Artifact GuideUKData Subject Rights

UK GDPR Data Subject Rights

Recognise the right being exercised, calculate the deadline, find the relevant data, apply any restriction to the specific material, and give the person a clear, secure response.

Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 27, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 27, 2026
Overview

People can exercise access, rectification, erasure, restriction, portability, objection, and automated-decision rights, but each right has different conditions and limits. A request can be verbal or written and does not need to mention the UK GDPR. Respond without undue delay and normally within one month. Since 5 February 2026, sets the start date when reasonably requested identity information or a permitted fee is outstanding; clarification can pause the access-request clock only where it is reasonably required to identify the requested information.

Section 1

How should a team recognise and time a rights request?

Identify which right is being exercised rather than treating every contact as a subject access request. Record receipt, identity and authority, the relevant time under , the processing and systems in scope, and any applicable exemption or restriction.

For access, the controller must make a reasonable and proportionate search. It must be able to explain why any further search would be unreasonable or disproportionate, and must still search the other information within scope. Record systems, custodians, search terms, date ranges, repositories, third-party data, redactions, and review.

Respond without undue delay and before the applicable period ends. A further two months is available where necessary because the request is complex or the person has made a number of requests. Tell the person within the first month and explain the reason for the extension.

  • Route requests by right while keeping one auditable intake and deadline record.
  • Ask for identity evidence only where reasonable doubts exist and only to the extent necessary.
  • For access clarification, record what information was reasonably required, when it was requested and received, what could still be answered, and the exact paused period.
  • Ask for a fee only where the law permits it, such as a request, and record the basis and calculation.
  • Apply DPA 2018 exemptions to the particular information and purpose; do not use them as blanket exclusions.
Section 2

What does each right require?

Access provides confirmation, a copy of the person's personal data, and supplementary information. Rectification covers inaccurate data and completion of incomplete data. Erasure applies only in specified circumstances, including where data is no longer needed, consent is withdrawn with no other basis, a valid objection succeeds, or processing is unlawful; legal obligations, freedom of expression, public-interest tasks, research safeguards, and legal claims can limit it.

Restriction applies in specified cases, including while accuracy or an objection is checked. Portability covers data the person provided where processing is based on consent or contract and carried out by automated means. Objection applies to public-task, recognised-legitimate-interest, and ordinary-legitimate-interest processing, with an absolute right to stop direct marketing.

Articles 22A to 22C govern a decision with no meaningful human involvement that produces a legal or similarly significant effect. The controller must tell the person about the decision and enable representations, human intervention, and a challenge. Solely automated significant decisions using face the additional Article 22B conditions, and a controller cannot make one where the decision processing relies wholly or partly on recognised legitimate interest.

  • Tell recipients about rectification, erasure, or restriction where required, unless this is impossible or involves disproportionate effort.
  • For portability, provide structured, commonly used, machine-readable data and transmit it directly where technically feasible and requested.
  • For an objection outside direct marketing, stop unless the controller demonstrates compelling legitimate grounds that override the person's interests, rights, and freedoms, or needs the data for legal claims.
  • For a solely automated significant decision, record the lawful basis, whether or recognised legitimate interest is involved, why human involvement is or is not meaningful, the information given, and the route for representation, intervention, and contest.
  • Do not erase evidence needed to assess and answer the request; preserve an appropriate audit record without retaining unnecessary response copies.
Section 3

When can a controller limit or refuse a request?

A controller may refuse to act on a request, or charge a reasonable fee where permitted, but it bears the burden of showing why. Repetition alone is not automatically excessive. Consider the request's context, overlap, interval, purpose, burden, and whether the person is exercising a fundamental right.

The Data Protection Act 2018 contains exemptions for particular data, purposes, and circumstances, including some third-party information, legal professional privilege, management forecasting, negotiations, regulatory functions, journalism, research, and crime or taxation. Apply the precise provision to the precise material. An exemption may limit only part of the response.

  • Before disclosing third-party personal data, consider consent, confidentiality, the type of information, any duty of confidence, and whether disclosure without consent is reasonable.
  • If refusing or limiting a request, tell the person without undue delay, explain the reason to the extent permitted, and state their right to complain to the ICO and seek a judicial remedy.
  • Separate information that can be supplied from information covered by an exemption, restriction, or disproportionate search conclusion.
  • Route legal privilege, safeguarding, confidential references, regulatory secrecy, and mixed-controller records for specific review.
Section 4

What records should the response workflow keep?

Use one intake channel and deadline record, but route the substance to the system and business owners who can search, correct, delete, restrict, export, or stop the processing. The controller remains accountable when a processor performs searches or technical changes.

Keep the original request, receipt date, identity or authority check, calculation, clarification and pause dates, search plan and results, decisions by right, exemption and third-party analysis, copies or descriptions of disclosed material, secure delivery evidence, recipient notifications, correspondence, approver, and closure date.

A rights request and a data protection complaint are separate even when one message contains both. Record and answer the right within , and also use the organisation's complaint process. Give people a way to complain, acknowledge receipt within 30 days, make appropriate enquiries, keep them informed, and communicate the outcome without undue delay.

  • Train customer support, HR, social-media, sales, and product teams to recognise requests and forward them without delay.
  • Use proportionate identity checks and a separate authority check for a representative; do not collect more identification data than needed.
  • Track corrections, deletions, restrictions, objections, and withdrawals through replicas, active processors, and relevant recipients.
  • Review recurring search gaps and update data maps, retention controls, processor instructions, and privacy information.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Binding response, identity, fee, timing, transparency, and controller-accountability requirements.
legislation.gov.uk
Referenced sections
  • Binding UK exemptions and restrictions that may qualify individual rights.
ico.org.uk
Referenced sections
  • ICO guidance on manifestly unfounded or excessive requests, third-party information, exemptions, and refusal notices.
Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.