DLC Tech Solutions - IT Support for Small Business
    GDPR Compliance

    GDPR Subject Access Requests

    How to handle GDPR data subject requests effectively — including subject access requests, erasure requests, and the right to be forgotten.

    Book a Consultation

    What Is a GDPR Request?

    A GDPR request — formally a "data subject request" — is made by an individual exercising one of their rights under the UK GDPR. The most common are Subject Access Requests (SARs), where an individual asks for a copy of the personal data you hold about them, and erasure requests invoking the right to be forgotten.

    Organisations must respond to most requests free of charge within one calendar month. Getting this wrong can lead to ICO complaints, enforcement action, and financial penalties.

    How to Handle a Subject Access Request

    1. Receive & Log the Request

    Record the request immediately when received — verbally, by email, or through any channel. Start the clock on your one-month response deadline.

    2. Verify the Identity

    Confirm the identity of the requester before disclosing any personal data. Request additional information if you have reasonable doubts.

    3. Locate the Data

    Search all systems, databases, emails, and paper records for personal data relating to the individual. This includes backups and archived data.

    4. Review & Redact

    Before disclosing, check whether the data contains information about other individuals that must be redacted to protect third-party rights.

    5. Respond Within Deadline

    Provide the data in a structured, commonly used format within one calendar month. Explain to the individual how their data is being processed.

    6. Apply Exemptions If Applicable

    In limited circumstances, exemptions may apply — for example, legal privilege, management information, or negotiations. Document any exemptions used.

    The Right to Be Forgotten

    The GDPR right to be forgotten — formally the "right to erasure" — allows individuals to request that you delete their personal data. You must comply when:

    • The data is no longer necessary for the purpose it was collected
    • The individual withdraws consent and there is no other lawful basis
    • The individual objects to processing and there are no overriding legitimate grounds
    • The data has been unlawfully processed
    • The data must be erased to comply with a legal obligation
    • The data was collected in relation to an offer of information society services to a child

    The right to erasure is not absolute. Exemptions exist for legal claims, public health, archiving in the public interest, and compliance with legal obligations. Document your reasoning when refusing an erasure request.

    Common Challenges

    Many organisations struggle with subject access requests because personal data is scattered across multiple systems — email, CRM, HR systems, shared drives, messaging platforms and backups. Without a clear data map, identifying and collecting all relevant data within the one-month deadline becomes extremely difficult.

    Organisations handling special category data face additional complexity — redaction requirements are more stringent and the risks of improper disclosure are higher.

    Get Your Processes Right

    A GDPR audit can assess your readiness to handle data subject requests. We help organisations build documented, repeatable processes — from request intake through to response. Pair this with data protection training for staff so frontline teams recognise requests immediately.

    Ready to Get Started?

    Contact us to discuss how we can support your organisation with practical, outcome-focused cyber security.

    Get in Touch