A subject access request asks for the person's personal information and related information about its use. It need not use a particular form or legal phrase. Recognise the request, record when it arrived and assess the response timetable under the current ICO guidance.
The usual response period is one month, with rules for circumstances such as necessary identity checks, clarification or permitted extensions. Plan a reasonable and proportionate search and document the approach. Review third party information and any applicable exemption before sending the response, rather than exporting an entire mailbox without assessment.
Recognise and route the request promptly
Train staff to recognise ordinary language asking for personal information. A request might reach a branch manager, an old account mailbox or a social media team. Log the receipt date and preserve the original wording. Avoid requiring the person to repeat a valid request through a preferred form merely because the business finds that route easier to administer.
Identify a case owner and a deputy immediately. Set a working timetable that leaves room for searches, review and secure delivery. The current ICO guide explains the usual one-month limit and the circumstances affecting calculation, clarification and extensions. [1] Do not assume every broad request permits a pause or an extra two months. Record the particular reason for any adjustment and communicate it as required.
Scope searches without narrowing the right unfairly
Ask which identifiers will find the relevant records: account numbers, former email addresses, names and dates of dealings may all help. Proportionate identity checks should respond to the risk of disclosing information to the wrong person. If the person is already authenticated in a suitable account, demanding extensive additional documents may be unnecessary. Representatives also need appropriate authority, but do not confuse verification with an opportunity to obstruct the request.
Plan searches across the systems likely to contain relevant personal information. Include archived case notes and relevant staff communications where appropriate, rather than searching only the customer database. The current framework refers to reasonable and proportionate searches. Keep a search log explaining locations, terms and decisions so that a missing result can be investigated without starting again from memory.
Review the material before disclosure
The right concerns personal information and associated information about its processing; it is not automatically a right to every complete document mentioning the requester. Review context, third-party information and any properly applicable exemptions. Avoid blanket redactions based only on document labels. Where specialist advice is needed, send the reviewer a focused issue list and the relevant passages rather than an unexplained bulk archive.
Keep an unaltered working copy and a separate disclosure copy. Test that redacted information cannot be recovered through hidden text, comments or attachments. Check spreadsheets for extra tabs and email exports for unrelated messages. Record decisions sufficiently to explain the response later, while restricting access to the request file because it can concentrate a large amount of personal information in one place.
Deliver a usable response and close the case
Choose a secure delivery method proportionate to the content and the person's circumstances. Explain the scope, provide the required supplementary information and make the material intelligible. Confirm the destination carefully; a correct search followed by an incorrect recipient creates a new incident. Keep evidence of dispatch and a route for questions about missing or unclear information.
Use Access controls for client records to improve permissions for request work and Creating a personal data retention schedule to determine retention of the resulting case file. For support through Business privacy notice review, provide the request, chronology, proposed deadline and search plan. Identify urgent decisions at the outset. A lawyer reviewing exemptions cannot compensate for a team that has not established where records are held or who must produce them.
Manage a correction after dispatch
A requester may identify a missing account or explain that an exported code is unintelligible. Treat the follow-up as an issue to investigate, preserving the original response and the new information. Check whether a search term was omitted, a system was unavailable or the response needs a clearer explanation. Do not quietly replace the disclosure file and lose the history of what was provided.
Use a short correction log showing the issue, investigation and supplementary response. Where the follow-up reveals a wider search weakness, update the search instructions for future cases. Keep any dispute about the business relationship separate from the handling of the information request; staff should not let an unpaid invoice or an ongoing complaint distract them from assessing the person's data protection rights.
Illustrative scenario
A former customer emails a sales manager asking for the information held about them. The manager forwards it through the internal request process immediately. The team identifies relevant systems, checks identity proportionately and reviews the material for other people's information before providing a secure response within the assessed timetable.
Preparation checklist
- Record receipt, scope and the responsible person.
- Check identity without collecting unnecessary documents.
- Log searches, decisions and any deadline adjustment.
- Review the response and deliver it securely.
Frequently asked questions
Must a person mention UK GDPR?
No. Staff should recognise a request for the person's information from its substance. Record and route it even when it arrives informally or through an ordinary customer contact.
Can we always extend a difficult request?
Extensions and timetable adjustments have specific conditions. Apply the current ICO guidance to the actual facts, document the reason and communicate appropriately rather than treating workload as automatic justification.
Should we send an entire staff mailbox?
No automatic bulk disclosure is appropriate. Search for relevant information, assess context and third-party material, and prepare a reviewed response using a secure delivery method.
What evidence should the request file contain?
Keep the original request, identity or authority checks, deadline reasoning, search log, review decisions and dispatch record. Limit access and apply an appropriate retention decision to that file.
Official sources
Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.
General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.
Report a correction