
How to respond to a Data Subject Access Request (DSAR)
A practical guide for organisations responding to a subject access request
How to respond to a Data Subject Access Request (DSAR)
Greater awareness of data protection rights means organisations are receiving more Data Subject Access Requests (DSARs). This guide explains the practical steps involved and the common problems to avoid. A request can be made verbally or in writing, including by email or social media, so staff need to recognise and route it promptly.
What is a DSAR?
A Data Subject Access Request (DSAR), also called a subject access request or SAR, is a person’s request to access their personal data under the UK GDPR. They can ask whether your organisation processes their data, obtain a copy and receive information about how you use it. A request does not need to mention the law or use a particular form. For organisations, the first step is recognising it and passing it promptly to the person responsible for responding.
2026 update — Data (Use and Access) Act 2025: The current rules expressly address reasonable and proportionate searches and pausing for clarification. They do not give organisations an automatic three months to respond or a general right to insist on a narrower request. Read what DUAA means for your DSAR procedure.
Received a DSAR? Download our practical DSAR Response Checklist
Use it to work through the request from receipt and identity checks through searches, review, redaction and secure disclosure.
DSAR response in 60 seconds
1. Log request date + confirm deadline
2. Verify ID (if needed)
3. Clarify information sought (where reasonably required)
4. Search systems + capture decisions
5. Review, redact third-party data, apply exemptions
6. Provide data + the required explanatory info
7. Send securely + document completion
What you must provide in a DSAR response
When you respond to a Data Subject Access Request, your reply needs to do more than simply send documents. In most cases you must provide:
Confirmation
- Confirm whether you process the individual’s personal data.
A copy of their personal data
- Provide the personal data you hold about them (in a commonly used electronic form where the request is made electronically, unless they ask otherwise).
- This includes personal data across systems (for example email, HR files, CRM records, Teams/Slack messages, case files, call notes and other records), not just your “main” database.
The “supporting information” (so the data makes sense)
Alongside the data itself, you must provide the required information that explains your processing, subject to any applicable exemption, including:
- Why you use their data (your purposes)
- What categories of personal data you process about them
- Who you share it with (identify specific recipients; provide categories instead where identifying them is impossible or manifestly unfounded or excessive)
- How long you keep it (retention periods or the criteria you use to decide them)
- Where you got it from (if you didn’t collect it directly from them)
- Their rights (e.g., to rectification, erasure, restriction, objection, and to complain to your organisation and the ICO)
- Information about automated decision-making, including profiling, where it applies (and meaningful information about the logic involved, plus the significance and likely consequences)
- International transfers (the appropriate safeguards where their data is or will be transferred to a third country or international organisation)
Tip: You don’t have to “write an essay” — but you do need to give enough context for the individual to understand what you hold, what you’re doing with it, and what their options are next.
Once you’ve recognised the DSAR, the first challenge is understanding what information you need to provide to the individual making the request. This will partly depend on the request itself. If the request is particularly broad, it is worth asking the individual if they can clarify the time-frame and/or the scope, but you cannot put pressure on them to do this and they do not have to.
What we see in practice
The difficult part is rarely recognising a textbook request. In our work, requests often arrive through an unexpected route—such as a personal inbox, grievance correspondence or a call—and searches begin before scope, custodians and systems are agreed. A short intake record and documented search plan help prevent delay and make the response easier to defend.
Identity checks
Only request additional identification where you have reasonable doubts about the requester’s identity, and ask for no more information than is necessary. Where identity information is reasonably required, the one-month period runs from the date you receive that information. Asking for identity evidence when identity is already clear can cause unnecessary delay.
Stopping the clock

Starting the clock
Respond without undue delay, normally within one calendar month of receipt. Count weekends and bank holidays, but move a deadline falling on either to the next working day. Where identity information is reasonably required, the period starts when it arrives.

Stopping the clock
You may pause the deadline where clarification is reasonably required to identify the information or processing activities concerned. Ask promptly, explain why, and record the date. Asking about the delivery format does not pause the clock.
You cannot force a narrower request. Supply any supporting information you can reasonably provide without clarification within the original month.

Resuming the clock
The clock resumes the day after clarification arrives. Add the paused calendar days, including the day you asked and the day the reply arrived, to the original deadline. Record the revised due date.
Example of pausing the deadline while you wait for clarification
If you ask for reasonably required clarification on 15 May and receive it on 18 May, the clock pauses for four days, including both dates. It resumes on 19 May. Add four days to the correctly calculated original deadline, applying the weekend and public-holiday rule where relevant.
Source: ICO guidance on response deadlines and clarification.
The 5 stage process
The subject access request process can be broken down into 5 key stages, as described below:
Stage 1
During the first stage, the search terms need to be established and the search conducted. Depending on the nature of the request, this may return a large volume of documents.
What we see in practice — search planning
We start by identifying where the person’s data is most likely to be held. Broad terms can return substantial irrelevant material. Testing them early helps establish the review work required and gives the team a clear basis for refining the search. Read our practical search guidance.
Stage 2
The documents returned by the search will need to be reviewed in order to establish what information needs to be provided to the individual. During the initial review round, discard anything that is out of scope, i.e. information that doesn’t contain the data of the individual either directly or indirectly. It is important to understand that the right to subject access is limited only to personal data of the requesting individual.
Stage 3
Review the material for third-party personal data and other information that may need to be redacted. Do not remove names, job titles or messages automatically: consider whether disclosure would adversely affect another person’s rights, whether consent is available and whether it is reasonable to disclose without consent. Search relevant business systems—including collaboration tools and, where justified, work-related data on personal devices—under an agreed, proportionate process. Record the reasons for material redactions.
Stage 4
Consider whether a Data Protection Act 2018 exemption applies to particular information. Exemptions are not blanket exclusions and should be used only to the extent justified by the facts. For example, the negotiations exemption in Schedule 2, Part 4, paragraph 23 may apply to a record of your intentions where disclosure would be likely to prejudice negotiations with the requester. Record the exemption relied on and the reasons for applying it, and disclose the remaining personal data.
Stage 5
Prepare a clear index and send the information securely. If you use password-protected files, send the password through a separate communication channel. For hard copies, use a suitable tracked-delivery service and assess whether splitting a large disclosure would reduce or increase risk. Keep a record of what was sent, when it was sent and how it was delivered.
What we see in practice — leave time for review
A common problem we see is a request left until the last moment. Retrieving records is only part of the work: review, exemptions, redaction and disclosure also need time. Assign responsibility and plan those stages when the request arrives.
Tip: There is no single six-year retention period for every type of record. Set and apply retention periods according to the legal, regulatory and operational need for each category of information. Consistent deletion at the end of an approved retention period reduces the amount of unnecessary material that must be reviewed during a DSAR.
AI-drafted DSARs
Some people use AI tools to draft DSARs, which can produce lengthy requests or unfamiliar terminology. The use of AI does not affect whether a request is valid. Focus on the substance of the request rather than how it was written. If the information sought is genuinely unclear and clarification is reasonably required, you may ask the requester to clarify it; follow the current rules on when the response period pauses and begin searching for information that can already be identified.
What is the two-month extension?
An organisation may extend the response period by up to a further two months where necessary if the request is complex or the person has made a number of requests. The requester must be told within the initial one-month period and given the reason for the extension. Complexity is fact-specific; a request is not complex merely because it involves a large amount of information.
Factors that may contribute to complexity include:
• Technical difficulties in retrieving the information – for example if data is electronically archived.
• Applying an exemption that involves large volumes of particularly sensitive information.
• Clarifying potential issues around disclosing information about a child to a legal guardian.
• Any specialist work involved in obtaining the information or communicating it in an intelligible form.
• Clarifying potential confidentiality issues around the disclosure of sensitive medical information to an authorised third party. Applying these exemptions would require legal advice.
Please note: The volume of information alone does not automatically make a request complex. Assess the particular circumstances and document why any extension is necessary.
What does the Data (Use and Access) Act 2025 mean for DSARs in 2026?
The Data (Use and Access) Act 2025 puts reasonable and proportionate searches on a statutory footing. Identify likely sources and document your decisions, including why you exclude a system. A requester can still ask for all their information. Our guide explains what a reasonable and proportionate search looks like.
The revised time-limit provisions apply to requests received from 5 February 2026. They expressly allow a pause where clarification is reasonably required to identify the information or processing activities concerned. They do not create the existing UK GDPR two-month extension or make three months the default response period. See the commencement and transitional rules.
From 19 June 2026, organisations must also facilitate data protection complaints. Make sure your response explains how the person can raise concerns with your organisation and complain to the ICO. Update your procedure, deadline tracker and response letters; the Act amends, rather than replaces, the UK GDPR. See the government’s explanation of the changes and current ICO subject-access guidance.
Can you refuse a DSAR?
Sometimes, but you need a specific, documented basis. A difficult request or an employment dispute is not, by itself, a reason to refuse.
Manifestly unfounded or excessive requests: You may refuse all or part, or charge a reasonable administrative fee, where this high threshold is met. Unfounded requests may involve clear evidence of an intention to harass or disrupt rather than exercise access rights. Assess excessiveness in context, including unreasonable repetition; length or volume alone is not enough. Consider each request individually and retain supporting evidence. See ICO guidance on unfounded or excessive requests.
Exemptions for particular information: These include legally privileged material, qualifying confidential references and certain negotiation records. Each has its own conditions. A document being confidential, or involving a solicitor, does not automatically justify withholding it. Apply an exemption only as far as justified and supply the remaining information.
Explain the decision: Notify the person without undue delay and within the applicable one-month period when refusing to act. Give the reasons, their rights to complain to your organisation and the ICO, and their ability to seek a court remedy. If explaining a particular exemption would undermine its purpose, give as much explanation as you lawfully can and record the full rationale internally. See ICO guidance on exemptions and refusal.
DSAR FAQs for organisations
How long do we have to respond?
Respond without undue delay, normally within one calendar month. If the corresponding date does not exist next month, use that month’s final day. Move a deadline falling on a weekend or public holiday to the next working day. See the deadline and pausing rules above.
When can we take a further two months?
Where necessary because the request is complex or the same person has made a number of rights requests. Explain the extension and its reasons within the initial month. Workload or a large disclosure does not automatically justify it. See the two-month extension section.
Can we ask for clarification and pause the deadline?
Yes, where clarification is reasonably required to identify the information sought. The pause includes the day you ask and the day their reply arrives; the clock resumes the following day. You cannot force a narrower request. Supporting information you can reasonably provide without clarification remains due within the original month.
What must our response include?
Confirmation about processing, a copy of the person’s data and the required supporting information, subject to applicable exemptions. Use the detailed list above to check purposes, recipients, retention, rights, complaint routes and other required information rather than sending documents alone.
Must we supply whole documents or every email?
The right is to the person’s personal data, not automatically every document in which their name appears. An extract may be appropriate, but include the data they are entitled to and enough context to understand it. A redacted document or explanatory cover note may be clearer. See ICO guidance on supplying information.
Can we redact other people’s information?
Assess it before disclosure. Consider consent and whether it is reasonable to disclose without consent; do not automatically remove every colleague’s name. Record material redaction decisions and check the final files to ensure concealed text cannot be recovered. See Stage 3 above.
Can we refuse a request made during a grievance or legal claim?
Not simply because there is a dispute. Assess any refusal against the unfounded or excessive threshold, or the conditions of a relevant exemption. Record your decision and explain the complaint routes. See when you can refuse a DSAR.
Do we have to search email, Teams and WhatsApp?
Include relevant business communications in a reasonable and proportionate search. Work-related information on private devices or messaging accounts may be in scope where held on your organisation’s behalf. If you have good reason to think staff hold relevant data there, arrange appropriate searches while protecting unrelated private information. Read our search guidance.
How should we send the response securely?
Use a method suited to the sensitivity and volume, such as a secure portal or suitably encrypted files. Verify the recipient and access permissions, send passwords through a separate channel, and check the person can open the material. Record what was disclosed and when.
What should we change following DUAA?
Update your procedure, deadline tracker and response letters for clarification, documented proportionate searches and complaints handling. Keep the ordinary one-month deadline as the starting point. The Act has not replaced the UK GDPR. See the 2026 DUAA update.
For the legal detail behind these answers, see the ICO guidance on deadlines and clarification, supplying information and subject access for organisations.
Need help responding to a DSAR?
Our DSAR Response Service supports organisations with searches, review, exemptions, redaction and the final response.
Learn more about our DSAR Response Service →
Explore More Data Protection & Privacy Services
Our team have a deep understanding of the following areas of law and continue to add value to our clients’ businesses.
Latest Insights
- The GDPR Accountability Principle: From Paper to PracticeAccountability principle As a new consultant at Westbrook Data Protection Services, one of the first […]
- Changes to employment law and the rise in Data Subject Access RequestsChanges to employment law and the rise in Data Subject Access Requests Employment Rights Act […]


