
Checklist for responding to a subject access request
- At-a-glance checklist
- Clear and easy to understand
- Helps you comply with your UK GDPR obligations
This checklist for responding to a subject access request provides a clear summary of the steps you should take when you receive a subject access request from an individual whose personal data you hold.
A subject access request includes a request to confirm whether you hold any of the individual’s personal data, what you are doing with it and why. It can also be a request to provide that individual with a copy of the the personal data that you have about them.
Ignoring a subject access request or failing to respond properly can lead to sanctions from the Information Commissioner’s Office, and, in the worst case, to fines.
Q&A
When should I use this document?
Use this document when you receive a subject access request from an individual whose personal data you hold.
What does this document cover?
This checklist gives a summary of the steps that you should take when responding to a subject access request, including:
- identifying the scope of the request, and asking for clarification if necessary;
- calculating the deadline for a full response; and
- identifying any exemptions that mean that you do not have disclose the information in question.
This checklist also provides links to template letters, which are useful when you are drafting your response to the request.
Why do I need this document?
You usually have one month to respond to a subject access request from an individual. If you ignore a subject access request or if you not reply adequately, this can lead to sanctions from the Information Commissioner’s Office and, in the most serious cases, to significant fines.
This checklist will help you in complying with your data protection obligations when someone sends you a subject access request.
Where can I find out more?
For further detailed guidance on identifying and responding to a subject access request, see Subject access requests.
Related Toolkits
Data breach toolkit
Personal data breach policy
Template personal data breach register
Notice of a personal data breach (affected individuals)
- How-to guide: Data breach toolkit
Data protection policy toolkit
- How-to guide: Data protection policy toolkit
Privacy policy
Cookie policy
Data protection policy
Staff privacy notice
Staff recruitment privacy notice
Data subject request policy
Data protection impact assessment policy
Personal data breach policy
Data subject request toolkit
- How-to guide: Data subject request toolkit
Data subject request policy
Subject access request form
Data transfer request form
Request form to correct inaccurate or incomplete data
Request form to delete data
Request form to stop using data
Letter acknowledging receipt of data subject request (and requesting verification of ID)
Letter asking for further information about a data subject request
Letter confirming no data held in response to data subject request
Letter explaining reasons for extension of time to respond to data subject requests
Letter to third party seeking consent to disclosure of information
Subject access request response template
Letter confirming that data processing has ceased
Letter explaining why data processing will continue
Letter confirming that data has been corrected
Letter explaining why data will not be corrected
Letter to party who has been supplied with data to confirm its correction
Letter confirming that data has been deleted
Letter explaining why data will not be deleted
Letter to party who has been supplied data to confirm its deletion
Letter supplying data in response to a portability request
Letter supplying data to a third party in response to a portability request
Small claims toolkit
- How-to guide: Small claims toolkit
Letter before action
Witness statement
Letter of non-attendance for small claims hearing