1 Obligations under the regulations
In the UK, a customer asking for a copy of their personal data is making a subject access request (SAR) under Article 15 of the UK GDPR. You must also provide the supplementary information in Article 15: purposes, categories, recipients, retention, their other rights, and the source of the data if you did not collect it from them.
The ICO requires you to respond without undue delay and within one month of receipt — or within one month of receiving identity information, authority to act, or a permitted fee. You may extend by up to two further months if the request is complex or you have received a number of requests from the same person, and you must explain why within the first month. A SAR can be verbal or written, including social media, and does not need the words “subject access request”.
You cannot normally charge a fee. You may refuse or charge only if the request is manifestly unfounded or excessive (Article 12(5)), and you must be able to prove it. Exemptions in the Data Protection Act 2018 that often arise for insurers include legal professional privilege, negotiations with the requester (for example a claims reserve paper that would prejudice settlement), and information about other people. Apply exemptions case by case and document the reason.
The FCA does not replace the ICO on SARs, but Consumer Duty (PRIN 2A) still expects you to support customers and keep an audit trail of how you treated them. DISP time limits for complaints sit alongside SAR duties — a complaint that also asks for “all my data” is both a complaint and a SAR.
2 What do I need to do
Train front-line staff to recognise a SAR in any channel. Then run one workflow so nothing sits in a personal inbox.
1. Log the SAR on the day it arrives
Record received date, channel, customer identifiers and the wording used. The one-month clock starts unless you still need ID or authority. Regzact can assist: capture the request on the Data Requests register, including via a public submission form.
2. Verify identity proportionately
The ICO says you should only ask for formal ID where necessary. Use checks you already have (policy number plus date of birth, a logged-in account) where that is enough. Regzact can assist: generate a task and send a reminder if identity evidence is outstanding.
3. Run a reasonable, proportionate search
Policy admin, claims, CRM, email, complaints, appointed representatives and archived stores. Assign owners per source. Do not stop at the “customer file”. Regzact can assist: categorise the request, generate tasks, and chase completions.
4. Apply exemptions, redact, and issue the pack
Explain withholdings. Send a secure copy plus the Article 15 information. If you extend the deadline, write to the customer within the first month. Regzact can assist: generate a response from multiple data sources and keep the send on the audit trail.
3 What records do I need to keep
The ICO expects you to show how you handled the request. Keep a file you could hand over in a complaint or investigation.
- The original SAR and the date it was received
- Identity or authority checks and any clock-stop correspondence
- Search scope — systems, custodians, and what was found
- Exemption and redaction decisions, with reasons
- A copy of what was sent and proof of delivery
- Any extension notice and the reasons given
- MI on volumes, cycle times, extensions and overdue SARs
Keep SAR files with your UK GDPR accountability records (Article 5(2) and Article 30). Match retention to your record of processing and any legal hold.
4 Using AI to streamline the process
Most of the elapsed time is discovery and collation. AI can:
- Flag inbound messages as SARs even when the customer does not use ICO wording
- Map the customer’s products to the systems that need to be searched
- Draft a pack from multiple sources and highlight likely third-party names
- Surface possible exemptions (negotiations, privilege, third-party data) for a human to accept or reject
A person still confirms identity, applies exemptions, and signs off. Use AI to assemble and triage — not to decide, unsupervised, what the customer is entitled to see.
5 How Regzact can help
Regzact has a dedicated Data Requests register and workflow covering capture, analysis, response generation and reporting.
- Capture — public form or internal entry, with an auditable received date
- Analyse — triage, categorise, and generate tasks for each source system
- Process — build a response from multiple data sources, record redactions, send reminders
- Govern — reporting on quality, cycle times and trends, with file export for the ICO, FCA or the board
Sanctions checks, staff SM&CR records, partner profiles, evidence files, emails, alerts and risk analysis sit on the same platform. Regzact can assist with each step of this process.
This is a practical how-to for compliance managers. It is not legal advice. Always check the current text of the regulations and your own policies before you act.