UK GDPR · Rights requests

How to Respond to a UK DSAR: A Workflow for Employers and SaaS Teams

When a UK subject access request arrives, log it, establish the requester and scope, calculate the applicable deadline, search reasonably and proportionately, review third-party information and exemptions, then respond securely with a decision record.

By The Data Protection OfficersReading time: 4 min
Original DSAR workflow illustration from request intake through search, review and secure response

Recognise and record the request

A person does not need to write “DSAR” or use a special form to exercise the right of access. Train support, HR and sales teams to route a request for personal information to a named owner. Record the date received, channel, requester, systems likely involved and immediate deadline calculation.

The usual UK response period is one month, subject to the rules on extensions and any permitted pause for clarification. Use the current ICO guidance to calculate a particular deadline; do not automatically pause because a request is inconvenient or broad. Ask for identity evidence only when reasonably needed and use a proportionate method.

Request log fieldIllustrative entry
Received / owner29 September, support inbox / privacy lead
ScopeCopy of account and support-ticket data
Deadline and basisCalculated under current ICO guidance; review if clarification is genuinely required
StatusSearch assigned to support, billing and product

Review third-party data and any exemptions

Read the material in context. Decide whether it is the requester's personal data, whether disclosure would reveal another person's information, and whether a specific exemption applies. Redaction is a reasoned decision, not an automatic rule for every name or entire document. Keep an internal explanation of what was withheld and why.

Illustrative decision: a support ticket names another customer and describes that customer's account issue. The reviewer may redact the unrelated customer's identifiers while disclosing the requester's own correspondence. The exact balance depends on the facts; record the reviewer's reasoning and any legal input.

Send the response and retain the decision trail

Provide the required information in a secure, accessible form and verify the recipient and delivery route. Explain any withholding, extension or refusal where applicable and preserve the request log, search log, review decisions and copy of the response. A complex case should have an owner for follow-up questions.

For organisations handling both a complaint and an access request, log both processes. A complaint acknowledgement does not replace the rights-request response.

Frequently asked questions

Can we insist on a special DSAR form?

No. A valid access request can arrive through ordinary channels. A form can help collect information but should not be a barrier to recognising the request.

Can we stop the clock while searching?

Searching alone does not pause the deadline. A clarification request can pause the UK time limit under the current rules when clarification is genuinely needed; record the dates and consult ICO guidance.

Keep researching

A practical next step

Make the next privacy decision clearer

Bring your organisation, processing, jurisdictions, current documents, internal owners, and deadline. We can help identify the right scope before an appointment or wider workstream begins.

This guide provides general information, not legal advice or a conclusion that a particular obligation applies. Confirm the legal scope and practical next steps against your organisation's facts.

Sources: ICO: A guide to subject access, ICO: DUAA changes to data protection

Choose the Right Data Protection Service

Compare the role and scope that fit the jurisdictions and processing activities that matter to your business.

Find the Right Data Protection Service in Minutes

Select your jurisdictions, compare annual pricing, and continue with the service that fits your scope.

View Data Protection Services