Recognise the right being exercised, calculate the deadline, find the relevant data, apply any restriction to the specific material, and give the person a clear, secure response.
Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.
People can exercise access, rectification, erasure, restriction, portability, objection, and automated-decision rights, but each right has different conditions and limits. A request can be verbal or written and does not need to mention the UK GDPR. Respond without undue delay and normally within one month. Since 5 February 2026, sets the start date when reasonably requested identity information or a permitted fee is outstanding; clarification can pause the access-request clock only where it is reasonably required to identify the requested information.
1
Section 1
How should a team recognise and time a rights request?
Identify which right is being exercised rather than treating every contact as a subject access request. Record receipt, identity and authority, the relevant time under , the processing and systems in scope, and any applicable exemption or restriction.
For access, the controller must make a reasonable and proportionate search. It must be able to explain why any further search would be unreasonable or disproportionate, and must still search the other information within scope. Record systems, custodians, search terms, date ranges, repositories, third-party data, redactions, and review.
Respond without undue delay and before the applicable period ends. A further two months is available where necessary because the request is complex or the person has made a number of requests. Tell the person within the first month and explain the reason for the extension.
Route requests by right while keeping one auditable intake and deadline record.
Ask for identity evidence only where reasonable doubts exist and only to the extent necessary.
For access clarification, record what information was reasonably required, when it was requested and received, what could still be answered, and the exact paused period.
Ask for a fee only where the law permits it, such as a request, and record the basis and calculation.
Apply DPA 2018 exemptions to the particular information and purpose; do not use them as blanket exclusions.
Access provides confirmation, a copy of the person's personal data, and supplementary information. Rectification covers inaccurate data and completion of incomplete data. Erasure applies only in specified circumstances, including where data is no longer needed, consent is withdrawn with no other basis, a valid objection succeeds, or processing is unlawful; legal obligations, freedom of expression, public-interest tasks, research safeguards, and legal claims can limit it.
Restriction applies in specified cases, including while accuracy or an objection is checked. Portability covers data the person provided where processing is based on consent or contract and carried out by automated means. Objection applies to public-task, recognised-legitimate-interest, and ordinary-legitimate-interest processing, with an absolute right to stop direct marketing.
Articles 22A to 22C govern a decision with no meaningful human involvement that produces a legal or similarly significant effect. The controller must tell the person about the decision and enable representations, human intervention, and a challenge. Solely automated significant decisions using face the additional Article 22B conditions, and a controller cannot make one where the decision processing relies wholly or partly on recognised legitimate interest.
Tell recipients about rectification, erasure, or restriction where required, unless this is impossible or involves disproportionate effort.
For portability, provide structured, commonly used, machine-readable data and transmit it directly where technically feasible and requested.
For an objection outside direct marketing, stop unless the controller demonstrates compelling legitimate grounds that override the person's interests, rights, and freedoms, or needs the data for legal claims.
For a solely automated significant decision, record the lawful basis, whether or recognised legitimate interest is involved, why human involvement is or is not meaningful, the information given, and the route for representation, intervention, and contest.
Do not erase evidence needed to assess and answer the request; preserve an appropriate audit record without retaining unnecessary response copies.
Turn UK GDPR Data Subject Rights into assigned work
Route each request by right, calculate the Article 12A clock, record searches and exemptions, carry the outcome through every relevant system, and keep a defensible response file.
A controller may refuse to act on a request, or charge a reasonable fee where permitted, but it bears the burden of showing why. Repetition alone is not automatically excessive. Consider the request's context, overlap, interval, purpose, burden, and whether the person is exercising a fundamental right.
The Data Protection Act 2018 contains exemptions for particular data, purposes, and circumstances, including some third-party information, legal professional privilege, management forecasting, negotiations, regulatory functions, journalism, research, and crime or taxation. Apply the precise provision to the precise material. An exemption may limit only part of the response.
Before disclosing third-party personal data, consider consent, confidentiality, the type of information, any duty of confidence, and whether disclosure without consent is reasonable.
If refusing or limiting a request, tell the person without undue delay, explain the reason to the extent permitted, and state their right to complain to the ICO and seek a judicial remedy.
Separate information that can be supplied from information covered by an exemption, restriction, or disproportionate search conclusion.
Route legal privilege, safeguarding, confidential references, regulatory secrecy, and mixed-controller records for specific review.
Use one intake channel and deadline record, but route the substance to the system and business owners who can search, correct, delete, restrict, export, or stop the processing. The controller remains accountable when a processor performs searches or technical changes.
Keep the original request, receipt date, identity or authority check, calculation, clarification and pause dates, search plan and results, decisions by right, exemption and third-party analysis, copies or descriptions of disclosed material, secure delivery evidence, recipient notifications, correspondence, approver, and closure date.
A rights request and a data protection complaint are separate even when one message contains both. Record and answer the right within , and also use the organisation's complaint process. Give people a way to complain, acknowledge receipt within 30 days, make appropriate enquiries, keep them informed, and communicate the outcome without undue delay.
Train customer support, HR, social-media, sales, and product teams to recognise requests and forward them without delay.
Use proportionate identity checks and a separate authority check for a representative; do not collect more identification data than needed.
Track corrections, deletions, restrictions, objections, and withdrawals through replicas, active processors, and relevant recipients.
Review recurring search gaps and update data maps, retention controls, processor instructions, and privacy information.