1 Obligations under the regulations
In Ireland, a customer who asks for a copy of their personal data is exercising the right of access in Article 15 of the GDPR. That is a subject access request, whether or not they use those words. You must also give the supplementary information in Article 15(1)–(2): purposes, categories of data, recipients, retention, their other rights, and the source of the data if it did not come from them.
Provide the information without undue delay and within one month. You may extend by up to two further months where the request is complex or you have received a number of requests — but you must tell the customer why within the first month (Article 12(3)). The Data Protection Commission’s controller guidance confirms that a request can be made in writing or verbally, and does not have to use the words “subject access request”.
You cannot charge a fee except where the request is manifestly unfounded or excessive (Article 12(5)). If you have reasonable doubts about identity, Article 12(6) lets you request additional information — and that pause is reflected in section 91 of the Data Protection Act 2018. Health data may be withheld where disclosure would be likely to cause serious harm, under the Data Protection Act 2018 (Access Modification) (Health) Regulations 2022.
For an insurer or intermediary this usually means policy records, claims files, call notes, complaint files, emails and any internal notes in which the customer can be identified. The DPC expects you to include internal material, redacted where needed, not only the documents the customer has already seen.
2 What do I need to do
Treat every channel as a possible subject access request: the online portal, email, letter, phone, or a line in a complaint. Then run one workflow from receipt to published response.
1. Receive the request through an online portal
Give customers a public submission form so requests land in one place with an auditable received date. Still log requests that arrive by email, post or phone on the same register — the one-month clock starts on the day you receive them, not the day they are typed up. Regzact can assist: capture SARs through an online submission portal or internal entry, with the received date on the Data Requests register.
2. Triage and analyse
Confirm identity only as far as is reasonable, decide the scope (which products, which period), and assign owners. Pause the clock if you still need ID. Mark complexity early if you may need the Article 12(3) extension. Regzact can assist: triage and analyse each request, categorise it, and generate tasks with reminders.
3. Collect the data
Search every system that holds the customer: policy administration, claims, CRM, email, complaints, partner files and archives. Article 15 is not limited to the “customer file”. Regzact can assist: collect data from multiple sources against the same request and track what is still outstanding.
4. De-duplicate
The same claim note or email will sit in several systems. Collapse copies so the pack is complete without sending the customer six versions of one document. Keep a record of what you treated as a duplicate. Regzact can assist: de-duplicate collected files before they go into the response pack.
5. Redact
Balance the customer’s right of access against the rights of others. Remove third-party data, legally privileged material and any health data that the 2022 Regulations allow you to withhold. Document every redaction. Regzact can assist: apply and record redactions on the assembled pack.
6. Publish the response back to the requestor
Send the pack securely, with the Article 15 supplementary information, before the deadline. Keep proof of send. If you extended the deadline, that notice must already have gone within the first month. Regzact can assist: publish the response back to the requestor and keep the send on the audit trail.
3 What records do I need to keep
If the DPC or the Central Bank asks how you handled access requests, you need a complete file per request — not a trail of emails.
- The original request, the channel (including the portal), and the date it was received
- Identity checks and any clock-stop correspondence
- Triage notes: scope, owners, and whether you treated it as complex
- Systems searched and the data collected from each
- What you de-duplicated, what you redacted or withheld, and why
- A copy of the pack published to the requestor and proof of send
- Any extension notice given under Article 12(3)
- Management reporting on volumes, cycle times and overdue items
Hold these with the rest of your GDPR accountability records (Article 5(2) and Article 30). Align retention with your record-of-processing and legal hold rules.
4 Using AI to streamline the process
The time sink is rarely the law — it is finding every copy of the customer across systems and turning it into a coherent pack. AI can:
- Classify inbound mail as a subject access request even when the customer does not use the legal wording
- Suggest which systems to search from the customer’s products and history
- Flag likely duplicates across sources before a person reviews the pack
- Highlight third-party names and possible exemptions (for example health data or legal advice) for a human decision
A person still has to confirm identity, apply exemptions, and sign off the response. Use AI to assemble and triage — not to decide, unsupervised, what the customer is entitled to see.
5 How Regzact can help
Regzact has a dedicated Data Requests register and workflow that runs the same loop as this guide.
- An online submission portal so customers can lodge a SAR themselves
- Triage and analysis of each request, with tasks and owners
- Data collection from multiple source systems
- De-duplication of the collected file
- Redaction of third-party and exempt material
- Publishing of the response back to the requestor, with an audit trail
Sanctions screening, staff fitness records, partner profiles, evidence files, emails, alerts and risk analysis are available on the same platform, so the SAR file can sit beside the rest of the customer’s compliance history.
This is a practical how-to for compliance managers. It is not legal advice. Always check the current text of the regulations and your own policies before you act.