basis.

Two cautions. This only works if you genuinely do hold a lot. And you must still respond to whatever they come back with — including "all of it", which is a valid answer. A clarification request used as a stalling device tends to be obvious to both the requester and the ICO.

5

Run a reasonable and proportionate search

This is the part most organisations get wrong, and the part the law changed most recently. The Data (Use and Access) Act 2025 wrote the "reasonable and proportionate" standard into legislation, confirming what ICO guidance had said for years: you must make reasonable efforts, but you are not obliged to search where doing so would be disproportionate to the value of providing the information.

You're entitled to weigh the volume of data involved, how it's stored and retrieved, genuine technical limitations, the nature of your organisation, and the resources you actually have. What you are not entitled to do is skip the search and hope.

Typical scope worth working through:

  • Mailboxes — theirs, and colleagues who corresponded about them
  • HR, case-management or CRM systems
  • Shared drives, SharePoint, OneDrive
  • Teams / Slack messages
  • Finance and billing records
  • Call recordings and CCTV, within your retention window
  • Paper files and archived storage
Document as you go. Write down what you searched, what you decided not to search, and why. That record is your entire defence if the response is later challenged — and under the new standard it's the difference between a proportionate search and an unevidenced one.
6

Decide what you can't hand over

Two separate questions, often confused.

Other people's data. You don't have to disclose information identifying a third party unless that person consents, or it's reasonable to comply without their consent. Weigh it case by case — a colleague's name in a work email is not the same as a colleague's medical detail.

Exemptions. Legal professional privilege, management forecasting, negotiations, crime prevention and others may apply to specific material. Apply them narrowly and record your reasoning.

The distinction that saves time: you're disclosing the requester's personal data — not automatically every document that data happens to sit inside.
7

Redact properly — not visually

A black rectangle drawn over text in a PDF is not redaction. The text is still underneath, and anyone can select and copy it out. This is one of the most common ways a SAR response becomes a reportable personal data breach — the organisation met the deadline and disclosed the very thing it was trying to protect.

Use tooling that genuinely destroys the underlying content, flatten the output, then open the finished file and try to select the redacted areas yourself before it goes anywhere.

8

Respond — and be able to evidence it

Send a copy of their personal data, plus the supplementary information the law requires: what you use it for, who you share it with, how long you keep it, where it came from, and what other rights they have.

Normally there is no fee. You can only charge where a request is manifestly unfounded or excessive, or for additional copies — and if you do charge, the clock doesn't start until the fee is paid.

Then keep the file: dates, searches run, decisions taken, exemptions applied, and exactly what was sent. If this ever becomes an ICO complaint or a tribunal exhibit, that trail is what you'll be judged on.

When is your response actually due?

Free tool. Enter the date the request arrived and get your statutory deadline — including how the complexity extension and weekend rules affect it.

  • Based on UK GDPR & the Data (Use and Access) Act 2025
  • Applies the one calendar month rule correctly
  • Flags when a complexity extension may apply
Free download

Take the whole thing with you.

The SAR Response Kit is everything on this page as a PDF you can forward to whoever actually has to do the work — plus the two things that aren't on this page:

  • A search checklist you can work through system by system and keep as your evidence
  • A response-letter template you can adapt and send
Instant download · free · no card. For UK organisations of any kind — employers, councils, housing, healthcare, finance.
When the manual version stops working

Doing this by hand is fine — once.

The trouble starts when the mailbox search returns four thousand documents, or the request lands in the middle of a dispute, or three arrive in the same month. That's the problem we're building software to solve.

🔍

Everything, however old

There's no time limit on a SAR. Every email, file, chat message and record you hold on the person is potentially in scope — scattered across every system you run.

✂️

Redaction is the hard part

Third-party data has to come out before disclosure. Doing that by hand across thousands of pages is where the hours go — and where the breaches happen.

⏱️

The clock doesn't care

One calendar month, regardless of volume, staffing or annual leave. The right of access is now the single biggest source of ICO data-protection complaints.

£4,000–7,500
typical cost of handling one complex SAR manually
39%
of all ICO data-protection complaints concern the right of access
+43%
year-on-year rise in data subject requests
How SARequest works

You stay in control. We do the heavy lifting.

Every document — pulled from your systems or scanned in — is screened automatically: what's relevant, what needs blacking out, what can be withheld. Nothing is sent until you've signed it off.

Log & verify

Record the request, start the statutory clock, and confirm the requester's identity — the safeguard that stops data going to the wrong person.

Search

Connect your systems once. SARequest searches everything you've connected for records relating to the individual, however far back they go — and scanned paper can be uploaded and made searchable too.

Redact & review

Third-party details are redacted and exemptions flagged for your review — with the reasoning shown, so you decide what stands.

Deliver & prove

Send a clean response pack by secure link, with a full audit trail evidencing a reasonable and proportionate search.

Founding pilot

Built with a handful of organisations, not just for them.

We're building the tool that turns a complex SAR into an afternoon's review — and shaping it around the first organisations who join.

Founding pilot — now open
  • Handle every subject access request in one place
  • Microsoft 365 connection + upload portal for scanned paper & other files
  • Automated search of electronic records & suggested redactions
  • CCTV / body-worn video request workflow
  • Statutory deadline tracking with stop-the-clock
  • Secure delivery & full audit trail
  • UK-hosted · data purged on a schedule you control
Apply to join the pilot
No card, no commitment. We'll only build it if enough organisations want it — pilot members shape what we ship and get first access at launch.
Security & trust

A compliance tool that's actually compliant.

You'd be connecting us to your most sensitive data, often during a dispute. That's why security isn't a feature here — it's the foundation.

Access is granted by you, scoped to what a live case requires, and revocable at any time
UK / EU hosting only — your data never leaves the region
We're a pipeline, not an archive — source data purged on case close
You control how long the finished pack is retained
Identity verification enforced before any data is released
True, destructive redaction — never a black box over live text
Your data is never used to train AI models
Our team has no routine access to your case content — any access is least-privilege, logged and exceptional
Every action logged for your audit trail
Data Processing Agreement with every customer