Practical data rights guide
A Subject Access Request is one of the simplest ways to find out what personal data an organisation holds about you. It is also one of the easiest rights to weaken in practice if the request is vague, the response is incomplete, or the follow-up is unfocused. This guide explains how to make a clearer SAR, how to check the response, and how to escalate without losing the evidential thread.
Publication snapshot
- A SAR does not need a special form. It can be made verbally or in writing, but a written request usually gives the best record.
- The ordinary right of access comes from Article 15 of the UK GDPR, supported by Article 12 rules on how requests must be handled.
- Most SARs must be answered without undue delay and within one month, subject to specific rules on identity, authority, fees, complexity and clarification.
- A strong escalation focuses on what was requested, what was supplied, what is missing, why it matters and what correction is sought.
What a SAR does
A Subject Access Request, often shortened to SAR, is a request for access to your personal data. It is not a general disclosure exercise, a freedom of information request, or a right to every document that mentions a dispute. It is a right to know whether your personal data is being processed, to receive a copy of that personal data, and to receive supplementary information about how it is being used.
That distinction matters. A document may contain your personal data, someone else’s personal data, legally privileged material, confidential business material, or information covered by an exemption. The practical objective is therefore not to demand “everything”, but to make a request that helps the organisation identify the personal data you are seeking and makes it harder to avoid the real issue.
Practical rule: a good SAR is clear enough to process, broad enough to capture the relevant personal data, and precise enough to test whether the organisation has searched properly.
Making the request
You should start by identifying the organisation that is likely to be the data controller. That may be an employer, council, NHS body, bank, school, university, insurer, landlord, professional firm, charity, platform or other organisation deciding how and why your personal data is processed.
There is no fixed wording required for a SAR. The request does not have to use the phrase “subject access request”, although using that phrase helps avoid confusion. A request can be made verbally or in writing, but writing is usually safer because it preserves the date, wording and scope.
Identify the controller
Check who decides why and how your personal data is processed. In some cases, more than one organisation may hold relevant data.
State who you are
Give your full name, contact details and any reference number, account number, case number, employee number or address used to identify you.
Define the data sought
Describe the date range, teams, systems, correspondence, calls, notes, decisions or records that are likely to contain your personal data.
Keep proof
Save the request, delivery evidence, acknowledgement, identity-check correspondence and any later clarification.
Template request
The wording below can be adapted. It is deliberately practical rather than aggressive. Overloaded requests can invite clarification, delay and avoidable argument. If the matter is urgent because of litigation, employment, safeguarding, housing, medical or regulatory issues, say so briefly and explain why the records matter.
Subject: Subject Access Request
Dear [Organisation name],
I am making a Subject Access Request under Article 15 of the UK GDPR.
Please provide a copy of the personal data you hold about me, including personal data contained in correspondence, internal notes, call recordings, case records, decision records, account records and documents relating to [briefly describe the relevant matter].
To help you identify the relevant material, please search records relating to [date range], [department/team], [account/reference number] and [specific issue].
Please also provide the supplementary information required for a right-of-access response, including the purposes of processing, categories of personal data, recipients or categories of recipients, retention information where available, source information where the data was not obtained from me, and information about any relevant automated decision-making.
If you need proof of identity, authority, or reasonable clarification of the information requested, please ask as soon as possible and explain precisely what you need.
Yours sincerely,
[Name]
If the request needs narrowing
If the organisation reasonably asks you to clarify a broad or unclear request, do not treat every clarification request as obstruction. Narrow by date range, department, issue, record type or decision. Preserve the original scope if you are concerned that relevant data may otherwise be excluded.
Timeline and clock issues
In most cases, the organisation must respond without undue delay and at the latest within one month of receiving the request. The clock does not normally wait for an acknowledgement. However, the timing can be affected where the organisation reasonably needs information to confirm identity, confirm a third party’s authority, receive a permitted fee, or clarify an unclear request.
The response period can be extended by two further months where the request is complex or where the person has made a number of requests. The organisation should tell you about the extension and explain why within the first month.
Request sent and received
Save the email, letter, portal receipt or other evidence showing when the request reached the organisation.
Identity, authority or clarification
If the organisation reasonably needs more information, it should ask promptly and explain what is required.
Ordinary deadline
The usual deadline is one month, calculated from the relevant receipt date unless a valid clock issue applies.
Complex or multiple requests
An extension may apply, but it should be explained within the first month and should not be used as a holding tactic.
Check, follow up, escalate
If the response is late, incomplete or unclear, identify the precise gap before escalating internally or to the ICO.
Checking the response
A SAR response should not be judged only by its size. A large bundle can still miss key data. A short response may be adequate if the organisation has explained its searches and the relevant data is limited. The better test is whether the response answers the request in a way that can be checked.
Confirmation
Does the organisation confirm whether it is processing your personal data?
Copy data
Does the response include the personal data itself, not just a summary chosen by the organisation?
Supplementary information
Does it explain purposes, categories, recipients, retention, rights and source information where relevant?
Format
Is the information intelligible, accessible and provided in a practical format?
Search logic
Can you see which teams, systems, dates or records were searched?
Redactions
Are redactions explained, or are whole pages blanked out without a clear exemption or reason?
Red flags and lawful limits
Not every refusal, fee request, redaction or privilege claim is improper. Some limits are lawful. The point is to test whether the organisation has applied those limits carefully and explained them properly.
Possible red flags
Unexplained delay, generic refusal wording, missing obvious records, no search explanation, excessive redaction, refusal to identify exemptions, or repeated redirection to the ICO without engaging with the issue.
Possible lawful limits
Identity checks, third-party data, legal professional privilege, manifestly unfounded or excessive requests, complex requests, repeated requests, security concerns and specific statutory exemptions.
Best response
Ask for reasons, identify what appears missing, request clarification of exemptions, and preserve the documents needed for an internal complaint or ICO complaint.
Be particularly careful with privilege. Legal professional privilege can be a legitimate basis for withholding information. A better challenge is not “privilege cannot apply”, but “please identify the basis on which privilege is claimed, the categories of documents withheld, and why the claim applies to the material requested”.
Escalation templates
If the response is inadequate, start with the organisation. A concise escalation is usually stronger than a long complaint. It should identify the request, the response, the missing material, the reasons the response appears incomplete, and the remedy sought.
Subject: Subject Access Request response — request for review
Dear [Organisation name],
I am asking you to review your response to my Subject Access Request dated [date].
The response appears incomplete for the following reasons:
- [Identify missing record, date range, system, correspondence, call recording or document type.]
- [Identify any redaction or exemption issue that has not been explained.]
- [Identify any supplementary information that has not been provided.]
Please confirm what searches were carried out, which systems or teams were included, which exemptions have been applied, and whether any further personal data will now be disclosed.
Please respond within [reasonable date]. If the issue is not resolved, I may refer the matter to the Information Commissioner’s Office and consider any other route available to me.
Yours sincerely,
[Name]
If the organisation does not resolve the issue, prepare the ICO complaint as an evidence bundle. Include the original SAR, proof of receipt, the response, your follow-up, the organisation’s reply, and a short schedule of what remains missing or disputed.
ICO complaint structure
- Identify the organisation and your relationship to it.
- State the date and wording of your SAR.
- Explain the response received and attach it.
- Identify the precise defects: delay, incomplete data, unexplained redactions, missing supplementary information or failure to explain exemptions.
- Explain what you did to resolve the matter directly with the organisation.
- State what you are asking the ICO to consider.
Source anchors
These official sources should be checked before sending a SAR, escalating a disputed response, or publishing detailed legal claims about the process:
- ICO: Right of access guidance — detailed guidance on recognising and responding to SARs.
- ICO: recognising a SAR — explains that no formal wording is required and requests can be verbal or written.
- ICO: responding to a SAR — covers timing, clarification, extensions, fees and response requirements.
- ICO: enforcing the right of access — explains complaints, enforcement powers, court orders, compensation and criminal concealment issues.
- ICO: make a complaint — public-facing route for complaints to the regulator.
- GOV.UK: Data (Use and Access) Act 2025 factsheet — official summary of reforms affecting UK GDPR and the Data Protection Act 2018.
Closing point
A SAR is strongest when it is treated as an evidence process, not a grievance letter. Make the request clearly, keep the chronology, check the response against what was actually requested, and escalate by identifying the missing data and the legal issue. That is how a data subject turns a broad right into a practical tool.
Legal Lens decision support
Get a free written assessment before escalating a SAR dispute
If your SAR response is late, incomplete or over-redacted, a focused review can help separate the evidence gap from the legal route before you send a long escalation.
What to send
The request, proof of receipt, response bundle, exemption wording and any internal review or complaint reply.
What the review tests
Whether the issue is timing, search scope, redaction, exemption use, missing supplementary information or a wider legal route.
What it does not promise
It does not guarantee disclosure, provide regulated legal services, or replace solicitor advice where court action is needed.
Independent Legal Lens consultancy. This is not a regulated solicitors’ firm. A preliminary assessment is not a substitute for regulated legal advice where that is needed.

