GDPR Subject Access Requests
How to handle GDPR data subject requests effectively — including subject access requests, erasure requests, and the right to be forgotten.
What Is a GDPR Request?
A GDPR request — formally a "data subject request" — is made by an individual exercising one of their rights under the UK GDPR. The most common are Subject Access Requests (SARs), where an individual asks for a copy of the personal data you hold about them, and erasure requests invoking the right to be forgotten.
Organisations must respond to most requests free of charge within one calendar month. Getting this wrong can lead to ICO complaints, enforcement action, and financial penalties.
How to Handle a Subject Access Request
1. Receive & Log the Request
Record the request immediately when received — verbally, by email, or through any channel. Start the clock on your one-month response deadline.
2. Verify the Identity
Confirm the identity of the requester before disclosing any personal data. Request additional information if you have reasonable doubts.
3. Locate the Data
Search all systems, databases, emails, and paper records for personal data relating to the individual. This includes backups and archived data.
4. Review & Redact
Before disclosing, check whether the data contains information about other individuals that must be redacted to protect third-party rights.
5. Respond Within Deadline
Provide the data in a structured, commonly used format within one calendar month. Explain to the individual how their data is being processed.
6. Apply Exemptions If Applicable
In limited circumstances, exemptions may apply — for example, legal privilege, management information, or negotiations. Document any exemptions used.
The Right to Be Forgotten
The GDPR right to be forgotten — formally the "right to erasure" — allows individuals to request that you delete their personal data. You must comply when:
- ●The data is no longer necessary for the purpose it was collected
- ●The individual withdraws consent and there is no other lawful basis
- ●The individual objects to processing and there are no overriding legitimate grounds
- ●The data has been unlawfully processed
- ●The data must be erased to comply with a legal obligation
- ●The data was collected in relation to an offer of information society services to a child
The right to erasure is not absolute. Exemptions exist for legal claims, public health, archiving in the public interest, and compliance with legal obligations. Document your reasoning when refusing an erasure request.
Common Challenges
Many organisations struggle with subject access requests because personal data is scattered across multiple systems — email, CRM, HR systems, shared drives, messaging platforms and backups. Without a clear data map, identifying and collecting all relevant data within the one-month deadline becomes extremely difficult.
Organisations handling special category data face additional complexity — redaction requirements are more stringent and the risks of improper disclosure are higher.
Get Your Processes Right
A GDPR audit can assess your readiness to handle data subject requests. We help organisations build documented, repeatable processes — from request intake through to response. Pair this with data protection training for staff so frontline teams recognise requests immediately.
Ready to Get Started?
Contact us to discuss how we can support your organisation with practical, outcome-focused cyber security.
Get in Touch