Subject Access Request First Response Checklist
Use this checklist when a customer, employee or other individual asks what personal data your business holds about them. Keep the SAR, any data-protection complaint, direct-marketing objection and erasure request connected but separate; record the decision trail from first receipt through to secure response.
Use this guide when a data-rights request lands in an inbox. It is a practical operating tool, not legal advice. Check current ICO guidance and take specialist advice for difficult, contentious or high-risk cases.
The first mistake is treating a data-rights request like an ordinary customer-service email. Do not panic. Do not delete data. Do not reply casually.
One message may contain several processes
- A subject access request — “what information do you hold about me?”
- A data-protection complaint — “I never agreed to this marketing”
- An objection to direct marketing — “stop emailing me”
- An erasure request — “delete everything”
Link the requests in one evidence log, but do not treat them as one deadline or one decision.
1 Receive
- □ Save the original request unchanged
- □ Record the date, time and channel received
- □ Identify the requester and their relationship to the business
- □ Treat plain-language requests for personal information seriously, even without the phrase “SAR”
- □ Avoid deleting or tidying relevant data after receipt
2 Log
- □ Give the request a reference and name an owner
- □ Record the normal one-month SAR due date
- □ Note any separate data-protection complaint acknowledgement date
- □ Link complaint, marketing-objection and erasure requests without merging their processes
- □ Create an evidence log from the start
3 Verify
- □ Decide whether identity verification is genuinely needed
- □ Use a known account email or authenticated login where suitable
- □ Ask for further evidence only where the disclosure risk justifies it
- □ Store and protect any identity evidence proportionately
- □ Do not automatically ask everyone for a passport
Clarify with a purpose
If a broad request concerns a large amount of information, ask specific, prompt clarification where it is needed to understand scope. Current ICO guidance has specific rules around timing. Clarification is for understanding the request, not buying time.
4 Search
Start with the data map. The appropriate search depends on the request, data types and systems used. Search reasonably and proportionately — not lazily, and not theatrically.
| Data type | Possible places to check | Owner / action |
|---|---|---|
| Email and correspondence | Microsoft 365, Outlook, shared mailboxes, archives | Identify mailbox owners and search terms |
| Notes and service history | CRM, helpdesk, spreadsheets | Export or record results with the system owner |
| Files and collaboration | SharePoint, OneDrive, Teams, cloud storage | Identify relevant sites, folders and message channels |
| Calls and messaging | VoIP, call recordings, business WhatsApp, SMS | Check whether the channel is approved and mapped |
| Supplier-held data | Payroll, marketing, cloud, IT-support platforms | Use the processor contact route and record the request |
If staff use a system to talk about customers or employees, that system may contain personal data. Do not forget Teams, business WhatsApp, AI summaries or processor platforms when they are relevant.
5 Review
- □ Check whether each item is relevant personal data
- □ Identify third-party information and internal opinions
- □ Consider whether consent, redaction, exemptions or specialist advice are needed
- □ Keep a reviewed copy of the final response material
- □ Treat backup and archived-system questions cautiously; accessibility and proportionality can be nuanced
Review is not optional
A SAR gives someone access to their data, not unrestricted access to everybody else’s. Finding the record is only the first step.
6 Respond
- □ Respond using the correct SAR process and the current ICO guidance
- □ Use a delivery method appropriate to the sensitivity and volume of the information
- □ Check recipient details before delivery
- □ Provide passwords or access instructions separately where appropriate
- □ Stop direct marketing promptly where the person has objected and preserve suppression information
- □ Assess any erasure request separately — do not erase records automatically
A SAR response should not create the data breach you are trying to avoid. Black highlighting is not redaction if the text is still underneath it.
7 Record
- □ Systems searched, staff involved and processors contacted
- □ Identity and clarification decisions
- □ Review, redaction and specialist-advice decisions
- □ Response date, delivery method and proof of delivery
- □ Separate complaint, marketing-objection and erasure outcomes
- □ Follow-up actions to improve the data map or process
SAR Readiness Outcome
| Outcome | Meaning | Next action |
|---|---|---|
| CONTROLLED | Owner, process, data map, secure delivery and evidence log are known. | Run a periodic sample test. |
| REVIEW | The process exists, but a recent system, staff or supplier change needs checking. | Update the map and confirm the owner. |
| ACTION REQUIRED | A gap is known: no clear owner, data location, safe redaction or secure delivery method. | Assign an owner and target date. |
| UNKNOWN | The business cannot yet explain how it would find or handle the data. | Start with the first-hour workflow and data map. |
Operational Heartbeat
Data-rights requests need an Operational Heartbeat: systems, processors, data locations, response procedures and staff awareness should be reviewed before a real request exposes the gaps.
- Quarterly — review the data map, system inventory, processor list, request log and complaint log
- Annually — review the SAR procedure, staff awareness, secure response method and a sample exercise
- After change — add new apps, AI tools, collaboration spaces, marketing platforms and suppliers to the map
Official Guidance to Recheck
ICO: A guide to subject access →
ICO: What should we consider when responding to a request? →
Plain-English Takeaway
Receive, log, classify, verify, search, review, respond and record. A small business does not need an enterprise privacy team to control an ordinary SAR, but it does need a named owner, a living data map, a repeatable process and evidence of what it did.
Downloadable guide
Subject Access Request First Response Checklist (PDF)
A two-page A4, selectable-text first-response checklist covering receipt, logging, classification, verification, search, review, redaction, secure response, evidence and a qualitative readiness outcome.
Download SAR First Response Checklist (PDF)A4 portrait, two pages, selectable text.
Want the full business explanation?
The Technology Intelligence article covers why this matters, where it helps and what to watch out for.
Read the full Technology Intelligence articleRelated Knowledge Centre resources
Operational Heartbeat Checklist
A plain-English checklist for business owners to assess whether their IT provider is monitoring the right things. Covers backups, servers, Microsoft 365, firewalls, security, certificates, storage and more.
View guideCold Email Compliance Decision Tree
A practical UK decision framework for business email outreach. Classify the recipient as corporate, individual or unknown; test whether PECR consent or soft opt-in applies; then record the UK GDPR, transparency, opt-out and suppression checks before sending.
View guideMicrosoft 365 Admin Health Check
A structured recurring review of a Microsoft 365 tenant across 15 health areas: users, licences, administrators, authentication, mailboxes, mail flow, SharePoint, OneDrive, external sharing, Teams & Groups, data protection, Secure Score, auditing, service health and recovery. Uses the IT Club Health Model (Known / Reviewed / Action Needed) to track ownership and progress. Complements — and does not duplicate — the IT Club Security Baseline and Secure Score guides.
View guide