We may not have the course you’re looking for. If you enquire or give us a call on +44 1344 203 999 and speak to our training experts, we may still be able to help with your training requirements.
We ensure quality, budget-alignment, and timely delivery by our expert instructors.

Key Takeaways
1. DSAR stands for Data Subject Access Request and relates to the right of access under UK data protection law.2. Individuals can request copies of their personal information and details about how it is being processed.3. A request does not usually need a special form or specific wording and can be made verbally or in writing.4. Organisations normally have one month to respond, although specific circumstances can affect the deadline.5. DSARs are generally free, but organisations can charge or refuse in limited circumstances.
Your personal information can exist in more places than you might realise. An employer could hold performance records and emails about you, while a retailer might retain your purchase history and complaints. A security system might also have recorded CCTV footage in which you appear.
UK data protection law gives individuals the right to find out what personal information organisations hold about them and how that information is being used. A Data Subject Access Request is one of the main ways to exercise this right.
So, What is a DSAR, what information can you ask for, and what must an organisation do after receiving one? This blog explains the complete process from both the individual's and organisation's perspective, including current response rules, fees, exemptions and practical examples.
What is a DSAR?
A Data Subject Access Request (DSAR) allows an individual, or someone authorised to act for them, to request access to personal information an organisation holds about them. This is known as the right of access under UK data protection law.
Through a DSAR, individuals can ask whether their personal data is being processed, request a copy of that information, and receive details about how it is used. For example, an employee could request HR records, performance information, or relevant emails that contain personal information about them.
However, a DSAR does not provide unrestricted access to every document an organisation holds. It only covers information that relates to the requester, while third-party data and information subject to applicable exemptions or restrictions may need to be removed or withheld.
DSAR: Myth vs Fact
Myth: A DSAR gives you access to every document an organisation holds about you.Fact: A DSAR only provides access to your personal information. Information may be redacted or withheld where it relates to other people or is subject to an applicable legal exemption or restriction.
DSAR vs SAR: Are They the Same?
In the UK, DSAR and SAR are commonly used to describe the same type of request. DSAR expands to Data Subject Access Request, while SAR stands for Subject Access Request.
The Information Commissioner's Office (ICO) predominantly uses the term Subject Access Request or SAR when explaining the right of access. Government bodies similarly refer to requests for an individual's personal information as SARs.
Therefore, seeing either term in an organisation's privacy notice or data protection procedure should not be taken to mean that separate rights are involved.
What Information Can You Request Through a DSAR?
A DSAR does not give someone automatic access to every document, database or email that mentions their name. It gives them access to their personal information contained within those sources.
Depending on the organisation and its relationship with the individual, this could include:
1) Contact and account details
2) Customer service records
3) Purchase or transaction histories
4) HR and employment information
5) Performance assessments
6) Emails containing information about the individual
7) Recorded telephone conversations
8) CCTV footage in which the person is identifiable
9) Complaint records
10) Internal notes or opinions relating to the individual
11) Relevant online or account identifiers
For example, an employee could request information about comments made concerning their performance. A customer could ask for recordings of calls they made to a company's complaints department. Someone who was involved in an incident at business premises could request relevant personal information contained in CCTV footage.
Did You Know?
In 2024, the Crown Prosecution Service received 608 Subject Access Requests, including 575 from people other than current or former employees.
In 2024, the Crown Prosecution Service received 608 Subject Access Requests, including 575 from people other than current or former employees.
Examples of Data Subject Access Requests
A DSAR can arise in many situations because businesses, employers and public bodies process personal information for different purposes. The following examples demonstrate how the right may be used in practice.

1) Employee DSAR
Suppose an employee receives an unexpectedly poor performance review and believes earlier discussions about their work influenced the decision. They could request personal information relating to their performance, such as relevant appraisal records, manager comments and correspondence about them.
This would not necessarily entitle the employee to every email exchanged by their managers. The organisation would need to identify the information that constitutes the employee's personal information.
2) Customer Complaint DSAR
A customer has repeatedly contacted an insurance company about a disputed account issue. They want to understand what information the company has recorded about the case.
The customer could request their complaint history, personal information contained in call recordings and relevant internal notes about how their case was handled.
3) CCTV DSAR
A visitor is involved in an incident inside a shop and believes the premises' CCTV recorded what happened. If they can be identified in the footage, they may request their personal information contained in the relevant recording.
The organisation would still need to consider the rights of other identifiable people appearing in the footage. This may require techniques such as redaction or blurring before relevant information is disclosed. The ICO specifically recognises CCTV footage as information that can become relevant when responding to a SAR.
4) Former Customer DSAR
Closing an account does not necessarily mean that all information connected with the customer disappears immediately. A former customer may therefore request personal information that an organisation continues to retain about them after the relationship has ended.
These examples show why the scope of a DSAR depends on what personal information is actually held, rather than simply whether an individual currently has an active relationship with the organisation.
Explore the world of Data Protection and implement GDPR compliant programmes by registering for GDPR Training now!
How to Make a DSAR?
ICO guidance states that a SAR can be made verbally or in writing, including through social media. The essential point is that it must be clear that the individual is requesting access to their own personal information.
Although there is no universal form that must be used, providing useful information can make the request easier to process. A practical approach involves the following steps:

1) Identify the Organisation: Determine which organisation is likely to hold the personal information. Its privacy notice may provide a dedicated contact point for data protection requests.
2) Describe the Information: Explain what you are looking for as clearly as possible. Giving dates, account references, departments or types of records may help the organisation locate relevant information.
3) Provide Identifying Details: Include sufficient information for the organisation to identify your records. Additional identity evidence should only be requested where reasonably necessary.
4) Send the Request: A request can be made through an appropriate written or verbal channel. Using email can be useful because it creates a dated record of what was requested.
5) Keep Evidence: Retain a copy of the request and any subsequent correspondence in case you later need to question the response or deadline.
Being specific can improve efficiency without limiting an individual's legal rights. For example, "Please provide all personal information contained in emails between the HR department and my manager concerning my disciplinary meeting between 1 March and 30 April" gives the organisation more useful search information than simply asking for "everything about me".
How Should an Organisation Respond to a DSAR?
Receiving a DSAR creates responsibilities for the organisation handling personal information. The process involves more than searching for the requester's name and forwarding every matching file. A structured response should normally move through the following stages:

1) Recognise the Request
A DSAR does not need to use formal legal language. Employees should therefore be able to identify requests that seek access to personal information.
a) Look for requests asking what personal information the organisation holds.
b) Do not rely only on terms such as “DSAR” or “right of access”.
c) Treat clear requests for personal data as potential DSARs, regardless of wording.
d) Record and forward the request promptly through the correct internal process.
2) Confirm Identity Where Necessary
Organisations should ensure personal information is disclosed to the correct person while avoiding unnecessary identity checks.
a) Request additional identification only where there are reasonable doubts about identity.
b) Keep identity verification reasonable and proportionate to the circumstances.
c) Do not automatically request formal identification from every individual.
d) Avoid collecting more personal information than necessary for verification.
3) Clarify the Scope Where Reasonably Required
Clarification may be needed when the organisation genuinely cannot determine what information the individual is requesting.
a) Ask for clarification only when it is reasonably required to process the DSAR.
b) Explain which part of the request needs further detail.
c) Use clarification to identify relevant records more accurately.
d) Do not pressure the requester into narrowing a valid request simply to reduce the workload.
4) Search for Relevant Personal Information
The organisation should conduct a reasonable and proportionate search across systems that may contain the requested personal data.
a) Identify relevant sources such as emails, HR systems, CRM platforms and archived records.
b) Include recordings, CCTV footage or other systems where applicable.
c) Focus searches on information that relates to the requester.
d) Keep the scope proportionate to the nature and wording of the DSAR.
5) Review the Information
Not every document found during the search should automatically be disclosed in full.
a) Identify which parts of the information relate to the requester.
b) Check whether the records contain personal information about other individuals.
c) Consider whether any legal exemptions or restrictions apply.
d) Redact or withhold information where there is a valid reason to do so.
6) Prepare the Response
The final response should provide the relevant personal information clearly, securely and with any required supporting details.
a) Present the information in a clear and accessible format.
b) Include the required supplementary information about how the data is processed.
c) Use appropriate security measures when sending sensitive personal information.
d) Keep a record of what was disclosed, redacted or withheld and why.
Gain expertise in protecting data through the Data Privacy Awareness Course – Join today!
How Long Does an Organisation Have to Respond to a DSAR?
An organisation must normally respond to a DSAR without undue delay within one month. The deadline can be affected by several circumstances such as:

1) Identity Verification
If an organisation has reasonable doubts about the requester’s identity, it may ask for additional information needed to confirm it. The organisation should request this information promptly and only ask for what is reasonably necessary to verify the individual.
2) Clarification
The updated ICO guidance allows the response period to be paused where clarification is reasonably required to respond effectively. The clock pauses when clarification is requested and resumes the day after the organisation receives the clarification.
3) Complex or Multiple Requests
Where necessary because a request is complex, or the organisation has received several requests from the same person, the response period can be extended by up to two further months. The requester must be told about the extension and the reason for it within the original one-month period.
Can an Organisation Charge for a DSAR?
A DSAR is normally free of charge. An organisation cannot impose a routine administration fee simply because searching for and reviewing the information requires staff time.
A reasonable administrative fee may be charged in limited circumstances. These include where a request is manifestly unfounded or excessive, or where an individual asks for further copies of information already provided following a request.

For example, if someone receives the information requested and then asks the organisation to produce several additional copies of the same material, an administrative charge may be appropriate for those further copies.
This is different from a complicated request. A DSAR does not become chargeable merely because it requires significant searching or contains large amounts of information.
Can an Organisation Refuse a DSAR?
Organisations cannot disregard a DSAR simply because responding is inconvenient. However, there are circumstances in which some or all the requested information may be withheld. The main situations need to be considered separately.

1) Manifestly Unfounded Request
A request may be considered manifestly unfounded where there is clear evidence that the individual has no genuine intention of exercising their right of access, or where the request is malicious and intended to cause disruption. Organisations should assess each request individually and have strong justification for relying on this provision.
For example, a person might state that their purpose is to disrupt the organisation or offer to withdraw the DSAR in exchange for some unrelated benefit. The threshold is high, and the organisation should assess the circumstances rather than apply a blanket rule.
2) Excessive Requests
A request can also potentially be refused where it is excessive. Factors can include substantial overlap with previous requests or repeatedly requesting the same unchanged information without a reasonable interval.
However, requesting a large amount of information does not by itself make a DSAR excessive. The organisation needs to consider whether the request is clearly unreasonable in the circumstances.
3) Information Covered by an Exemption
Data protection law contains exemptions that can restrict the right of access in particular circumstances. An exemption may apply to some information while the remainder can still be provided.
An organisation therefore needs to assess exemptions against the actual information rather than treating one exempt item as justification for rejecting the entire request. The ICO notes that organisations may sometimes partially or fully withhold information where an applicable exemption permits it.
4) Information About Other People
A document may contain the requester's personal information alongside information about colleagues, customers, or other individuals. The organisation must consider those people's information before disclosure.
This can result in names, passages, or other information being removed rather than the entire document being withheld. The ICO also makes clear that an organisation does not necessarily have to provide complete original documents. It must provide the requester's personal information contained within them, subject to applicable restrictions.
What Happens if an Organisation Does Not Respond to a DSAR?
If an organisation does not respond within the applicable period, or the individual believes important personal information has been omitted, the first step is usually to contact the organisation.
The requester should explain the issue clearly and retain records of correspondence. If information appears to be missing, identifying what they believe has not been provided can help the organisation review its response.
Where the matter remains unresolved, the individual can make a data protection complaint to the organisation and may subsequently raise the issue with the ICO. The ICO advises individuals to allow the organisation to address the problem first. It can then consider complaints concerning potential infringements of data protection rights.
Individuals may also be able to seek enforcement of their data protection rights through the courts. Anyone considering legal proceedings should obtain appropriate independent legal advice.
Conclusion
Understanding What is a DSAR helps individuals take greater control of their personal information while helping organisations meet their data protection responsibilities. A DSAR provides access to personal information and details about how it is processed. A clear process helps ensure the right of access works effectively for both individuals and organisations.
Enhance data protection skills for professional credibility. Register for the Data Protection Act Training (DPA 2018) Course now!
Frequently Asked Questions
How Far Back Can a DSAR go?
There is no fixed time limit determining how far back a DSAR can go. An individual can request relevant personal information that an organisation still holds. However, information that has been lawfully deleted in accordance with a retention policy may no longer be available.
What is a DSAR: Data Subject Access Request Explained
Generally, an organisation does not have to recreate personal information that has already been permanently deleted before receiving the request. However, information that still exists and can be retrieved through a reasonable and proportionate search may need to be considered if it falls within the scope of the DSAR.
Can an Organisation Ask Why I am Making a DSAR?
An organisation may ask why you are making a DSAR, but you generally do not have to provide a reason to exercise your right of access. However, explaining what information you need may help the organisation identify and locate relevant personal data more efficiently.
Can an Organisation Ask Why I am Making a DSAR?
Yes. A third party can make a DSAR on behalf of another individual where they have appropriate authority to act for them. An organisation may need evidence showing that the third party has permission or legal authority to make the request.
Does a DSAR Have to Mention GDPR?
No. A request does not need to mention the UK GDPR, DSAR or SAR to be valid. If it is clear that an individual is asking for access to their personal information, the organisation should recognise and handle it as a Subject Access Request.
The Knowledge Academy is a world-leading provider of professional training courses, offering globally recognised qualifications across a wide range of subjects. With expert trainers, up-to-date course material, and flexible learning options, we aim to empower professionals and organisations to achieve their goals through continuous learning.
Top Rated Course