Data Subject Access Requests
Individuals have the right under the UK GDPR to ask what personal data you hold about them, what you do with it, and why. This is commonly referred to as a subject access request (often shortened to “SAR”).
This collection is designed as a practical toolkit: the documents are intended to work together so you can follow a clear process from recognising a request through to issuing the appropriate response.
When Should You Use These Templates?
Use this collection if you want a structured way to handle SARs, including:
- recognising requests in practice (there is no prescribed format a SAR must follow);
- acknowledging receipt and, where appropriate, asking for clarification or proof of identity before disclosing data;
- managing time limits (usually one month, with a limited ability to extend where requests are complex or numerous);
- dealing with the limited situations where a fee can be charged (for example where a request is “manifestly unfounded or excessive”); and
- responding consistently, including where you locate no relevant personal data.
What Templates Are Included?
Policies And Guidance (How The Process Works)
Data Subject Access Request Guidance Notes
Practical guidance explaining how SARs work and what to do at each stage, including recognition, what information must be provided, time limits, fees, requests made on someone else’s behalf, and dealing with data about other individuals and processors.
Data Subject Access Request Policy and Procedure
An internal policy setting out the end-to-end SAR process, including who does what, recognising requests, clarifying scope, time limits, fees, searches, exemptions, and refusal grounds. It is up-to-date and compliant with the Data (Use and Access) Act 2025 requirement for reasonable and proportionate searches.
Short Form Subject Access Request Policy (Employees)
An employee-facing policy explaining the right of access and how staff can make a SAR to their employer, including response times, fees, and complaints.
A Form Individuals Can Use (Optional)
Subject Access Request Form
A standard form you can make available to help individuals provide the details you need to locate their personal data and understand their request, while recognising that individuals cannot be required to use a specific form.
Response Letters (Covering Common Scenarios)
SAR Letter - Acknowledgement
An initial acknowledgement letter with options to confirm the usual response timeframe and, where needed, request proof of identity or further information to clarify the request.
SAR Letter - Fee and or Additional Time
A letter for cases where you need to explain an extension (and the reasons) or where a fee is being charged, for example for complex requests or requests that are manifestly unfounded or excessive.
SAR Letter - Receipt of Additional Information or Proof of Identity
A letter acknowledging receipt of clarification or identity evidence and confirming the date by which you will provide the substantive response.
SAR Letter - Receipt of Fee
A letter acknowledging receipt of a fee charged in the limited circumstances permitted, and confirming the date by which you will respond.
SAR Letter - No Data Found
A response for situations where your searches have revealed no personal data about (or relating to) the individual, suitable either following initial receipt or after receiving clarification or identity evidence.
Why Use These Templates?
These templates are designed to help you implement a repeatable SAR handling process, rather than responding ad hoc each time:
- The policy and guidance notes help staff recognise SARs and follow a consistent workflow, including time limits, searches, and exceptions.
- The optional form helps individuals give you enough information to locate their data efficiently and reduce back-and-forth.
- The letter set supports clear, consistent communication at each stage, especially where you need ID, clarification, additional time, a fee, or where no data is found.
For more information about each document in this collection, please click on the links below:
- Data Subject Access Request Guidance Notes
- Data Subject Access Request Policy and Procedure
- Short Form Subject Access Request Policy (Employees)
- Subject Access Request Form
- SAR Letter - Acknowledgement
- SAR Letter - Fee and/or Additional Time
- SAR Letter - Receipt of Additional Information/ID
- SAR Letter - Receipt of Fee
- SAR Letter - No Data Found
Data Subject Access Requests is part of Business . Just £38.50 + VAT provides unlimited downloads from Business for 1 year.
