irmion
HelpLog in Find a tool

Privacy & Data Rights · THE NO-PANIC PLAN

Prepare a secure UK GDPR subject-access response

A subject-access request (SAR) can arrive in plain language, verbally, or through an ordinary business channel; it does not need to use legal wording. This workflow is for organizations acting as controllers under the UK GDPR. It is operational guidance, not legal advice, and the Information Commissioner's Office (ICO) guidance and UK data-protection law can change. Confirm the applicable legal regime, current ICO guidance, and your organization's DPO or counsel process before deciding a deadline, exemption, or refusal. Never send a data package until the requester and delivery destination have been checked and the disclosure has passed a second-person review where required.

MISSION Help a UK GDPR controller receive, search, review, prepare, and securely deliver a subject-access response with a documented owner, current deadline assessment, and case-by-case disclosure review.

Route a subject-access request to the privacy owner and track a reviewed secure response

THE REAL-WORLD BIT

What happens outside this browser tab?

Recognize and route the request promptly; record receipt and assign an accountable case owner; assess identity and authority proportionately and calculate a provisional response date using current ICO guidance; clarify only when reasonably needed while continuing appropriate searches; map systems and run reasonable, proportionate searches; review third-party rights and any applicable exemption individually with documented reasons; prepare an intelligible, commonly used copy and supplementary information; quality-check identity, scope, redactions, and format; then deliver securely and preserve a minimal case record under policy.

YOUR CHECKLIST, WITH FEWER DRAMATIC SIGHES

One step at a time.

Follow the order below. If a step names a Nirmion tool, its link is right there with it.

  1. 01

    Recognize the request and route it to the privacy owner

    Treat a request for a person's information as a possible SAR even when the message does not say “subject access request” or cite the UK GDPR. It may arrive verbally or through a staff member, customer-support channel, or social account. Record the channel and received date, preserve the original communication in the approved case system, and route it promptly to the DPO or designated privacy owner. Confirm that the organization is the relevant controller and whether the request concerns UK GDPR data rather than law-enforcement Part 3 or another regime. The ICO's guidance says organizations should train staff to recognize requests and establish a process for recording verbal requests.

  2. 02

    Open a restricted case record and assess identity or authority

    Assign a case ID, accountable owner, search leads, secure communication route, and provisional response date calculated by the privacy owner against current ICO guidance. The Data Subject Request Tracker can structure milestones and ownership, but it does not calculate a legal deadline, determine whether an extension or clock pause applies, or store the requester's identity documents. Confirm identity only to the extent reasonably necessary to avoid disclosing information to the wrong person; the ICO advises proportionate checks and warns against requesting formal ID when it is unnecessary. If an agent or representative made the request, verify their authority using the approved process. Store identity evidence separately with restricted access and a deletion rule.

  3. 03

    Clarify only when necessary and manage timing under current guidance

    Review what the person asked for and whether the organization can identify and retrieve the requested information without more detail. Ask for clarification only when it is reasonably required to provide an effective response; do not pressure the person to narrow a request merely because the search is inconvenient. If clarification or further identity information is needed, send the request promptly, record what was requested and why, and have the privacy owner apply the current ICO rules to the response period. The ICO's timing guidance distinguishes identity confirmation, reasonable clarification, extensions for qualifying complex or multiple requests, and when a clock may be paused; do not assume that a question automatically pauses every deadline. Send any required extension notice with its reasons within the applicable period.

  4. 04

    Map the data sources and run a reasonable, proportionate search

    Ask system and record owners to search the repositories likely to hold the person's information, such as customer or employee systems, email, case tools, relevant shared drives, archived records, and processor-held data. Specify the identifiers and date ranges approved for the search, who ran it, when, and where results are stored. Search for personal information rather than only exact name matches; aliases, account IDs, and historical addresses may be relevant when authorized. The controller remains responsible for coordinating processor information. The ICO says a reasonable and proportionate search is required, while the search scope depends on context; document the systems considered and why any repository was excluded instead of claiming every possible copy was searched.

  5. 05

    Review third-party information and exemptions item by item

    Before disclosure, review each responsive item for information about other people, legally privileged material, or another exemption that may apply under the relevant law. Do not blanket-redact a whole record or rely on a category label alone. Consider whether it is reasonable to disclose third-party information, whether separation or contextual redaction can protect others while preserving the requester's information, and whether a DPO or legal reviewer must decide. Record the item or category, decision-maker, legal basis, reasoning, redaction made, and any notice required. The ICO's detailed guidance describes case-by-case assessments and expects an organization to justify and document any exemption it applies.

  6. 06

    Prepare an intelligible copy and verify the complete response

    Compile the requester's personal information in a commonly used electronic format when the request was made electronically, unless the person asks for another format, and include the supplementary information the right of access requires. Make the response clear and accessible; explain redactions or withheld material as required by the current guidance. Have a second authorized reviewer confirm the requester, scope, all included files, third-party redactions, attachments, and stated delivery format. Check that filenames, metadata, comments, tracked changes, hidden spreadsheet columns, and archive contents do not expose unrelated people or internal notes. A preview or pattern scanner is not proof that the bundle is safe or complete; use the organization's approved review environment for sensitive source data.

  7. 07

    Deliver through a checked secure route and close the case carefully

    Confirm the destination with the requester using a trusted channel and select a delivery method appropriate to the information's sensitivity, size, and accessibility needs. Use an approved secure portal or protected file transfer where available; if using a password-protected archive, send its password through a separate verified channel and confirm the recipient can access the files. Double-check the address, recipient permissions, link expiry, download access, and whether the person can obtain a copy in a usable format. Record the sent date, method, included scope, tracking or receipt evidence, and any follow-up. Keep only the minimal case record needed for accountability and delete identity documents, exports, and working copies under the retention schedule. Escalate a misdirected or exposed response through the incident process immediately.

THE HELPER CREW

Tools for the fiddly bits.

These are the currently published Nirmion tools matched to this guide. Open a tool page for its accepted inputs and limits.

RECEIPTS, PLEASE

Sources & review notes

Each source is linked to the steps it supports. Open it to check its scope and current guidance.

Source checked 2026-10-10