Journey

Handle a data subject access request

Respond correctly to a data subject access request within the one-month deadline. Covers identity verification, data searches, exemptions, extensions, and record-keeping.

Running a Business Updated 15 September 2026
references 2 guides

You have received a data subject access request

When someone asks for their personal data, your response deadline starts immediately. You have one calendar month from receipt to respond - not from when you start processing it.

Getting this wrong exposes you to ICO enforcement. Breach of data subject rights falls under the higher tier of UK GDPR fines (up to 17.5 million pounds or 4% of turnover).

What counts as a DSAR

A DSAR does not need specific wording. Any clear request for personal data counts:

  • "I want to see my data"
  • "What do you have on me?"
  • "Send me everything you hold about me"

The person does not need to mention "DSAR", "subject access request", "Article 15", or "UK GDPR". Written requests (email, letter, social media) and verbal requests (phone, face-to-face) all count. Train your staff to recognise these.

Verify identity proportionately

Before releasing data, you must confirm the request is genuine. But do not over-verify - match your checks to the sensitivity of the data:

  • Low-risk data: Request from email already on file may be sufficient
  • Medium-risk: Ask them to confirm details only they would know
  • High-risk (sensitive data): May request photo ID - but keep it proportionate

Asking for certified passport copies to confirm a mailing list address would be excessive. Releasing data to the wrong person is itself a data breach.

Search for the data

Conduct a reasonable and proportionate search across all systems where their data might exist:

  • Databases, CRM systems, business applications
  • Email accounts and archives
  • Paper files and physical records
  • Backup systems
  • CCTV footage, call recordings
  • HR records, finance systems

You do not need to search every location exhaustively, but you must make genuine efforts. The Data (Use and Access) Act 2025 clarifies that "reasonable and proportionate" is the standard.

What you must provide

A DSAR response must include both the personal data and information about how you process it.

Specifically, you must tell them:

  • Why you are processing their data (purposes)
  • What types of data you hold (categories)
  • Who you have shared or will share it with (recipients)
  • How long you keep it (retention periods)
  • Where it came from if not collected from them directly
  • Any automated decision-making affecting them

Provide the data in a commonly-used electronic format (PDF, CSV) if the request was made electronically.

When you can redact information

You can withhold some information, but exemptions apply to specific pieces of data - not whole documents. Redact the exempt parts and provide the rest.

  • Third party data: Redact other people's personal data unless they consent
  • Legal professional privilege: Confidential lawyer-client communications
  • Confidential references: References you have given (not received)
  • Crime prevention: If disclosure would prejudice crime detection

Document your reasoning for each exemption applied. If you withhold anything, explain why to the individual.

Full DSAR response guidance

Detailed exemptions, redaction rules, third-party requests, and the 'stop the clock' provision from DUAA 2025.

Respond and keep records

DSARs are free in most cases. You can only charge a reasonable fee if the request is manifestly unfounded or excessive - a high bar to prove.

Understand data protection obligations

Broader context on UK GDPR compliance, ICO registration, and ongoing data protection requirements.

Keep records of:

  • When the request was received (date starts the clock)
  • What searches you conducted
  • What you provided
  • Any exemptions applied and why
  • When and how you responded

This demonstrates accountability if the ICO investigates.

If you cannot meet the deadline

For complex or multiple requests, you can extend by a further two months (three months total). But you must:

  • Tell the individual within the first month
  • Explain why the extension is needed

You cannot simply ignore the deadline and explain later. The notification must happen within the original one-month period.

When you can refuse

You can refuse if the request is manifestly unfounded or excessive. This is a high bar:

  • Manifestly unfounded: The person clearly has no intention to exercise their rights - making threats or demands unrelated to data access
  • Excessive: Repetitive identical requests without good reason

A large request for substantial data is not automatically excessive. You must demonstrate why refusal is justified, and you must still inform them of their right to complain to the ICO.