1 Obligations under the regulations
In the UK, a customer asking for a copy of their personal data is making a subject access request (SAR) under Article 15 of the UK GDPR. You must also provide the supplementary information in Article 15: purposes, categories, recipients, retention, their other rights, and the source of the data if you did not collect it from them.
The ICO requires you to respond without undue delay and within one month of receipt — or within one month of receiving identity information, authority to act, or a permitted fee. You may extend by up to two further months if the request is complex or you have received a number of requests from the same person, and you must explain why within the first month. A SAR can be verbal or written, including social media, and does not need the words “subject access request”.
You cannot normally charge a fee. You may refuse or charge only if the request is manifestly unfounded or excessive (Article 12(5)), and you must be able to prove it. Exemptions in the Data Protection Act 2018 that often arise for insurers include legal professional privilege, negotiations with the requester (for example a claims reserve paper that would prejudice settlement), and information about other people. Apply exemptions case by case and document the reason.
The FCA does not replace the ICO on SARs, but Consumer Duty (PRIN 2A) still expects you to support customers and keep an audit trail of how you treated them. DISP time limits for complaints sit alongside SAR duties — a complaint that also asks for “all my data” is both a complaint and a SAR.
2 What do I need to do
Train front-line staff to recognise a SAR in any channel. Point customers to an online portal where you can, and run one workflow so nothing sits in a personal inbox.
1. Receive the request through an online portal
A public submission form gives you an auditable received date and stops SARs landing in inboxes. Still log requests that arrive by email, post, phone or social media on the same register — the one-month clock starts on receipt. Regzact can assist: capture SARs through an online submission portal or internal entry, with the received date on the Data Requests register.
2. Triage and analyse
Verify identity proportionately — the ICO says you should only ask for formal ID where necessary. Confirm authority if an adviser or solicitor is acting. Set the search scope and owners, and flag complexity if you may need an extension. Regzact can assist: triage and analyse each SAR, categorise it, and generate tasks with reminders.
3. Collect the data
Run a reasonable, proportionate search of policy admin, claims, CRM, email, complaints, appointed representatives and archives. Do not stop at the “customer file”. Regzact can assist: collect data from multiple sources against the same request and track what is still outstanding.
4. De-duplicate
The same correspondence will appear in several systems. Collapse copies so the pack is complete without sending six versions of one email. Keep a note of what you treated as a duplicate. Regzact can assist: de-duplicate collected files before they go into the response pack.
5. Redact
Apply DPA 2018 exemptions case by case: third-party data, legal professional privilege, and negotiations with the requester. Explain withholdings. A person must sign off each redaction. Regzact can assist: apply and record redactions on the assembled pack.
6. Publish the response back to the requestor
Send a secure copy plus the Article 15 information before the deadline. Keep proof of delivery. If you extend the deadline, write to the customer within the first month. Regzact can assist: publish the response back to the requestor and keep the send on the audit trail.
3 What records do I need to keep
The ICO expects you to show how you handled the request. Keep a file you could hand over in a complaint or investigation.
- The original SAR, the channel (including the portal), and the date it was received
- Identity or authority checks and any clock-stop correspondence
- Triage notes: scope, owners, and whether you treated it as complex
- Search scope — systems, custodians, and the data collected from each
- What you de-duplicated, and exemption and redaction decisions with reasons
- A copy of the pack published to the requestor and proof of delivery
- Any extension notice and the reasons given
- MI on volumes, cycle times, extensions and overdue SARs
Keep SAR files with your UK GDPR accountability records (Article 5(2) and Article 30). Match retention to your record of processing and any legal hold.
4 Using AI to streamline the process
Most of the elapsed time is discovery and collation. AI can:
- Flag inbound messages as SARs even when the customer does not use ICO wording
- Map the customer’s products to the systems that need to be searched
- Flag likely duplicates across sources before a person reviews the pack
- Surface possible exemptions (negotiations, privilege, third-party data) for a human to accept or reject
A person still confirms identity, applies exemptions, and signs off. Use AI to assemble and triage — not to decide, unsupervised, what the customer is entitled to see.
5 How Regzact can help
Regzact has a dedicated Data Requests register and workflow that runs the same loop as this guide.
- An online submission portal so customers can lodge a SAR themselves
- Triage and analysis of each request, with tasks and owners
- Data collection from multiple source systems
- De-duplication of the collected file
- Redaction of third-party and exempt material
- Publishing of the response back to the requestor, with an audit trail
Sanctions checks, staff SM&CR records, partner profiles, evidence files, emails, alerts and risk analysis sit on the same platform. Regzact can assist with each step of this process.
This is a practical how-to for compliance managers. It is not legal advice. Always check the current text of the regulations and your own policies before you act.