You have received a data subject access request
When someone asks for their personal data, your response deadline starts immediately. You have one calendar month from receipt to respond - not from when you start processing it.
Getting this wrong exposes you to ICO enforcement. Breach of data subject rights falls under the higher tier of UK GDPR fines (up to 17.5 million pounds or 4% of turnover).
What counts as a DSAR
A DSAR does not need specific wording. Any clear request for personal data counts:
- "I want to see my data"
- "What do you have on me?"
- "Send me everything you hold about me"
The person does not need to mention "DSAR", "subject access request", "Article 15", or "UK GDPR". Written requests (email, letter, social media) and verbal requests (phone, face-to-face) all count. Train your staff to recognise these.
Verify identity proportionately
Before releasing data, you must confirm the request is genuine. But do not over-verify - match your checks to the sensitivity of the data:
- Low-risk data: Request from email already on file may be sufficient
- Medium-risk: Ask them to confirm details only they would know
- High-risk (sensitive data): May request photo ID - but keep it proportionate
Asking for certified passport copies to confirm a mailing list address would be excessive. Releasing data to the wrong person is itself a data breach.
Search for the data
Conduct a reasonable and proportionate search across all systems where their data might exist:
- Databases, CRM systems, business applications
- Email accounts and archives
- Paper files and physical records
- Backup systems
- CCTV footage, call recordings
- HR records, finance systems
You do not need to search every location exhaustively, but you must make genuine efforts. The Data (Use and Access) Act 2025 clarifies that "reasonable and proportionate" is the standard.
What you must provide
A DSAR response must include both the personal data and information about how you process it.
Specifically, you must tell them:
- Why you are processing their data (purposes)
- What types of data you hold (categories)
- Who you have shared or will share it with (recipients)
- How long you keep it (retention periods)
- Where it came from if not collected from them directly
- Any automated decision-making affecting them
Provide the data in a commonly-used electronic format (PDF, CSV) if the request was made electronically.
When you can redact information
You can withhold some information, but exemptions apply to specific pieces of data - not whole documents. Redact the exempt parts and provide the rest.
- Third party data: Redact other people's personal data unless they consent
- Legal professional privilege: Confidential lawyer-client communications
- Confidential references: References you have given (not received)
- Crime prevention: If disclosure would prejudice crime detection
Document your reasoning for each exemption applied. If you withhold anything, explain why to the individual.
Full DSAR response guidance
Detailed exemptions, redaction rules, third-party requests, and the 'stop the clock' provision from DUAA 2025.
Respond and keep records
DSARs are free in most cases. You can only charge a reasonable fee if the request is manifestly unfounded or excessive - a high bar to prove.
Understand data protection obligations
Broader context on UK GDPR compliance, ICO registration, and ongoing data protection requirements.
Keep records of:
- When the request was received (date starts the clock)
- What searches you conducted
- What you provided
- Any exemptions applied and why
- When and how you responded
This demonstrates accountability if the ICO investigates.
If you cannot meet the deadline
For complex or multiple requests, you can extend by a further two months (three months total). But you must:
- Tell the individual within the first month
- Explain why the extension is needed
You cannot simply ignore the deadline and explain later. The notification must happen within the original one-month period.
When you can refuse
You can refuse if the request is manifestly unfounded or excessive. This is a high bar:
- Manifestly unfounded: The person clearly has no intention to exercise their rights - making threats or demands unrelated to data access
- Excessive: Repetitive identical requests without good reason
A large request for substantial data is not automatically excessive. You must demonstrate why refusal is justified, and you must still inform them of their right to complain to the ICO.