How to Respond to a UK DSAR: A Workflow for Employers and SaaS Teams
When a UK subject access request arrives, log it, establish the requester and scope, calculate the applicable deadline, search reasonably and proportionately, review third-party information and exemptions, then respond securely with a decision record.

Recognise and record the request
A person does not need to write “DSAR” or use a special form to exercise the right of access. Train support, HR and sales teams to route a request for personal information to a named owner. Record the date received, channel, requester, systems likely involved and immediate deadline calculation.
The usual UK response period is one month, subject to the rules on extensions and any permitted pause for clarification. Use the current ICO guidance to calculate a particular deadline; do not automatically pause because a request is inconvenient or broad. Ask for identity evidence only when reasonably needed and use a proportionate method.
| Request log field | Illustrative entry |
|---|---|
| Received / owner | 29 September, support inbox / privacy lead |
| Scope | Copy of account and support-ticket data |
| Deadline and basis | Calculated under current ICO guidance; review if clarification is genuinely required |
| Status | Search assigned to support, billing and product |
Plan and document a reasonable search
Map likely systems from the requester's relationship with the organisation. For an employee, this may include HR, payroll, email and relevant messaging systems. For a SaaS user, account records, support tickets, billing contacts and product logs may matter. Define search terms, custodians and date ranges, then record why they are reasonable and proportionate.
The Data (Use and Access) Act 2025 clarified the reasonable and proportionate search standard and the clarification pause. The ICO updated its guidance in July 2026. An overly narrow search can omit relevant data; an uncontrolled export can disclose other people's information.
| System | Search performed | Result / reviewer |
|---|---|---|
| Support desk | Account ID and known email aliases | 14 tickets; support lead |
| Billing | Customer ID and invoices | 3 records; finance lead |
| Product logs | User ID within retention window | Export reviewed; engineering lead |
Review third-party data and any exemptions
Read the material in context. Decide whether it is the requester's personal data, whether disclosure would reveal another person's information, and whether a specific exemption applies. Redaction is a reasoned decision, not an automatic rule for every name or entire document. Keep an internal explanation of what was withheld and why.
Illustrative decision: a support ticket names another customer and describes that customer's account issue. The reviewer may redact the unrelated customer's identifiers while disclosing the requester's own correspondence. The exact balance depends on the facts; record the reviewer's reasoning and any legal input.
Send the response and retain the decision trail
Provide the required information in a secure, accessible form and verify the recipient and delivery route. Explain any withholding, extension or refusal where applicable and preserve the request log, search log, review decisions and copy of the response. A complex case should have an owner for follow-up questions.
For organisations handling both a complaint and an access request, log both processes. A complaint acknowledgement does not replace the rights-request response.
Frequently asked questions
Can we insist on a special DSAR form?
No. A valid access request can arrive through ordinary channels. A form can help collect information but should not be a barrier to recognising the request.
Can we stop the clock while searching?
Searching alone does not pause the deadline. A clarification request can pause the UK time limit under the current rules when clarification is genuinely needed; record the dates and consult ICO guidance.
Keep researching
Related resources
A practical next step
Make the next privacy decision clearer
Bring your organisation, processing, jurisdictions, current documents, internal owners, and deadline. We can help identify the right scope before an appointment or wider workstream begins.
This guide provides general information, not legal advice or a conclusion that a particular obligation applies. Confirm the legal scope and practical next steps against your organisation's facts.
Sources: ICO: A guide to subject access, ICO: DUAA changes to data protection
