1. Section 3: Individual rights and accountability

1.2. 3.2 Subject access requests

UK data protection learning

3.2 Subject access requests

Recognising, searching for and securely disclosing personal data.

Recognising a SAR

A SAR does not need to use legal language, cite legislation or arrive on a special form. A message such as “Please send me the notes you hold about my performance” may be a valid request.

A practical response workflow

  1. Recognise and log: record the date received and route the request promptly.
  2. Verify identity proportionately: ask only for information reasonably needed to confirm identity.
  3. Clarify where permitted and useful: clarification can help focus the request, but should not be used to create unnecessary delay.
  4. Search reasonably and proportionately: identify relevant systems, mailboxes, paper records and processors.
  5. Review: separate the requester's personal data from third-party information and consider exemptions.
  6. Respond securely: normally within one calendar month, using an appropriate delivery method.
  7. Document: retain evidence of searches, decisions, redactions and communications.
Current search standard: The organisation is expected to carry out a reasonable and proportionate search. It should be able to explain what it searched and why.

Time and extensions

The normal response period is one calendar month. In suitable cases involving complexity or multiple requests, an extension may be available, but the individual must be informed within the initial period and given reasons.

Activity: Recognise and scope a SAR

Read the request: “Send me all emails, Teams messages, notes and disciplinary documents about me from the last two years.”

  1. Which teams, systems and people may hold responsive information?
  2. What identity check, if any, is proportionate?
  3. What search terms and date ranges should be recorded?
  4. What third-party information might require review?
  5. How will the response be sent securely?
Open the answer guidance
A documented search plan may include HR systems, line-manager files, email, collaboration platforms, case-management tools and relevant processors. Identity checks should be proportionate. Third-party information must be considered carefully rather than disclosed automatically.

Official reference points

Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.