
A plain-English guide for UK organisations. No login, no paywall — the whole process is on this page.
You have one calendar month from the day the request arrives. In that time you must run a reasonable and proportionate search of the places the person's data is likely to be, remove or withhold other people's personal data, and send them a copy along with the supplementary information the law requires. The clock pauses while you wait for proof of identity or for the requester to clarify what they actually want. If the request is genuinely complex, you can take up to two extra months — but you have to tell them, and explain why, inside the first month.
It's also on its way to your inbox — check spam if it doesn't arrive in a minute.
Download the PDF →This is what a defensible SAR response looks like from the moment it lands to the moment you close the file.
There is no such thing as an invalid channel. A SAR can arrive by email, letter, web form, social media — or be said out loud to any member of your staff. It doesn't have to use the words "subject access request", cite the UK GDPR, or explain why.
That makes the most valuable habit a cultural one: front-line staff need to know that anything resembling "send me what you hold on me" gets forwarded the same day. Record the date received, the channel, and who it came from.
A SAR is a person asking for their own personal data. It is not a Freedom of Information request (which applies to public authorities and covers any recorded information), it is not disclosure in litigation, and it is not a general "explain your decision" complaint — though it often arrives bundled with one.
If someone is asking for data about a third party, they need that person's authority. Classify it correctly on day one, or you'll spend a month answering the wrong question.
Where you have genuine doubt about the requester's identity, ask for proof — and the clock pauses from the day you ask until the day after you receive it. This is the "stop the clock" mechanism, now on a statutory footing under the Data (Use and Access) Act 2025.
Treat it as a safeguard, not a delaying tactic. Handing someone's HR file to an impersonator is a data breach in its own right. Ask only for what's proportionate, and ask immediately — not in week three.
If you process a large amount of information about the person, you're entitled to ask them to specify what they're actually after. The clock pauses here too, on the same basis.
Two cautions. This only works if you genuinely do hold a lot. And you must still respond to whatever they come back with — including "all of it", which is a valid answer. A clarification request used as a stalling device tends to be obvious to both the requester and the ICO.
This is the part most organisations get wrong, and the part the law changed most recently. The Data (Use and Access) Act 2025 wrote the "reasonable and proportionate" standard into legislation, confirming what ICO guidance had said for years: you must make reasonable efforts, but you are not obliged to search where doing so would be disproportionate to the value of providing the information.
You're entitled to weigh the volume of data involved, how it's stored and retrieved, genuine technical limitations, the nature of your organisation, and the resources you actually have. What you are not entitled to do is skip the search and hope.
Typical scope worth working through:
Two separate questions, often confused.
Other people's data. You don't have to disclose information identifying a third party unless that person consents, or it's reasonable to comply without their consent. Weigh it case by case — a colleague's name in a work email is not the same as a colleague's medical detail.
Exemptions. Legal professional privilege, management forecasting, negotiations, crime prevention and others may apply to specific material. Apply them narrowly and record your reasoning.
A black rectangle drawn over text in a PDF is not redaction. The text is still underneath, and anyone can select and copy it out. This is one of the most common ways a SAR response becomes a reportable personal data breach — the organisation met the deadline and disclosed the very thing it was trying to protect.
Use tooling that genuinely destroys the underlying content, flatten the output, then open the finished file and try to select the redacted areas yourself before it goes anywhere.
Send a copy of their personal data, plus the supplementary information the law requires: what you use it for, who you share it with, how long you keep it, where it came from, and what other rights they have.
Normally there is no fee. You can only charge where a request is manifestly unfounded or excessive, or for additional copies — and if you do charge, the clock doesn't start until the fee is paid.
Then keep the file: dates, searches run, decisions taken, exemptions applied, and exactly what was sent. If this ever becomes an ICO complaint or a tribunal exhibit, that trail is what you'll be judged on.
Free tool. Enter the date the request arrived and get your statutory deadline — including how the complexity extension and weekend rules affect it.
The SAR Response Kit is everything on this page as a PDF you can forward to whoever actually has to do the work — plus the two things that aren't on this page:
It's also on its way to your inbox — check spam if it doesn't arrive in a minute.
Download the PDF →The trouble starts when the mailbox search returns four thousand documents, or the request lands in the middle of a dispute, or three arrive in the same month. That's the problem we're building software to solve.
There's no time limit on a SAR. Every email, file, chat message and record you hold on the person is potentially in scope — scattered across every system you run.
Third-party data has to come out before disclosure. Doing that by hand across thousands of pages is where the hours go — and where the breaches happen.
One calendar month, regardless of volume, staffing or annual leave. The right of access is now the single biggest source of ICO data-protection complaints.
Every document — pulled from your systems or scanned in — is screened automatically: what's relevant, what needs blacking out, what can be withheld. Nothing is sent until you've signed it off.
Record the request, start the statutory clock, and confirm the requester's identity — the safeguard that stops data going to the wrong person.
Connect your systems once. SARequest searches everything you've connected for records relating to the individual, however far back they go — and scanned paper can be uploaded and made searchable too.
Third-party details are redacted and exemptions flagged for your review — with the reasoning shown, so you decide what stands.
Send a clean response pack by secure link, with a full audit trail evidencing a reasonable and proportionate search.
We're building the tool that turns a complex SAR into an afternoon's review — and shaping it around the first organisations who join.
You'd be connecting us to your most sensitive data, often during a dispute. That's why security isn't a feature here — it's the foundation.