Dealing with your first Subject Access Request
Someone has asked for their data. Here’s what you have to provide, how long you have, what can you withhold, and how to avoid a request turning into a complaint.
It usually arrives by email, rarely uses the words ‘subject access request’, and rarely comes entirely out of the blue. Often, it’s from somebody who is already unhappy. An ex-employee; a customer in the middle of a complaint. Sometimes it’s from a solicitor, in which case the wording is more formal and the intent is easier to read.
However it was made, it counts. There’s no form, no required wording, and no requirement that the person knows the legal term for what they’re doing. ‘Please send me everything you hold about me’ is a valid request. So is the same sentence when it’s buried in the fourth paragraph of a complaint about a delivery.
The clock starts running as soon as they click send — not when you notice that you’re dealing with a Data Subject Access Request (DSAR).
How long you have
As a general rule, you have one month to respond to an DSAR. You can extend by up to two further months in situations where the request is complex, or where the person has made several requests, but before the origina month is up, you have to tell them that you’re extending and why, inside the original month.
You can stop the clock while you seek clarification about what they actually want, or while you satisfy yourself who they are. That ability existed in regulatory guidance for some time before the Data (Use and Access) Act 2025 wrote it into statute. Helpfully, it also confirms that the search you carry out has to be reasonable and proportionate rather than limitless.
The second half of that make a huge difference to UK SMEs. Most of the fear around these requests comes from a belief that you have to search everywhere, forever, and produce everything.
You have to search reasonably, which is a different obligation and a much more manageable one.
What you have to provide
A copy of their personal data, plus information about how you use it. The purposes, who you share it with, how long you keep it, where you got it if it didn’t come from them, and what rights they have.
Personal data goes wider than people expect. It isn’t just the record in the CRM, it’s also any emails that mention them. And yes, it includes the note a manager made, the messages in a team channel discussing them and the minutes recording a decision about them. Suffice to say, if it relates to an identifiable person it’s in scope.
It is not every document they were ever copied into. The test is whether the information relates to them, not whether their name appears in it.
What you can withhold
This is often the bit that gets handled badly. Businesses withhold too much, or they panic and disclose things they shouldn’t have, which can land them in further trouble.
- Other people’s personal data can be held back where releasing it would identify them, unless they consent or it’s reasonable to release it anyway. In practice that means redaction rather than refusal. A complaint made about the requester by a named colleague is the standard hard case, and it comes up constantly.
- Legally privileged material stays privileged. Advice from your lawyers doesn’t go in the bundle.
- Other exemptions exist, covering things like negotiations, management forecasting and crime prevention. They’re narrower than people hope.
- You can refuse outright where a request is manifestly unfounded or excessive. The bar is high (excessive is not the same as inconvenient). If you do refuse, you have to say why, and tell the requester that they can complain.
Where it goes wrong
The request itself is rarely the problem. But there are some simple ways to turn a straightforward administrative task into a dispute or an ICO complaint:
- Treating the subject access request as hostile. The instinct is to slow down, involve a solicitor and say as little as possible. The problem is that this will be obvious to the requester. Most people making these requests want to know what you have. The ones who are building a case are usually building it out of how you respond.
- Missing the start date. This is nearly always an inbox problem. Requests that get sent to a general enquiries address, or to somebody who was on annual leave, are easy ways to find yourself breaching the one-month deadline.
- Finding things nobody knew existed. A thorough search turns up the informal channels such as the WhatsApp thread where somebody was discussed candidly or the note that was never meant to be read by its subject. Nothing unlawful has necessarily happened. The relationship still doesn’t survive it.
- Over-redacting. A response containing forty pages of black boxes reads as if you have something to hide, even when every redaction is justified. Where you’ve held something back, just say what category it was, and why.
The first 48 hours after a Data Subject Access Request arrives:
- Record the date it arrived and work out the deadline.
- Satisfy yourself of who they are. Ask for identification only where you genuinely need it, because asking as a delaying tactic is obvious, and it costs you goodwill you may want later.
- Acknowledge it. A short neutral acknowledgement changes the tone of everything that follows.
- Ask what they’re looking for, if the request is broad. Most people want something specific. Asking what it is can save everyone considerable work and this is also where the clock can pause.
- Work out where the data actually is, including the informal places.
- Decide who in your team is responsible for responding to the DSAR, and give them the time to do it properly. It will take longer than you think.
