
A subject access request can arrive as an ordinary email and may also include a data-protection complaint, an objection to direct marketing or an erasure request. The safe response is to log it, identify the rights involved, verify identity where appropriate, search relevant systems proportionately, review carefully, respond securely and keep evidence.
This question has been published anonymously. Details that could identify the person or organisation have been removed. IT Club provides practical technology and process guidance, not legal advice.
The Question
“A customer has emailed asking for all the personal data we hold about them. They also say they never agreed to marketing and want everything deleted. What do we actually need to do?”
— Asked anonymously. Generalised from a real business-owner enquiry.
The Short Answer
If a SAR lands today
Do not panic. Do not delete data. Do not reply casually. The first mistake is treating a data-rights request like an ordinary customer-service email.
- 1Save and log the original request, including the date and time received.
- 2Identify the rights being exercised; one message can contain more than one.
- 3Acknowledge it using the right process and give it a named owner.
- 4Verify identity only where that is necessary and proportionate.
- 5Identify the systems likely to hold relevant personal data.
- 6Gather, review and redact information before disclosure.
- 7Handle any marketing objection, complaint or erasure request separately.
- 8Respond securely and record what you did.
Inventory first. Delete later — if deletion is actually required.
A customer might write: “I keep getting marketing emails from you. I never signed up. Tell me what data you hold about me and delete it. If I do not hear back, I am going to the ICO.” One email can trigger several different UK GDPR processes at the same time.
| What may be in the email | What it means in practice |
|---|---|
| “Tell me what data you hold about me” | Potential subject access request (SAR): assess the request for access to their personal data. |
| “I never agreed to marketing” | Potential data-protection complaint: use the organisation’s complaints process as well as reviewing the marketing history. |
| “Stop emailing me” | Potential objection to direct marketing: stop the marketing and preserve enough suppression information to prevent it restarting. |
| “Delete everything” | Potential erasure request: assess it separately. It is not an instruction to erase every record immediately. |
Treat the rights request and the complaint as related, but separate, processes.
Recognise a Subject Access Request
A subject access request lets an individual ask for access to the personal data an organisation holds about them, together with related information required by law. It is not a special form that only arrives via a legal department.
- A customer, employee, former employee, job applicant, supplier contact, contractor or another identifiable individual may make a SAR.
- They do not have to use the phrase “subject access request”, quote UK GDPR, fill in a special form or write to a particular person.
- A company does not have a SAR right in the same way that an individual does, although a named person at that company may.
- A request can arrive by email, letter, a web form, a social channel or another ordinary business channel.
The practical rule
If someone asks “what information do you hold about me?”, treat it seriously even if they never use the letters SAR.
ICO: A guide to subject access →
The Clock Matters — But Scope Matters First
ICO guidance says organisations normally have one month to respond to a SAR. The detailed rules around calculating the period, extending it for complex or numerous requests, asking for ID and seeking clarification matter. Do not make up your own deadline or assume every difficult request gives you extra time.
- Record the receipt date and the response due date as soon as the request is recognised.
- An extension of up to a further two months may be possible where a request is complex or a person has made numerous requests; current ICO guidance explains when and how the person must be told.
- If you reasonably need identity information, request it promptly and only to the extent needed to avoid disclosing data to the wrong person.
- Where a very broad request concerns a large amount of information, clarification may be relevant. The current law and ICO guidance contain specific timing rules; use clarification to understand scope, not to buy time.
Clarification is for understanding the request, not buying time. The clock matters, but knowing what the request actually covers matters first.
The Data (Use and Access) Act 2025 changed parts of the UK data-protection framework. Before relying on an extension, clarification or refusal in a live case, check the current ICO guidance and take specialist advice where needed.
ICO: What should we consider when responding to a request? →
Verify Identity Without Creating Another Data Problem
You should not automatically ask every requester for a passport. The identity check needs to match the risk: a known customer writing from the account email may need a different approach to someone asking for sensitive information through an unfamiliar channel.
- Confirm through a known email account or authenticated account login where appropriate.
- Use existing customer details carefully to establish confidence.
- Request additional evidence only where the disclosure risk genuinely justifies it.
- Keep any identity material limited, protected and only for as long as necessary.
Proportionate verification
Identity checks should reduce disclosure risk without creating a new pile of unnecessary personal data.
Do Not Delete Data Because a SAR Has Arrived
Do not start deleting data to reduce what may need to be disclosed. A request to access data is not permission to clean up the evidence. If routine deletion, mailbox cleanup or retention activity could affect the requested material, flag that risk and get responsible guidance before it runs.
If the person also asks for erasure, record that as a separate request. The right to erasure is not absolute: an organisation may have legitimate legal or business reasons to retain certain information. “Delete everything” is a request to assess — not necessarily an instruction to erase every record immediately.
Map the Places Where Data May Live
Many SARs become painful because nobody knows where the data lives. The technical work is not just searching Outlook: it is making a defensible decision about which systems are relevant to the person, the request and the organisation’s data map.
The IT Club Data Map
DATA TYPE → SYSTEM → OWNER → PURPOSE → RETENTION → ACCESS
| Data type | Typical system | Questions to answer |
|---|---|---|
| Customer email and correspondence | Microsoft 365 / Outlook | Which mailbox, shared mailbox, archive or forwarding rule could contain it? |
| Customer notes and contact history | CRM / helpdesk | Who owns the record and what exports or attachments exist? |
| Files and documents | SharePoint / OneDrive / cloud storage | Which site, folder, link or collaboration space is relevant? |
| Calls and messages | VoIP, Teams, WhatsApp, SMS | Is the channel approved for business use and is it included in the map? |
| Payments, HR or supplier records | Accounting, HR, payroll or processor platform | Who controls access and how is a search requested? |
A SAR is much easier when you already know where personal data lives.
If staff use a system to talk about customers, that system may contain personal data. That can include email, Teams, SharePoint, OneDrive, CRM, accounting records, helpdesk tickets, call recordings, cloud storage, spreadsheets, paper files, business WhatsApp and third-party processors. It does not mean every system is always in scope: the search should be reasonable and proportionate to the request.
“Too much work” is not the same thing as “disproportionate”. You need a defensible search, not a theatrical one.
Finding Data Is Not the Same as Disclosing It
Relevant emails can include messages to or from the person, internal discussions identifying them, attachments and forwarded correspondence. Finding the email is only the first step. You still need to decide what can lawfully be disclosed.
- A record may contain the requester’s data and another person’s data. A SAR gives someone access to their data, not unrestricted access to everybody else’s.
- You may need to consider redaction, consent, the rights of others and relevant exemptions before disclosure.
- Internal opinions about a person can still be personal data. “It is internal” does not automatically make it out of scope.
- Employee SARs often draw in HR records, emails, Teams messages, performance notes, grievance records and manager communications. They can become operational projects quickly.
Backups, archived systems and AI tools deserve careful treatment. They may contain personal data, but accessibility, searchability and proportionality can be nuanced. Do not give a blanket answer for every backup or AI platform: document the system, ask what it can reasonably be searched for and take specialist advice on difficult cases.
Newer data locations to include in the map
- AI chat histories, Copilot prompts, AI-generated summaries and workflow logs where personal data is stored
- CRM AI features and call-summary tools
- Collaboration tools, guest workspaces and externally shared files
- Processor platforms such as payroll, marketing, cloud and IT-support systems
Adding AI to the workflow can add another place you need to know personal data might exist. Outsourcing the system does not necessarily outsource the responsibility to answer the request.
Keep the Complaint, Marketing Objection and Erasure Request Separate
A person may be raising several rights at once. The operational answer is to link the records, but do not merge the deadlines or the decisions.
| If they say… | Practical next action |
|---|---|
| “I never agreed to this marketing” | Open or link a data-protection complaint. Since June 2026, ICO guidance says organisations must provide a complaints route and acknowledge receipt within 30 days, then take appropriate steps and communicate the outcome without undue delay. |
| “Stop emailing me” | Stop direct marketing promptly, record the objection and retain enough suppression information to make sure the person is not re-imported into a future campaign. |
| “Delete everything” | Assess the erasure request separately. Retention may still be justified for some records; do not delete evidence of the SAR or the marketing objection. |
A useful marketing rule
The right answer to “stop marketing to me” may be to remember enough information to make sure you really stop.
ICO: How to deal with data protection complaints →
Respond Securely — And Redact Properly
A SAR response should not create the data breach you are trying to avoid. Think about the recipient, sensitivity, delivery method and what will happen if the information is sent to the wrong place.
- Consider an authenticated portal, secure file transfer, protected link or another suitable method for the sensitivity and volume involved.
- Use separate communication for any password or access method where appropriate.
- Check that the response is addressed to the verified recipient and contains the reviewed version of the material.
- Use proper redaction or export tools for editable documents and PDFs.
Black highlighting is not redaction if the text is still underneath it. Do not simply draw black boxes over an editable Word document or PDF and assume the hidden text is gone.
What Should the Response Include?
A SAR response is not just a folder of screenshots or an unexplained export. In clear, accessible language, it will normally provide the requester with a copy of their personal data and the relevant context required by the current rules. The exact answer depends on the case, so check the current ICO guidance rather than copying a legal template.
- The personal data itself, in an intelligible and accessible form
- The purposes for which it is being processed and the categories of personal data involved
- The recipients, or categories of recipients, who have received or may receive it
- The retention period, or the criteria used to decide how long it will be kept
- The person’s relevant rights, including rectification, erasure, restriction and objection where applicable
- The right to complain to the ICO
- The source of the data where it was not collected directly from the person, where that information is available
- Information about automated decision-making or profiling where it applies
Explain what has been provided, what has been withheld or redacted and how the person can access the response securely. This is practical guidance, not a legal response template or certification.
ICO: Right of access detailed guidance →
The IT Club SAR Workflow
RECEIVE → LOG → CLASSIFY → VERIFY → CLARIFY IF NEEDED → SEARCH → REVIEW → REDACT → RESPOND → RECORDReceive. Record. Search. Review. Respond. A simple, owned workflow is more useful to a small business than a dense policy nobody can find when a real request arrives.
The SAR First-Hour Checklist
- □ Save the original request and note the received date and time
- □ Identify the requester and the likely relationship to the business
- □ Identify each right being exercised: access, complaint, marketing objection, erasure or another request
- □ Notify the responsible person and name an owner
- □ Stop routine deletion where it could affect relevant information
- □ Note the SAR deadline and any separate complaint acknowledgement date
- □ Identify likely systems, processors and staff who may hold relevant data
- □ Decide whether clarification is genuinely needed
- □ Decide the identity-verification approach proportionately
First-hour mindset
The first hour is about control, not collecting every document.
Keep an Evidence Log
Keep a factual record of the request, decisions and outcome. If the ICO later asks what happened, “we think someone searched Outlook” is not a good audit trail.
- Request date, requester and contact channel
- Scope and any clarification
- Identity-verification decision
- Systems searched, processors contacted and staff involved
- Review, redaction and exemption decisions
- Response date, secure delivery method and evidence of delivery
- Separate complaint, marketing-objection and erasure outcomes
SAR Readiness Is People, Process, Places and Proof
| Readiness area | Question for the business owner |
|---|---|
| People | Who receives and owns a SAR today? Would staff recognise one? |
| Process | Is there a logged, repeatable first-hour and response workflow? |
| Places | Do you know where customer, employee and supplier-contact data lives? |
| Proof | Can you show which systems were searched, what was reviewed and how you responded? |
If the answer to “who handles a SAR?” is “probably whoever sees the email”, the process is not ready.
Qualitative SAR readiness scorecard
- CONTROLLED — owner, procedure, deadline tracking, data map, systems, processors, secure delivery and evidence log are known and tested
- REVIEW — the process exists but a recent change to people, systems or suppliers needs checking
- ACTION REQUIRED — a specific gap is known; assign an owner and a date
- UNKNOWN — the organisation cannot yet explain how it would find or handle the relevant data
Use the scorecard to identify the biggest gap, quickest fix and next action. It is an IT Club working model, not a legal certification or compliance score.
Make It Part of the Operational Heartbeat
Data-rights requests need an Operational Heartbeat: systems, processors, data locations, response procedures and staff awareness should be reviewed before a real request exposes the gaps.
- Quarterly: review the data map, system inventory, processor list, request log and complaint log.
- Annually: review the SAR procedure, staff awareness, secure response method and a sample tabletop test.
- After material change: add new apps, AI tools, marketing platforms, collaboration spaces and suppliers to the data map before they become a blind spot.
The IT Club View
A SAR should not be a legal emergency if the business is prepared. The SAR itself is rarely the real problem. The real problem is discovering how little control the business has over its own data.
You do not need an enterprise privacy team to handle ordinary requests well. You do need a clear owner, a data map, a repeatable process and enough evidence to show what you did.
Has a data-rights request landed in your inbox?
Tell the IT Club Advisor what the person has asked for and which systems may contain their data. We can help you identify the practical IT and process questions you need to address before responding. IT Club provides practical technology guidance, not legal advice.
Free to ask. No credit card. No sales pressure. Fair usage applies.
Frequently Asked Questions
Does a SAR have to be in writing or use the phrase “subject access request”?
No. A SAR can arrive through ordinary business channels and does not need special wording. If someone asks for the personal information you hold about them, recognise and assess it rather than waiting for a formal template.
How long does a business normally have to respond?
The normal ICO timescale is one month. The detailed rules around calendar calculations, extensions, identity verification and clarification matter, so record the date promptly and check current ICO guidance for the live case.
Can we ask for clarification or pause the deadline?
Clarification can be appropriate for a broad or unclear request, particularly where a large amount of data is involved. Current law contains specific conditions around its effect on timing. Use it to understand scope, ask promptly and do not use it as a routine delay tactic.
Do we have to ask for a passport?
No. Identity checks should be necessary and proportionate. A known account email, login or existing customer details may sometimes be sufficient. Do not collect more identity material than the disclosure risk requires.
Do emails, Teams messages, WhatsApp and AI chat logs count?
They can. If a business system or approved work channel contains personal data about the requester, it may need consideration in a reasonable and proportionate search. AI logs and backup systems can be nuanced, so record what exists and seek specialist advice for difficult cases.
Can we redact other people’s data?
Possibly. A SAR is about the requester’s data, not unrestricted access to other people’s information. Review third-party information, relevant exemptions and the rights of others before disclosure, and use proper redaction tools.
What should a SAR response contain?
Normally, a clear response includes a copy of the requester’s personal data plus relevant context such as purposes, categories, recipients, retention, applicable rights, the right to complain to the ICO, source information where relevant and automated-decision information where it applies. Explain any redactions or withheld material. The exact content depends on the case, so check current ICO guidance rather than using this as a legal template.
Can we refuse or charge for a SAR?
SARs are normally free. Refusal or a fee is limited to circumstances allowed by law and should not be treated as an easy answer to an inconvenient request. “Annoying” is not a lawful refusal category.
What if the person also asks to stop marketing or delete their data?
Handle those rights separately from the SAR. Stop marketing and retain a suppression record where needed to keep it stopped. Assess erasure carefully; it is not automatically compatible with every retention requirement or with preserving evidence of how you handled the request.
Can IT Club provide legal advice on a SAR?
No. IT Club can help identify practical technology and process questions, such as where relevant data may be held, how to map systems and how to deliver a reviewed response securely. For legal interpretation, contentious cases or difficult exemptions, take specialist advice.
Related Reading
Read: Is Your Cold Email Legal? A UK Business Guide to GDPR and PECR →
Read: Microsoft 365 Admin Health Check: 15 Things Every Business Should Review →
Read: Microsoft 365 Security Baseline Checklist →
Use the Subject Access Request First Response Checklist →
Official Guidance to Recheck
ICO: A guide to subject access →
Plain-English Takeaway
A subject access request should be a managed business process, not a crisis. Recognise it, log it, separate the rights involved, verify identity where appropriate, search the relevant systems proportionately, review and redact carefully, respond securely and retain evidence. Most small-business SAR problems begin with poor data visibility and unclear ownership rather than the request itself.
Need the practical steps?
A short, instruction-led version of this topic is available in the Knowledge Centre.
View the Knowledge Centre GuideRelated Articles
Do I Really Need to Spend £1,000+ on a Business Laptop?
Need a powerful business laptop without spending £1,000+? See why a refurbished workstation with 32 GB RAM can offer better value for many SMEs.
Read articleDoes MFA Have to Apply to Every Microsoft 365 Guest?
Does every Microsoft 365 guest need MFA? IT Club explains Teams meetings, SharePoint sharing, guest access and Conditional Access in plain English.
Read articleWindows Defender Not Updating? How to Check and Fix It for Cyber Essentials
Cyber Essentials scan flagging an outdated Microsoft Defender installation even though you use another antivirus? Here's how to identify what's actually protecting the PC and fix the underlying Defender vulnerability.
Read article