Close Menu
    What's Hot

    About Us

    Purchase Our Services

    Can personal data be processed outside of the UK and EU?

    LinkedIn X (Twitter)
    GDPR Subject Access Request HelpGDPR Subject Access Request Help
    • The ICO
    • About Us
    • Purchase
    LinkedIn X (Twitter)
    CONTACT
    • Home
    • Business

      Can personal data be processed outside of the UK and EU?

      Are there correct ways to respond to a GDPR subject access request?…

      When can a SAR be refused in full or in part?

      Do all businesses need to be compliant with the UK GDPR?

      Should you register your company with the ICO?

    • Personal

      Will the UK police respond to a GDPR subject access request?

      What does the UK GDPR mean for individuals?

      I don’t live in the UK or EU, what are my rights under GDPR?

      A company has not responded to my GDPR subject access request, what can I do?

      Dealing with unwanted and nuisance calls…

    • Technology

      A faulty server could be considered a breach of the GDPR…

      A glossary and explanation of GDPR terms

      Significant fines and breaches in the news…

      Why IT Security is at the core of good GDPR practice…

    • Purchase Our Services
    GDPR Subject Access Request HelpGDPR Subject Access Request Help
    Home » Are there correct ways to respond to a GDPR subject access request?…
    Business

    Are there correct ways to respond to a GDPR subject access request?…

    Martin Kayes, CISSPBy Martin Kayes, CISSPUpdated:April 15, 20243 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    When a company receives a GDPR subject access request (SAR), they are legally obligated to respond promptly and appropriately to ensure compliance with data protection laws.

    Here is a guide on how companies should respond to a GDPR subject access request:

    1. **Acknowledge Receipt of the Request**: Upon receiving a SAR, acknowledge receipt promptly, ideally within a week. This acknowledgment can be a simple confirmation email to the individual making the request, acknowledging that their request has been received and is being processed.

    2. **Verify the Identity of the Requestor**: Before disclosing any personal data, it is essential to verify the identity of the individual making the SAR. This helps prevent unauthorised access to sensitive information. Requestors may need to provide photo id, such as a scan of their passport, proof of address and account security information to confirm their identity (also known as KYC).

    3. **Assess the Request**: Review the scope and details of the SAR to understand the specific information requested and the timeframe within which the data must be provided. Determine whether any exemptions or limitations apply to the disclosure of certain types of personal data, such as legal privilege or third-party information.

    4. **Retrieve and Compile the Requested Data**: Once the identity of the requestor is verified and the scope of the request is understood, begin gathering the relevant personal data. This may involve retrieving information from various sources within the organisation, such as databases, emails, messages and paper records. Ensure that all requested data is compiled in a clear and understandable format. You will more than likely have to redact any personal information that relates to other persons

    5. **Provide the Response**: Respond to the SAR within the timeframe specified by the GDPR, usually within one month of receiving the request. Provide the requested personal data to the individual in a secure manner, such as encrypted email or through a secure online portal. Include any necessary explanations or context to help the individual understand the information provided.

    6. **Inform About Any Exemptions or Limitations**: If certain exemptions or limitations apply to the disclosure of personal data requested in the SAR, clearly communicate this to the individual. Provide explanations for why certain information cannot be disclosed and inform them of their rights to challenge the decision or seek redress.

    7. **Offer Assistance and Clarification**: Be available to answer any questions or provide further assistance to the individual regarding the information provided in response to their SAR. Offer clarification or additional context if needed to ensure they understand the data disclosed.

    8. **Document the Response**: Keep detailed records of the SAR and the organisation’s response, including any communications with the individual, steps taken to verify identity, and the data provided. This documentation is essential for demonstrating compliance with the GDPR in case of audits or regulatory inquiries.

    9. **Review and Update Internal Processes**: After handling a SAR, review your organisation’s internal processes and procedures for handling such requests. Identify any areas for improvement and update policies or training as needed to ensure ongoing compliance with data protection laws.

    10. **Delete KYC Documents**: If the individual (Data Subject) has provided you with copies of their photo ID, passport, etc, solely for proof of identity in relation to the SAR, then you should securely delete their KYC documents from your systems.

    By following these steps, companies can effectively respond to GDPR subject access requests, respecting individuals’ rights to access their personal data while ensuring compliance with data protection regulations.

    business UpperBanner
    Martin Kayes, CISSP
    • Website

    Related Posts

    Can personal data be processed outside of the UK and EU?

    When can a SAR be refused in full or in part?

    Do all businesses need to be compliant with the UK GDPR?

    Should you register your company with the ICO?

    What does the UK GDPR mean for organisations?

    What you shouldn’t do when responding to a SAR…

    Don't Miss
    Business

    Can personal data be processed outside of the UK and EU?

    By Martin Kayes, CISSP

    Yes, data can be processed internationally under the UK GDPR (General Data Protection Regulation). Under…

    Are there correct ways to respond to a GDPR subject access request?…

    When can a SAR be refused in full or in part?

    Will the UK police respond to a GDPR subject access request?

    Stay In Touch
    • LinkedIn
    • Twitter
    Specialist Investigations
    About Us
    About Us

    A trading style of Cobalt ICT Limited

    Providing affordable, professional help with GDPR, Subject Access Requests, Data Privacy and Cyber Essentials.

    Offering services and consultancy with PAYG and Monthly Retainer options

    Based in London

    We are based in London but for security reasons we do not publish our physical address.

    Our registered office is:
    c/o Kinnair & Company
    Aston House, 21 Redburn Road
    Newcastle Upon Tyne
    NE5 1NB

    A registered company in England and Wales. Registration Number 05484135

    Business Hours

    Monday - Friday
    9am - 5pm
    Terms and Conditions

    LinkedIn X (Twitter)
    • Home
    • Business
    • Personal
    • Technology
    • Fines & Breaches
    • GDPR News
    • Privacy Policy
    © 2025 Cobalt ICT Limited.

    Type above and press Enter to search. Press Esc to cancel.