Recognise a subject access request in any channel, calculate the Article 12A deadline, run a reasonable and proportionate search, and give the personal data and required information unless a specific restriction applies.
Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.
This workflow implements under the UK GDPR as amended through 5 February 2026. It starts the Article 12A clock from the latest permitted trigger, supports a documented clarification pause where further information is reasonably required to identify the information or processing sought, and records the now stated in Article 15(1A).
1
Section 1
How should a DSAR Workflow run under the UK GDPR?
Log any request that, in substance, asks whether the controller processes the person's data or seeks access to it. Route verbal, social-media, customer-support, and employee requests as well as formal written requests. Confirm an agent's authority and request extra identity information only when the controller has reasonable doubts; use data proportionate to that doubt.
Article 12A sets one month beginning with the latest of receipt, receipt of necessary identity information, or payment of a permitted fee. The controller may extend by two further months when complexity or the number of requests makes that necessary, but must notify the person within the first month and give reasons.
For an Article 15 request, the controller may ask for information it reasonably requires to identify the information or processing activities sought. The period from asking until receiving that clarification does not count. Ask only where clarification is needed for an effective response; the controller cannot force the person to narrow the request, and a workable request should proceed without a routine pause.
A limits unreasonable or disproportionate search effort; it is not a general exemption from the right. Search the sources reasonably likely to contain responsive personal data, record why excluded sources were disproportionate to the importance of the information, and do not substitute a document count for analysis of the requester's personal data.
Requests about a child require a competence, authority, best-interests, welfare, and privacy assessment. A competent child can exercise the right or authorise a representative. Parental responsibility does not automatically entitle an adult to all of a child's information, and the applicable position can differ across the UK.
Intake owner: preserve the request, channel, receipt time, requester details, authority to act, requested format, accessibility needs, and all correspondence.
Deadline owner: calculate the , any identity or fee trigger, a justified clarification pause, extension notice, and final due date.
Search owners: search locations reasonably likely to hold responsive personal data and record systems, accounts, date ranges, custodians, processors, queries, and results.
Reviewer: separate the requester's personal data from whole documents, protect other people's rights and freedoms, and apply each exemption only to the material it covers.
Reviewer: disclose another person's information only where that person consents or it is reasonable without consent; document the case-specific balance rather than applying a blanket third-party redaction rule.
Response owner: provide confirmation, a copy of responsive personal data, the Article 15 supplementary information, explanations for withheld material or refusal, and the controller-complaint, ICO-complaint, and judicial-remedy routes where required. Use a commonly used electronic format for an electronic request unless the person asks otherwise, and deliver it securely and accessibly.
Complaint owner: for a data-protection complaint received on or after 19 June 2026, acknowledge it within 30 days, investigate and provide progress without undue delay, and communicate the outcome without undue delay.
What fields should the DSAR Workflow template capture?
The case record should show that the controller responded to the actual request on time and based the disclosure on a . It should also make every pause, extension, fee, refusal, exemption, and redaction reviewable.
Request and clock: original wording, channel, receipt, , identity doubt and evidence, fee status, clarification request and receipt, extension notice, and due date.
Scope and search: confirmed scope, products, systems, processors, custodians, accounts, dates, search method, search owner, results, and quality check.
Review: personal-data analysis, duplicate handling, third-party material, confidentiality, exemptions and provisions, redactions, withheld categories, and legal review.
Response: data and supplementary information supplied, format and accessibility, secure delivery, refusal or limitation reasons, fee, response time, complaint and remedy information, and delivery evidence.
Child or representative request: competence, best interests, parental responsibility or other authority, the person's wishes, third-party evidence, decision, and reviewer.
How should teams review and improve the DSAR Workflow?
Review the workflow after missed or extended deadlines, complaints, overturned exemptions, repeated clarification, failed identity checks, new systems, processor changes, or searches that cannot be reproduced. Update the data map and search instructions when actual data locations differ from the record.
Track the time spent in intake, identity, clarification, search, review, approval, and delivery.
Sample completed cases to confirm searches were reasonable and proportionate and redactions were independently checked.
Keep current owners and search instructions for archives, messaging, backups, employee systems, and processors.
Revise template wording when Article 12A timing or the controller's complaint and remedy information changes.