Subject Access Requests – Common Mistakes And How to Avoid Them

31st March 2025

Subject Access Requests, or SARs, are requests by individuals to organisations asking what personal data is being processed on them. Data protection laws including the Data Protection Act 2018 and the GDPR state that data subjects have the right to access their personal information. They can make this request in writing or verbally, although organisations cannot require requests to be made in writing or by using a specific form. SARs should be responded to as swiftly as possible and within one calendar month, apart from complex requests or multiple requests from the same person, in which case, another 2 calendar months can be added to the deadline. Many organisations are unclear about how to deal with SARs and can make mistakes – here are a few ways to avoid this, helping your organisation respond to SARs promptly and avoiding any potential complications.

Verify the Data Subject’s Identity

If the individual is not known to you, proportionate efforts should be taken to verify the identity of the individual making the request. You need to be satisfied that they are who they claim to be, and can take reasonable steps to verify this. You can seek proof of identity such as a photo ID or ask them questions that only the data subject would know. Disclosing personal data to the wrong person is a data breach that can have serious consequences, especially if it involves sensitive data.

Keep All Records In Order

Organisations can miss SAR deadlines simply by not having the required information to hand. Keeping accurate records and having an organised, centralised filing system means that all personal data can be found easily. This can avoid any missed deadlines, incomplete information, the disclosure of irrelevant or excessive data, and wasted employee time. You should also keep a record of all SARs and responses to demonstrate compliance with data protection laws. This should include the original request, the steps taken to fulfil the request, details of how the data was delivered to the individual, and if relevant, the reason for denying a request or extending the deadline.

Respond Within One Month

Failing to respond to a subject access request within the permitted time scale means that the individual who made the request can complain to the ICO, potentially triggering an investigation and obtaining a court order to enforce their right of access. Responding to SARs promptly and using a tracking system that sends timely reminders to the employees dealing with SARs can help organisations stay on top of SARs and avoid missing any deadlines. Even if the organisation intends to deny the SAR, they should inform the individual of this as soon as possible, providing the reason for the denial. If an individual’s request is unclear or missing essential information, requesting clarification can help to extend the time limit.

Only Disclose Relevant Data

Some organisations may inadvertently disclose irrelevant data, include more data than is necessary, or even expose the personal data of others when responding to a subject access request. To avoid this, only disclose the personal information that the data subject has requested and remove or redact any information that is irrelevant or includes the personal data of others. Read the request carefully and find out if they are looking for data relating to something specific – don’t assume they want every piece of data you have about them. It’s okay to ask if the SAR relates to a particular timeframe or instance.

Train Team Members Adequately

Make sure that all employees are trained on how to recognise and respond to a subject access request. Having a clear and well-defined process for dealing with SARs and making sure all team members are aware of this can help ensure compliance and avoid any future issues. You should regularly review your SAR process to make sure it is still compliant and that all staff members know what to do in the event of a SAR, including potential grounds for refusal or extensions on the deadline. For more information on SARs, see the ICO website.

Do you need some help creating a SAR policy or training your employees on data protection? Griffin House Consultancy can help – get in touch with us on our Contact page or call us on 01673 885533.

 

Author: Mike Martin LLM

Mike is an information governance specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details