🎉 New: check if your AI-generated ads, images or reviews need disclosure under ASA/CAP rules — free compliance check.
Data & Privacy

Subject Access Request (SAR) Handling Compliance Check

Check whether your business has a compliant process for responding to Subject Access Requests within the legal deadline under UK GDPR.

✅ Free ⏱ 6 minutes 🤖 AI-powered 🔥 Trending

Why this matters

Under Article 15 of UK GDPR, any individual can ask your business what personal data you hold about them and how it’s used, and you must normally respond within one calendar month, free of charge. That deadline can be extended by a further two months for complex or numerous requests, but only if you tell the requester why within the first month — silently missing the deadline is itself a breach. The Data (Use and Access) Act 2025 clarified the “stop the clock” rule: where you genuinely need to ask a requester to clarify what they want, the response clock pauses until they reply, but this can’t be used as a delaying tactic for straightforward requests. Businesses of every size receive SARs, often from disgruntled employees, ex-customers, or complainants, and the ICO treats a mishandled SAR as a serious matter in its own right, separate from whatever underlying dispute prompted it.

The most common compliance failures aren’t about refusing requests outright — they’re process failures: missing the one-month deadline because nobody owns the request, failing to verify the requester’s identity properly, disclosing third-party personal data that should have been redacted, or not applying available exemptions (such as legal privilege or data that would identify another individual) correctly. A business without a clear internal process — who receives the request, how identity is verified, who searches for the data, who reviews it before disclosure — is exposed to ICO complaints, reputational damage, and in serious cases regulatory enforcement, even though SARs themselves are meant to be a straightforward transparency right rather than a legal minefield.

What you'll need

  • Whether your business has ever received a Subject Access Request
  • Whether you have a documented SAR process (who receives, verifies, searches, reviews, responds)
  • Awareness of the one-month response deadline and extension rules
  • How personal data about individuals is stored and searchable across your systems

What you'll get

A personalised compliance report covering: a score out of 100, an executive summary, a list of findings ranked by severity, and a prioritised action plan with timeframes.

This check reviews your business’s process for identifying, verifying, searching for, and responding to Subject Access Requests within the legal deadline under UK GDPR Article 15, as clarified by the Data (Use and Access) Act 2025.

General guidance only — not legal advice. Consult a qualified UK solicitor for specific issues.