Subject Access Requests: A Practical Guide for UK Businesses
It usually arrives as a short, polite email: “Please send me all the personal data you hold about me.” That single sentence is a subject access request, one of the strongest rights people have under UK data protection law, and the moment it lands a one-month clock starts ticking. Mishandling these requests is one of the most common ways ordinary businesses end up in a complaint to the Information Commissioner’s Office. The good news is that a subject access request is very manageable once you know the rules.
What a subject access request actually is
Anyone whose personal data you hold can ask for a copy of it, along with an explanation of why you have it, who you have shared it with, and how long you will keep it. It is not just customers. Current staff, former staff, suppliers and members of the public can all make a request, and they do not have to use any special wording or even the phrase “subject access request”. An email, a letter, even a verbal request all count.
The rules you need to know
- One month to respond. The clock starts when you receive the request and, if needed, confirm the person’s identity. For complex or numerous requests you can extend by up to two further months, but you must tell the person within the first month.
- Usually free. You cannot charge in most cases. You can only refuse, or charge, for requests that are manifestly unfounded or excessive, and you need to be able to justify that.
- Verify identity first. Make sure the person is who they say they are before you hand over any data, but do not use identity checks as a delaying tactic.
- Provide it in an accessible format. If the request comes in by email, an electronic copy is usually expected.
The tricky parts
Two things catch businesses out. The first is other people’s data. A request often pulls up information that also identifies someone else, in an email thread for example, and you generally need to redact or remove those third parties before you disclose. The second is scope. “All my data” can mean emails, your CRM, HR files, call recordings, CCTV and more, and personal data has a habit of hiding in places you forget. There are also some exemptions, such as legal advice, but they are narrower than people assume, so it is wise to check rather than rely on them.
How to be ready, not caught out
The businesses that handle these calmly are the ones that prepared before a request ever arrived. That means:
- Knowing where personal data actually lives across your systems, from Microsoft 365 and your CRM to shared drives and CCTV.
- Having one named person who owns the process.
- A simple, written procedure so nobody has to invent it under time pressure.
- Good data hygiene, so you are not searching years of clutter every time.
Well-organised, secure systems make the difference between a request being a ten-minute job and a stressful week. If you have registered with the ICO, and if you process personal data you almost certainly need to, as our ICO registration guide explains, handling access requests properly is the natural next step.
In short
A subject access request is not something to fear. Know the one-month deadline, verify who you are dealing with, watch out for other people’s data, and keep your own data well organised so you can actually find things. If you would like help getting your systems and data in order so requests are easy to answer, get in touch.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


