Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

How to Handle a Subject Access Request (SAR)

In short

Anyone whose personal data you hold can ask for a copy of it — that's a subject access request, or SAR. You usually have one calendar month to respond, and you normally cannot charge. Most SARs are straightforward if you stay calm, verify who is asking, search properly, and redact other people's information. This article walks you through it.

What a subject access request actually is

A subject access request — a SAR — is simply someone asking you for a copy of the personal data you hold about them. It is one of the core rights people have under UK GDPR, and anyone can use it: a customer, a former employee, a job applicant, a supplier contact, even someone who only made an enquiry.

The part that catches businesses out is how informal a SAR can be. A SAR does not have to mention GDPR, use the words “subject access request”, or come through any particular channel. An email saying “please send me everything you hold about me” counts. So can a message on social media, a letter, or a request made verbally in a meeting. That is why everyone on your team needs to be able to recognise one and pass it to the right person quickly — the clock starts whether or not you spot it.

The one-month deadline

You normally have one calendar month to respond, starting from the day you receive the request (or from the day you receive whatever you need to verify the person’s identity). “One calendar month” means, for example, a request received on 3 March is due by 3 April.

If a request is genuinely complex, or the person has made several requests, you can extend by up to a further two months. But you must tell them within the first month that you are extending and why. You cannot quietly let the deadline slide.

The most damaging mistake is spending two of your four weeks deciding whether the request is “really” a SAR. Treat the clock as running from day one and get moving.

Step by step: how to respond

1. Log it and start the clock

Record the date received and diary the deadline. Note who is dealing with it. A simple shared log prevents SARs falling between two people.

2. Verify who is asking

You are entitled to confirm the requester’s identity before releasing anything — and you should, because handing personal data to the wrong person is itself a breach. Ask for reasonable proof, but do not use verification as a delaying tactic or demand excessive documents. If someone is asking on another person’s behalf (a solicitor, a family member), check they have authority to do so.

3. Work out the scope

People can ask for everything, or narrow it (“just my emails from this year”). If a request is very broad, you can ask them to clarify what they are looking for — which can also pause the clock while you wait for a reply. Be helpful, not obstructive.

4. Search properly

This is where most of the real work is. Personal data can be almost anywhere: your CRM, email inboxes and sent items, shared drives, accounting software, HR files, WhatsApp or Teams messages, handwritten notes, and backups. Search by name, email address, account number and any other identifiers. Keep a note of where you searched so you can show your work later.

5. Review and redact

Go through what you have found and remove other people’s personal data unless there is good reason to disclose it. Redaction — blacking out or removing third-party details — is one of the easiest places to slip up, so take your time. Apply any genuine exemptions (such as certain legal advice) narrowly, and record what you withheld and why.

6. Respond clearly

Provide the data in a commonly used, accessible format — usually a secure PDF or document pack. Include the supporting information people are entitled to: your purposes for processing, who you share data with, how long you keep it, and their other rights. If you are relying on any exemption, say so. Send it securely — never as an unprotected attachment to an unverified address.

Common mistakes to avoid

  • Missing the deadline because no one logged the request. A shared inbox rule and a simple log fixes this.
  • Charging a fee by default. SARs are free unless the request is manifestly unfounded or excessive, or someone wants extra copies. Those exceptions are narrow.
  • Refusing because of the person’s motive. A SAR made during a dispute or grievance is still valid. Motive rarely lets you off the hook.
  • Over-redacting or under-redacting. Withholding the requester’s own data is wrong; disclosing other people’s data is also wrong. Aim for the line between the two and document your reasoning.
  • Forgetting the awkward places. Backups, personal-feeling notes, and messaging apps all count if they contain personal data.
  • Sending the response insecurely, which turns a routine SAR into a data breach.

Reduce the pain before it starts

SARs are far easier to handle when your data is tidy. If you know what you hold, where it lives and how long you keep it — the sort of picture a Record of Processing Activities gives you — a SAR becomes a search task rather than a scramble. Good records retention (deleting what you no longer need) also means less to trawl through.

Strong access controls help too: the same multi-factor authentication and account hygiene that protect you from attackers also make it easier to verify identities and keep data where you expect it.

When to get help

Most SARs are manageable in-house. A few — large volumes, live disputes, tangled email histories, or requests touching sensitive data — are worth a steadier hand. As a managed IT and cyber-security provider in Leeds and Yorkshire, DACROS can help you search across your systems thoroughly, respond securely, and put simple processes in place so the next SAR is routine.

If a request has landed and you are not sure where to start, get in touch — we will keep it calm and plain-English. You can also see how we support regulated firms on our pages for accountants and solicitors.

Frequently asked questions

How long do we have to respond to a SAR?

Usually one calendar month from the day you receive the request (or from when you receive the information needed to verify the requester's identity). For complex requests, or where someone has made several requests, you can extend by up to a further two months — but you must tell the person within the first month that you are extending, and why. Do not let the clock run down while you decide whether it is genuine.

Can we charge a fee for a SAR?

Normally no. You must provide the information free of charge. You can only charge a 'reasonable fee' based on administrative costs if the request is manifestly unfounded or excessive, or if someone asks for further copies of the same data. These exceptions are narrow, so treat 'free of charge' as the default rather than looking for a reason to bill.

What if the information includes details about other people?

You must still respond, but you should not disclose other people's personal data without good reason. The usual approach is to redact (black out or remove) third-party information — other customers' details, colleagues' names where not appropriate to share — while still giving the requester their own data. Redaction is one of the most common places SARs go wrong, so take care and keep a note of what you withheld and why.

Someone made a SAR just to be difficult during a dispute. Do we still have to comply?

Almost always, yes. The person's motive generally does not remove their right of access, even during a complaint, grievance or legal dispute. You can refuse or charge only in genuinely narrow circumstances (manifestly unfounded or excessive requests), and you must be able to justify that decision. When in doubt, respond properly — refusing a valid SAR is far riskier than the effort of answering it.

Can we refuse to hand over emails or internal notes?

Emails and notes that contain the person's personal data are generally in scope — the format does not matter. Some specific exemptions exist (for example certain legal advice, or information that would reveal a third party). But you cannot withhold data simply because it is inconvenient or unflattering. If a genuine exemption applies, apply it narrowly and record your reasoning.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.