How to Respond to a Data-Subject Access Request
A practical workflow for request intake, identity verification, data discovery, secure disclosure, documentation, and improvement.
Rights requests are an operational test
A data-subject access request is not just an email for the legal team. It tests whether an organisation knows what personal data it holds, where it is stored, who owns the systems, how identity is verified, what can be disclosed, and how quickly teams can work together. The best time to build this capability is before the first request arrives.
STEP 1
Create one clear intake channel
Provide a simple route such as a dedicated privacy email address, online form, customer-service escalation, or written request channel. Publish it in your privacy notice and train staff to recognise requests.
STEP 2
Log the request
Record the date received, requester details, request type, business area, assigned owner, target date, communications, status, and outcome.
STEP 3
Verify identity
Use a proportionate process based on sensitivity and the risk of misidentification. Do not collect more identity evidence than necessary.
STEP 4
Clarify the scope
For broad requests, ask whether the request relates to a specific account, period, product, channel, employment relationship, or transaction. Clarification should help, not become an unnecessary barrier.
STEP 5
Locate relevant data
Use your inventory and processing register to identify likely sources such as CRM systems, email, support tickets, HR systems, finance systems, shared drives, archives, paper records, and vendor platforms.
STEP 6
Review before disclosure
Check whether information relates to other people, contains confidential business information, may be subject to restrictions, is complete and understandable, and can be delivered securely.
STEP 7
Respond securely and clearly
Use a secure delivery method. Explain the information provided, material limitations, follow-up options, and how the individual can raise concerns.
STEP 8
Learn from the request
Review whether data was easy to locate, ownership was clear, systems caused delays, supplier support was adequate, and procedures or training need improvement.
A simple readiness checklist
- • Published privacy contact route
- • Central request register
- • Identity-verification procedure
- • Defined owners and escalation path
- • Data inventory and system map
- • Secure-response method
- • Templates for acknowledgement and response
- • Training for customer-facing staff
- • Periodic testing and review
Data rights readiness
Turn privacy rights into a working process.
Explore the data rights guidance and identify operational gaps through the free readiness assessment.