A subject access request (SAR) is a request from a person to see the personal data a business holds about them. Under UK GDPR everyone has this right of access, and the business must usually reply within one calendar month with a copy of the data and an explanation of how it is used.
How a subject access request works
There is no required form or wording. A request can arrive by email, letter, phone, live chat or a social media message, and it counts even if the person never says “subject access request”. It is one of the core data subject rights, so staff who handle enquiries need to recognise one.
The deadline is one calendar month from receiving the request, or from receiving anything you reasonably need to confirm the person’s identity. It can be extended by up to two further months if the request is complex or the person has made several, as long as you explain why within the first month. Since the Data (Use and Access) Act 2025, two points that used to be guidance are written into the law: you only need to make searches that are reasonable and proportionate, and if you ask the person to clarify a broad request, the clock stops until they reply. At the time of writing (October 2026), both are in force.
The response is usually free. You must provide a copy of the personal data plus supporting information: the purposes, the recipients, how long you keep it, where you got it and the person’s other rights, including complaining to the ICO. You can withhold other people’s data, and you can refuse or charge a reasonable fee for requests that are manifestly unfounded or excessive, but the bar is high.
Why it matters
Marketing data is spread across many systems, which makes SARs harder than they look. A single customer can appear in:
- the CRM, including notes, call logs and deal history;
- the email platform, with sign-up source, segments, and opens and clicks per campaign;
- website form submissions, booking tools and live chat transcripts;
- customer lists uploaded to ad platforms;
- call recordings, and emails or messages between staff that discuss the person.
Your email platform and CRM providers act as processors, so you must retrieve the data from them; they will not answer for you. Requests also arrive in disputes, from unhappy customers or former staff, where a slow or incomplete answer becomes a complaint to the ICO.
Common mistakes
- Not recognising a request because it came through Instagram or a review reply, so the month passes.
- Sending only the CRM record and forgetting email engagement data, form submissions and notes.
- Asking for identification when you already know who the person is, simply to delay.
- Sending the reply to an unverified address, which can itself become a breach.
- Keeping data for years with no data retention rules, so there is far more to search and disclose.
How to act on it
Write a simple procedure: who logs a request, how you verify identity, where to search and who approves the reply. List every marketing tool that holds personal data and check that each can export one person’s records. Most CRMs and email platforms can, but some need an admin to do it.
Keep less to begin with. Delete old exports, set retention periods for leads that never converted, and avoid free-text notes about people that you would not want them to read. When I map a business’s marketing tools as part of a digital marketing strategy, I note where personal data sits, which also makes answering a SAR much quicker.
