Legal and Compliance

Subject Access Request (SAR)

Also called DSAR, data subject access request

A request from a person for a copy of the personal data a business holds about them, which must usually be answered within one calendar month.

Quick facts: Subject Access Request (SAR)

Category
Legal and Compliance
Also called
DSAR, data subject access request
Level
Beginner
Affects
CRM records, email platform data, form submissions, ad audiences, complaint risk
Where to see it
CRM and email platform export tools, request log, ICO right of access guidance
In this article4
  1. How a subject access request works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

A subject access request (SAR) is a request from a person to see the personal data a business holds about them. Under UK GDPR everyone has this right of access, and the business must usually reply within one calendar month with a copy of the data and an explanation of how it is used.

How a subject access request works

There is no required form or wording. A request can arrive by email, letter, phone, live chat or a social media message, and it counts even if the person never says “subject access request”. It is one of the core data subject rights, so staff who handle enquiries need to recognise one.

The deadline is one calendar month from receiving the request, or from receiving anything you reasonably need to confirm the person’s identity. It can be extended by up to two further months if the request is complex or the person has made several, as long as you explain why within the first month. Since the Data (Use and Access) Act 2025, two points that used to be guidance are written into the law: you only need to make searches that are reasonable and proportionate, and if you ask the person to clarify a broad request, the clock stops until they reply. At the time of writing (October 2026), both are in force.

The response is usually free. You must provide a copy of the personal data plus supporting information: the purposes, the recipients, how long you keep it, where you got it and the person’s other rights, including complaining to the ICO. You can withhold other people’s data, and you can refuse or charge a reasonable fee for requests that are manifestly unfounded or excessive, but the bar is high.

Why it matters

Marketing data is spread across many systems, which makes SARs harder than they look. A single customer can appear in:

  • the CRM, including notes, call logs and deal history;
  • the email platform, with sign-up source, segments, and opens and clicks per campaign;
  • website form submissions, booking tools and live chat transcripts;
  • customer lists uploaded to ad platforms;
  • call recordings, and emails or messages between staff that discuss the person.

Your email platform and CRM providers act as processors, so you must retrieve the data from them; they will not answer for you. Requests also arrive in disputes, from unhappy customers or former staff, where a slow or incomplete answer becomes a complaint to the ICO.

Common mistakes

  • Not recognising a request because it came through Instagram or a review reply, so the month passes.
  • Sending only the CRM record and forgetting email engagement data, form submissions and notes.
  • Asking for identification when you already know who the person is, simply to delay.
  • Sending the reply to an unverified address, which can itself become a breach.
  • Keeping data for years with no data retention rules, so there is far more to search and disclose.

How to act on it

Write a simple procedure: who logs a request, how you verify identity, where to search and who approves the reply. List every marketing tool that holds personal data and check that each can export one person’s records. Most CRMs and email platforms can, but some need an admin to do it.

Keep less to begin with. Delete old exports, set retention periods for leads that never converted, and avoid free-text notes about people that you would not want them to read. When I map a business’s marketing tools as part of a digital marketing strategy, I note where personal data sits, which also makes answering a SAR much quicker.

Do and do not

Do

  • Train staff to recognise a request in any channel
  • Check each marketing tool can export one person's data
  • Set retention periods so there is less to search

Do not

  • Ignore requests that arrive by social media
  • Send only the CRM record
  • Use identity checks as a delaying tactic

Questions people ask about this

How long do I have to respond to a subject access request?

One calendar month from receiving the request, or from receiving any identity information you reasonably need. You can extend by up to two more months for complex or multiple requests, but you must tell the person within the first month and explain why. If you ask them to clarify a broad request, the deadline pauses until they reply.

Do I have to include email opens and clicks in a SAR response?

Yes, if they are linked to the person. Email platforms record which campaigns someone received, opened and clicked, and that is personal data about them. Export the contact's activity history along with their profile, segments and sign-up details, and explain in plain English what each part shows.

Can I refuse a subject access request?

Only in limited cases. You can refuse, or charge a reasonable fee, if a request is manifestly unfounded or excessive, for example one made purely to cause disruption, or a repeat of a request you answered recently. You must explain your decision and tell the person they can complain to the ICO. Being busy or finding the request awkward is not a reason to refuse.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.