Guide · Data & Privacy

Subject Access Requests

How to ask for your personal data, what a SAR covers and how organisations should recognise one.

A Subject Access Request gives you access to your personal data and information about how it is being used.

A Subject Access Request (SAR, sometimes called a DSAR) is the exercise of the right of access. It can be made verbally or in writing and does not require special wording, a form or the phrase “Article 15”. The organisation must recognise the substance of the request.

A SAR is not limited to a customer-service account printout. Depending on what the organisation holds, personal data can appear in emails, CRM notes, complaint files, call recordings, chat logs, CCTV, internal messages, account history, audit logs and other systems. The organisation must make a reasonable and proportionate search.

Key points

  • The standard response period is one calendar month, subject to current rules on ID, clarification and valid extensions.
  • The right covers personal data, not necessarily whole documents as documents.
  • The response should also include supplementary information such as purposes, recipients/categories, retention information and source where applicable.
  • Third-party rights and statutory exemptions can justify redaction or withholding of some information.
  • A weak or incomplete response can be challenged before going to the ICO.

What are you actually entitled to?

You are entitled to confirmation whether your personal data is being processed, access to that personal data, and specified contextual information about the processing. If an email contains one paragraph about you and ten paragraphs about someone else, the right focuses on the personal data relating to you; the organisation may redact or extract where necessary.

What should the organisation search?

Current ICO guidance requires a reasonable and proportionate search. That still means reasonable efforts to locate relevant personal data across likely systems. An organisation can consider the volume and difficulty of searching, but it must be able to justify why a search would be unreasonable or disproportionate. It should not simply search one convenient database if other obvious repositories are likely to contain relevant data.

Email and internal records

Emails are not automatically disclosable in full simply because your name appears in them, but personal data about you within them can fall within the SAR. Search terms, custodians, date ranges and system locations can therefore become important in an incomplete-response dispute.

Format and security

If you make the request electronically, the response will normally be supplied in a commonly used electronic format unless you ask otherwise. The organisation should provide the information securely and in a form that is intelligible and accessible.

In practice

  • Define the categories that matter to you without unnecessarily narrowing away relevant data.
  • Include useful identifiers, account numbers, old email addresses or date ranges if they genuinely help locate your data.
  • Keep proof of the request and every later ID/clarification exchange.
  • When reviewing the response, compare it against known events and records rather than only counting pages.

Evidence worth keeping

Original SAR and the date it was sent
Acknowledgement and any ID request
Any clarification request and your reply
Extension notice and reasons if used
Disclosure files and covering letter
Earlier records showing information existed if you later dispute completeness