← Back to insights
DATA RIGHTS

How to Respond to a Data-Subject Access Request

A practical workflow for request intake, identity verification, data discovery, secure disclosure, documentation, and improvement.

Written by Lahiru Livera, Cybersecurity Advisor · Last reviewed: August 2026
Educational guidance only — not legal advice. Verify response requirements, timing, permitted limitations, and escalation duties against official sources and obtain appropriate advice for complex cases.

Rights requests are an operational test

A data-subject access request is not just an email for the legal team. It tests whether an organisation knows what personal data it holds, where it is stored, who owns the systems, how identity is verified, what can be disclosed, and how quickly teams can work together. The best time to build this capability is before the first request arrives.

STEP 1

Create one clear intake channel

Provide a simple route such as a dedicated privacy email address, online form, customer-service escalation, or written request channel. Publish it in your privacy notice and train staff to recognise requests.

STEP 2

Log the request

Record the date received, requester details, request type, business area, assigned owner, target date, communications, status, and outcome.

STEP 3

Verify identity

Use a proportionate process based on sensitivity and the risk of misidentification. Do not collect more identity evidence than necessary.

STEP 4

Clarify the scope

For broad requests, ask whether the request relates to a specific account, period, product, channel, employment relationship, or transaction. Clarification should help, not become an unnecessary barrier.

STEP 5

Locate relevant data

Use your inventory and processing register to identify likely sources such as CRM systems, email, support tickets, HR systems, finance systems, shared drives, archives, paper records, and vendor platforms.

STEP 6

Review before disclosure

Check whether information relates to other people, contains confidential business information, may be subject to restrictions, is complete and understandable, and can be delivered securely.

STEP 7

Respond securely and clearly

Use a secure delivery method. Explain the information provided, material limitations, follow-up options, and how the individual can raise concerns.

STEP 8

Learn from the request

Review whether data was easy to locate, ownership was clear, systems caused delays, supplier support was adequate, and procedures or training need improvement.

A simple readiness checklist

  • • Published privacy contact route
  • • Central request register
  • • Identity-verification procedure
  • • Defined owners and escalation path
  • • Data inventory and system map
  • • Secure-response method
  • • Templates for acknowledgement and response
  • • Training for customer-facing staff
  • • Periodic testing and review

Data rights readiness

Turn privacy rights into a working process.

Explore the data rights guidance and identify operational gaps through the free readiness assessment.