Resources · Ireland
Ireland · Data protection

How to manage data access requests

What to do when a customer asks for a copy of their data — from recognising the request to issuing a complete, evidenced response.

1 Obligations under the regulations

In Ireland, a customer who asks for a copy of their personal data is exercising the right of access in Article 15 of the GDPR. You must also give the supplementary information in Article 15(1)–(2): purposes, categories of data, recipients, retention, their other rights, and the source of the data if it did not come from them.

GDPR Articles 12 and 15 · Data Protection Act 2018

Provide the information without undue delay and within one month. You may extend by up to two further months where the request is complex or you have received a number of requests — but you must tell the customer why within the first month (Article 12(3)). The Data Protection Commission’s controller guidance confirms that a request can be made in writing or verbally, and does not have to use the words “subject access request”.

You cannot charge a fee except where the request is manifestly unfounded or excessive (Article 12(5)). If you have reasonable doubts about identity, Article 12(6) lets you request additional information — and that pause is reflected in section 91 of the Data Protection Act 2018. Health data may be withheld where disclosure would be likely to cause serious harm, under the Data Protection Act 2018 (Access Modification) (Health) Regulations 2022.

For an insurer or intermediary this usually means policy records, claims files, call notes, complaint files, emails and any internal notes in which the customer can be identified. The DPC expects you to include internal material, redacted where needed, not only the documents the customer has already seen.

2 What do I need to do

Treat every channel as a possible access request: email, letter, phone, web form, or a line in a complaint. Then run a single workflow.

1. Log the request on the day it arrives

Record the date received, channel, customer identifiers, and the wording of the request. The one-month clock starts here unless you need identity information. Regzact can assist: capture the request on the Data Requests register, including via a public submission form.

2. Verify identity — only as far as is reasonable

Ask for ID only where you have genuine doubt. Do not collect more than you need. Pause the clock until you have enough to be sure you are sending data to the right person. Regzact can assist: generate a task and send the identity request with a reminder if it is not returned.

3. Triage and search every system that holds the customer

Policy administration, claims, CRM, email, complaints, partner files, and archived stores. Article 15 is not limited to the “customer file”. Assign owners and deadlines for each source. Regzact can assist: categorise the request, generate tasks across data sources, and track completion.

4. Redact third-party and exempt material, then issue the pack

Balance the customer’s right of access against the rights of others. Document every redaction. Send the pack securely, with the Article 15 supplementary information, before the deadline. Regzact can assist: assemble a response from multiple sources, record the send, and keep the audit trail.

3 What records do I need to keep

If the DPC or the Central Bank asks how you handled access requests, you need a complete file per request — not a trail of emails.

  • The original request and the date it was received
  • Identity checks and any clock-stop correspondence
  • Systems searched and who searched them
  • What was disclosed, what was withheld, and why
  • A copy of the pack that went to the customer and proof of send
  • Any extension notice given under Article 12(3)
  • Management reporting on volumes, cycle times and overdue items

Hold these with the rest of your GDPR accountability records (Article 5(2) and Article 30). Align retention with your record-of-processing and legal hold rules.

4 Using AI to streamline the process

The time sink is rarely the law — it is finding every copy of the customer across systems and turning it into a coherent pack. AI can:

  • Classify inbound mail as an access request even when the customer does not use the legal wording
  • Suggest which systems to search from the customer’s products and history
  • Draft a first-cut pack from multiple data sources, flagging likely third-party names for review
  • Highlight possible exemptions (for example health data or legal advice) for a human decision

A person still has to confirm identity, apply exemptions, and sign off the response. Use AI to assemble and triage — not to decide, unsupervised, what the customer is entitled to see.

5 How Regzact can help

Regzact has a dedicated Data Requests register and workflow. It is built around the same loop as this guide: capture, analyse, process, govern.

  • Capture — public submission form or internal entry, with an auditable received date
  • Analyse — triage, categorise, and generate tasks for each data source
  • Process — pull a response from multiple sources, record redactions, and send with reminders if owners stall
  • Govern — reporting on response quality, cycle times and trends, plus file export for the DPC or the board

Sanctions screening, staff fitness records, partner profiles, evidence files, emails, alerts and risk analysis are available on the same platform, so the access-request file can sit beside the rest of the customer’s compliance history. Regzact can assist with each step of this process.

Open the Registers solution · Book a demo

This is a practical how-to for compliance managers. It is not legal advice. Always check the current text of the regulations and your own policies before you act.

Keep going

Other how-tos for Ireland compliance teams.

Start Your Trial Today.

Join insurers, MGAs, and brokers across the UK and Ireland who have made compliance a strategic advantage. Book a personalised demo and see Regzact working with your own network.

No credit card required All regulatory frameworks included Set up in under a day

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.