Resources · United Kingdom
United Kingdom · UK GDPR

How to manage subject access requests

What to do when a customer makes a subject access request under the UK GDPR — from receiving the SAR to publishing a complete, evidenced response.

1 Obligations under the regulations

In the UK, a customer asking for a copy of their personal data is making a subject access request (SAR) under Article 15 of the UK GDPR. You must also provide the supplementary information in Article 15: purposes, categories, recipients, retention, their other rights, and the source of the data if you did not collect it from them.

UK GDPR Articles 12 and 15 · Data Protection Act 2018 · ICO Right of Access

The ICO requires you to respond without undue delay and within one month of receipt — or within one month of receiving identity information, authority to act, or a permitted fee. You may extend by up to two further months if the request is complex or you have received a number of requests from the same person, and you must explain why within the first month. A SAR can be verbal or written, including social media, and does not need the words “subject access request”.

You cannot normally charge a fee. You may refuse or charge only if the request is manifestly unfounded or excessive (Article 12(5)), and you must be able to prove it. Exemptions in the Data Protection Act 2018 that often arise for insurers include legal professional privilege, negotiations with the requester (for example a claims reserve paper that would prejudice settlement), and information about other people. Apply exemptions case by case and document the reason.

The FCA does not replace the ICO on SARs, but Consumer Duty (PRIN 2A) still expects you to support customers and keep an audit trail of how you treated them. DISP time limits for complaints sit alongside SAR duties — a complaint that also asks for “all my data” is both a complaint and a SAR.

2 What do I need to do

Train front-line staff to recognise a SAR in any channel. Point customers to an online portal where you can, and run one workflow so nothing sits in a personal inbox.

1. Receive the request through an online portal

A public submission form gives you an auditable received date and stops SARs landing in inboxes. Still log requests that arrive by email, post, phone or social media on the same register — the one-month clock starts on receipt. Regzact can assist: capture SARs through an online submission portal or internal entry, with the received date on the Data Requests register.

2. Triage and analyse

Verify identity proportionately — the ICO says you should only ask for formal ID where necessary. Confirm authority if an adviser or solicitor is acting. Set the search scope and owners, and flag complexity if you may need an extension. Regzact can assist: triage and analyse each SAR, categorise it, and generate tasks with reminders.

3. Collect the data

Run a reasonable, proportionate search of policy admin, claims, CRM, email, complaints, appointed representatives and archives. Do not stop at the “customer file”. Regzact can assist: collect data from multiple sources against the same request and track what is still outstanding.

4. De-duplicate

The same correspondence will appear in several systems. Collapse copies so the pack is complete without sending six versions of one email. Keep a note of what you treated as a duplicate. Regzact can assist: de-duplicate collected files before they go into the response pack.

5. Redact

Apply DPA 2018 exemptions case by case: third-party data, legal professional privilege, and negotiations with the requester. Explain withholdings. A person must sign off each redaction. Regzact can assist: apply and record redactions on the assembled pack.

6. Publish the response back to the requestor

Send a secure copy plus the Article 15 information before the deadline. Keep proof of delivery. If you extend the deadline, write to the customer within the first month. Regzact can assist: publish the response back to the requestor and keep the send on the audit trail.

3 What records do I need to keep

The ICO expects you to show how you handled the request. Keep a file you could hand over in a complaint or investigation.

  • The original SAR, the channel (including the portal), and the date it was received
  • Identity or authority checks and any clock-stop correspondence
  • Triage notes: scope, owners, and whether you treated it as complex
  • Search scope — systems, custodians, and the data collected from each
  • What you de-duplicated, and exemption and redaction decisions with reasons
  • A copy of the pack published to the requestor and proof of delivery
  • Any extension notice and the reasons given
  • MI on volumes, cycle times, extensions and overdue SARs

Keep SAR files with your UK GDPR accountability records (Article 5(2) and Article 30). Match retention to your record of processing and any legal hold.

4 Using AI to streamline the process

Most of the elapsed time is discovery and collation. AI can:

  • Flag inbound messages as SARs even when the customer does not use ICO wording
  • Map the customer’s products to the systems that need to be searched
  • Flag likely duplicates across sources before a person reviews the pack
  • Surface possible exemptions (negotiations, privilege, third-party data) for a human to accept or reject

A person still confirms identity, applies exemptions, and signs off. Use AI to assemble and triage — not to decide, unsupervised, what the customer is entitled to see.

5 How Regzact can help

Regzact has a dedicated Data Requests register and workflow that runs the same loop as this guide.

  • An online submission portal so customers can lodge a SAR themselves
  • Triage and analysis of each request, with tasks and owners
  • Data collection from multiple source systems
  • De-duplication of the collected file
  • Redaction of third-party and exempt material
  • Publishing of the response back to the requestor, with an audit trail

Sanctions checks, staff SM&CR records, partner profiles, evidence files, emails, alerts and risk analysis sit on the same platform. Regzact can assist with each step of this process.

Open the Registers solution · Book a demo

This is a practical how-to for compliance managers. It is not legal advice. Always check the current text of the regulations and your own policies before you act.

Keep going

Other how-tos for United Kingdom compliance teams.

Start Your Trial Today.

Join insurers, MGAs, and brokers across the UK and Ireland who have made compliance a strategic advantage. Book a personalised demo and see Regzact working with your own network.

No credit card required All regulatory frameworks included Set up in under a day

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.