Resources · United Kingdom
United Kingdom · Data protection

How to manage data access requests

What to do when a customer asks for a copy of their data — recognising a SAR, searching systems, applying exemptions, and evidencing the response.

1 Obligations under the regulations

In the UK, a customer asking for a copy of their personal data is making a subject access request (SAR) under Article 15 of the UK GDPR. You must also provide the supplementary information in Article 15: purposes, categories, recipients, retention, their other rights, and the source of the data if you did not collect it from them.

UK GDPR Articles 12 and 15 · Data Protection Act 2018 · ICO Right of Access

The ICO requires you to respond without undue delay and within one month of receipt — or within one month of receiving identity information, authority to act, or a permitted fee. You may extend by up to two further months if the request is complex or you have received a number of requests from the same person, and you must explain why within the first month. A SAR can be verbal or written, including social media, and does not need the words “subject access request”.

You cannot normally charge a fee. You may refuse or charge only if the request is manifestly unfounded or excessive (Article 12(5)), and you must be able to prove it. Exemptions in the Data Protection Act 2018 that often arise for insurers include legal professional privilege, negotiations with the requester (for example a claims reserve paper that would prejudice settlement), and information about other people. Apply exemptions case by case and document the reason.

The FCA does not replace the ICO on SARs, but Consumer Duty (PRIN 2A) still expects you to support customers and keep an audit trail of how you treated them. DISP time limits for complaints sit alongside SAR duties — a complaint that also asks for “all my data” is both a complaint and a SAR.

2 What do I need to do

Train front-line staff to recognise a SAR in any channel. Then run one workflow so nothing sits in a personal inbox.

1. Log the SAR on the day it arrives

Record received date, channel, customer identifiers and the wording used. The one-month clock starts unless you still need ID or authority. Regzact can assist: capture the request on the Data Requests register, including via a public submission form.

2. Verify identity proportionately

The ICO says you should only ask for formal ID where necessary. Use checks you already have (policy number plus date of birth, a logged-in account) where that is enough. Regzact can assist: generate a task and send a reminder if identity evidence is outstanding.

3. Run a reasonable, proportionate search

Policy admin, claims, CRM, email, complaints, appointed representatives and archived stores. Assign owners per source. Do not stop at the “customer file”. Regzact can assist: categorise the request, generate tasks, and chase completions.

4. Apply exemptions, redact, and issue the pack

Explain withholdings. Send a secure copy plus the Article 15 information. If you extend the deadline, write to the customer within the first month. Regzact can assist: generate a response from multiple data sources and keep the send on the audit trail.

3 What records do I need to keep

The ICO expects you to show how you handled the request. Keep a file you could hand over in a complaint or investigation.

  • The original SAR and the date it was received
  • Identity or authority checks and any clock-stop correspondence
  • Search scope — systems, custodians, and what was found
  • Exemption and redaction decisions, with reasons
  • A copy of what was sent and proof of delivery
  • Any extension notice and the reasons given
  • MI on volumes, cycle times, extensions and overdue SARs

Keep SAR files with your UK GDPR accountability records (Article 5(2) and Article 30). Match retention to your record of processing and any legal hold.

4 Using AI to streamline the process

Most of the elapsed time is discovery and collation. AI can:

  • Flag inbound messages as SARs even when the customer does not use ICO wording
  • Map the customer’s products to the systems that need to be searched
  • Draft a pack from multiple sources and highlight likely third-party names
  • Surface possible exemptions (negotiations, privilege, third-party data) for a human to accept or reject

A person still confirms identity, applies exemptions, and signs off. Use AI to assemble and triage — not to decide, unsupervised, what the customer is entitled to see.

5 How Regzact can help

Regzact has a dedicated Data Requests register and workflow covering capture, analysis, response generation and reporting.

  • Capture — public form or internal entry, with an auditable received date
  • Analyse — triage, categorise, and generate tasks for each source system
  • Process — build a response from multiple data sources, record redactions, send reminders
  • Govern — reporting on quality, cycle times and trends, with file export for the ICO, FCA or the board

Sanctions checks, staff SM&CR records, partner profiles, evidence files, emails, alerts and risk analysis sit on the same platform. Regzact can assist with each step of this process.

Open the Registers solution · Book a demo

This is a practical how-to for compliance managers. It is not legal advice. Always check the current text of the regulations and your own policies before you act.

Keep going

Other how-tos for United Kingdom compliance teams.

Start Your Trial Today.

Join insurers, MGAs, and brokers across the UK and Ireland who have made compliance a strategic advantage. Book a personalised demo and see Regzact working with your own network.

No credit card required All regulatory frameworks included Set up in under a day

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.