
How to respond to a Data Subject Access Request (DSAR)
A practical guide for organisations responding to a subject access request
How to respond to a Data Subject Access Request (DSAR)
Greater awareness of data protection rights means organisations are receiving more Data Subject Access Requests (DSARs). This guide explains the practical steps involved and the common problems to avoid. A request can be made verbally or in writing, including by email or social media, so staff need to recognise and route it promptly.
Received a DSAR? Download our practical DSAR Response Checklist
Use it to work through the request from receipt and identity checks through searches, review, redaction and secure disclosure.
DSAR response in 60 seconds
1. Log request date + confirm deadline
2. Verify ID (if needed)
3. Clarify scope (only if genuinely unclear)
4. Search systems + capture decisions
5. Review, redact third-party data, apply exemptions
6. Provide data + the required explanatory info
7. Send securely + document completion
What you must provide in a DSAR response
When you respond to a Data Subject Access Request, your reply needs to do more than simply send documents. In most cases you must provide:
Confirmation
- Confirm whether you process the individual’s personal data.
A copy of their personal data
- Provide the personal data you hold about them (in a commonly used electronic form where the request is made electronically, unless they ask otherwise).
- This includes personal data across systems (for example email, HR files, CRM records, Teams/Slack messages, case files, call notes and other records), not just your “main” database.
The “supporting information” (so the data makes sense)
Alongside the data itself, you should provide the key information that explains your processing, including:
- Why you use their data (your purposes)
- What categories of personal data you process about them
- Who you share it with (recipients / categories of recipients)
- How long you keep it (retention periods or the criteria you use to decide them)
- Where you got it from (if you didn’t collect it directly from them)
- Their rights (e.g., to rectification, erasure, restriction, objection, and to complain to the ICO)
- Information about automated decision-making, including profiling, where it applies (and meaningful information about the logic involved, plus the significance and likely consequences)
Tip: You don’t have to “write an essay” — but you do need to give enough context for the individual to understand what you hold, what you’re doing with it, and what their options are next.
Once you’ve recognised the DSAR, the first challenge is understanding what information you need to provide to the individual making the request. This will partly depend on the request itself. If the request is particularly broad, it is worth asking the individual if they can clarify the time-frame and/or the scope, but you cannot put pressure on them to do this and they do not have to.
What we see in practice
The difficult part is rarely recognising a textbook request. In our work, requests often arrive through an unexpected route—such as a personal inbox, grievance correspondence or a call—and searches begin before scope, custodians and systems are agreed. A short intake record and documented search plan help prevent delay and make the response easier to defend.
Identity checks
Only request additional identification where you have reasonable doubts about the requester’s identity, and ask for no more information than is necessary. Where identity information is reasonably required, the one-month period runs from the date you receive that information. Asking for identity evidence when identity is already clear can cause unnecessary delay.
Stopping the clock

Starting the clock
When an individual makes a request organisations have one calendar month to respond. This includes bank holidays and weekends.

Stopping the clock
If you genuinely need to verify someone’s identity or you need clarification because the request is unclear, you can pause the deadline while you wait for the information you’ve reasonably asked for.
You should not use this to delay responding where the request is already clear.

Resuming the clock
Once you have the relevant information you should make a note of the date you received this and revise your timeframe. So if it took the individual 5 days to respond you can add this onto the clock.
Example of pausing the deadline while you wait for clarification
If you receive a DSAR on 14 May, the one-month deadline starts the same day. This means you should respond by 14 June. If you ask the individual for clarification on 15 May (because the request is genuinely unclear), the deadline is paused from 15 May until the date the individual responds. If the individual provides clarification on 18 May, the deadline starts running again from 18 May. Because the deadline was paused for three days (15–18 May), you can extend the original one-month deadline by three days. You should therefore respond by 17 June.
Source: ICO guidance on responding to a right of access request.
The 5 stage process
The subject access request process can be broken down into 5 key stages, as described below:
Stage 1
During the first stage, the search terms need to be established and the search conducted. Depending on the nature of the request, this may return a large volume of documents.
Stage 2
The documents returned by the search will need to be reviewed in order to establish what information needs to be provided to the individual. During the initial review round, discard anything that is out of scope, i.e. information that doesn’t contain the data of the individual either directly or indirectly. It is important to understand that the right to subject access is limited only to personal data of the requesting individual.
Stage 3
Review the material for third-party personal data and other information that may need to be redacted. Do not remove names, job titles or messages automatically: consider whether disclosure would adversely affect another person’s rights, whether consent is available and whether it is reasonable to disclose without consent. Search relevant business systems—including collaboration tools and, where justified, work-related data on personal devices—under an agreed, proportionate process. Record the reasons for material redactions.
Stage 4
Consider whether a Data Protection Act 2018 exemption applies to particular information. Exemptions are not blanket exclusions and should be used only to the extent justified by the facts. For example, the negotiations exemption in Schedule 2, Part 4, paragraph 23 may apply to a record of your intentions where disclosure would be likely to prejudice negotiations with the requester. Record the exemption relied on and the reasons for applying it, and disclose the remaining personal data.
Stage 5
Prepare a clear index and send the information securely. If you use password-protected files, send the password through a separate communication channel. For hard copies, use a suitable tracked-delivery service and assess whether splitting a large disclosure would reduce or increase risk. Keep a record of what was sent, when it was sent and how it was delivered.
Tip: There is no single six-year retention period for every type of record. Set and apply retention periods according to the legal, regulatory and operational need for each category of information. Consistent deletion at the end of an approved retention period reduces the amount of unnecessary material that must be reviewed during a DSAR.
AI-drafted DSARs
Some people use AI tools to draft DSARs, which can produce lengthy requests or unfamiliar terminology. The use of AI does not affect whether a request is valid. Focus on the substance of the request rather than how it was written. If the information sought is genuinely unclear and clarification is reasonably required, you may ask the requester to clarify it; follow the current rules on when the response period pauses and begin searching for information that can already be identified.
What is the two-month extension?
An organisation may extend the response period by up to a further two months where necessary if the request is complex or the person has made a number of requests. The requester must be told within the initial one-month period and given the reason for the extension. Complexity is fact-specific; a request is not complex merely because it involves a large amount of information.
Factors that may contribute to complexity include:
• Technical difficulties in retrieving the information – for example if data is electronically archived.
• Applying an exemption that involves large volumes of particularly sensitive information.
• Clarifying potential issues around disclosing information about a child to a legal guardian.
• Any specialist work involved in obtaining the information or communicating it in an intelligible form.
• Clarifying potential confidentiality issues around the disclosure of sensitive medical information to an authorised third party. Applying these exemptions would require legal advice.
Please note: The volume of information alone does not automatically make a request complex. Assess the particular circumstances and document why any extension is necessary.
What does the UK Data (Use and Access) Act 2025 mean for DSARs?
The Data (Use and Access) Act 2025 places the requirement to conduct a reasonable and proportionate search on a statutory footing. This does not mean a requester must always narrow a valid request. The organisation should identify the systems most likely to contain the requested personal data, carry out proportionate searches and document its decisions.
The Act did not create the existing additional two-month extension for complex or multiple requests. That extension continues to apply where it is necessary, and the requester must be informed within the initial one-month period. The Act also introduced updated rules on clarification and pausing the response period. Check the current ICO subject-access guidance before relying on an extension or pause.
Need help responding to a DSAR?
Our DSAR Response Service supports organisations with searches, review, exemptions, redaction and the final response.
Learn more about our DSAR Response Service →
Explore More Data Protection & Privacy Services
Our team have a deep understanding of the following areas of law and continue to add value to our clients’ businesses.
Latest Insights
- The GDPR Accountability Principle: From Paper to PracticeAccountability principle As a new consultant at Westbrook Data Protection Services, one of the first […]
- Changes to employment law and the rise in Data Subject Access RequestsChanges to employment law and the rise in Data Subject Access Requests Employment Rights Act […]


