The right of access, and why the policy matters
Respond without undue delay and within one month of receipt. You can extend by up to two further months for a complex request, if you tell the person why within the first month. You can pause the clock while you ask for clarification that is reasonably required. You must make a reasonable and proportionate search. In most cases you cannot charge a fee.
The policy's job is to make those rules happen in your organisation: who recognises a request, who logs it, which systems are searched, who decides on exemptions, and what record is kept of each response.
The right of access is in Article 15 of the UK General Data Protection Regulation (UK GDPR). A request under it is usually called a subject access request (SAR), sometimes a data subject access request (DSAR). A person, the data subject, is entitled to confirmation that the organisation is processing their personal data, a copy of that data, and supplementary information about the processing. The exemptions sit in the Data Protection Act 2018. Both have been amended by the Data (Use and Access) Act 2025, whose data protection changes were brought into force in stages; the ICO's summary, dated 19 June 2026, says all of them are now in force.
The law does not require a document called a subject access request policy. It does require the organisation, as data controller, to comply and to be able to show how it complies, and for anything larger than a very small charity that means writing the procedure down. The ICO's guidance on preparing for a subject access request is effectively a checklist for one. Maintained schools and academies, as public authorities, must appoint a data protection officer, and the policy should name that role; charities and care providers that have not appointed one should name whoever leads on data protection.
A subject access request policy usually sits alongside the data protection policy and the retention schedule, and is written using clear and plain language, because it is read by staff who will receive requests and often published for the people who make them.
What the policy should cover
A useful subject access request procedure answers each of these for your organisation, by role rather than by name so it survives staff changes:
- Scope. Who can make a request (staff, former staff, volunteers, pupils, parents, residents, families, donors, anyone), and that it covers all personal data held, in every system: files, email, databases, CCTV, and work messages wherever they are held.
- Recognising a request. A request can be made verbally or in writing, including via social media, to any member of staff, and does not have to mention "subject access" or the law. A verbal request is as valid as a written one; write it down and, if you can, confirm it back to the individual making the request. You may offer a subject access request form, but a request is valid without one. The ICO's page on recognising a request is worth giving to every receptionist and team leader.
- Logging and passing on. The date of receipt, and who it goes to, the same day.
- Identity and authority. When to ask for proof of identity, and what is proportionate; how to check that someone requesting on another's behalf, a solicitor or a relative, is authorised.
- Clarification. When asking the requester what they want is reasonably required, and how the pause in the clock is recorded.
- Searching. Which systems are searched, by whom, and how the organisation decides what is reasonable and proportionate.
- Exemptions and third parties. Who decides whether information is withheld, and how the reasons are recorded.
- The response. What is sent, in what format, how securely, and who signs it off.
- Refusals, fees and extensions. When a request may be treated as manifestly unfounded or excessive, and who decides.
- Complaints. How the person can complain to the organisation and to the ICO.
- Records and review. The SAR log, how long response files are kept, and when the policy is reviewed.
Schools should add two things that apply only to them: a pupil's own right of access, and the separate right of a parent to see their child's educational record, both covered in section 03.
Responding to a subject access request, step by step
The ICO's guidance on what to consider when responding to a request sets out the timings. In order:
- Log the date of receipt. You "must comply with a SAR without undue delay and at the latest within one month of receipt of the request". The month runs to the corresponding date in the next month; if that falls on a weekend or bank holiday, the deadline is the next working day.
- Check the identity of the data subject if you need to. Be "reasonable and proportionate about what you ask for"; a member of staff emailing from their work account rarely needs to send a passport. The clock does not start until you have the information you reasonably need to confirm identity or authority.
- Clarify only where it is reasonably required. Since the Data (Use and Access) Act, the ICO's guidance says that when you ask for clarification "the time limit pauses on the day you request clarification and resumes on the day after you receive it". It is not to be used on a blanket basis, and you should still search for what the request clearly covers.
- Search. "You must make a reasonable and proportionate search to respond to a SAR." The ICO's page on finding and retrieving the information lists what bears on that: "the circumstances of the request; the volume of information you may need to search in order to respond; any difficulties involved in finding the information; and the fundamental nature of the right of access." Record what you searched for the information requested, and why you stopped where you did.
- Decide on extension early. If the request is complex, or the person has made a number of requests, you may extend by up to two further months, but you "must let the person know that you are extending the time limit and explain your reasons why within one month".
- Apply exemptions item by item, and redact other people's information where required (section 04).
- Send the response. The personal data, and the supplementary information Article 15 requires: the purposes of processing, the categories of data, the recipients, the retention period or how it is decided, the rights to rectification, erasure, restriction and objection, the right to complain to your organisation and to the ICO, the source of the data if not from the person, and any automated decision-making. If the request was made electronically, provide the information in a commonly used electronic form unless the person asks otherwise.
- Close the log entry with what was sent, what was withheld and why, and the date.
On fees, the ICO's position is short: "In most cases, you cannot charge a fee." A reasonable fee for administrative costs is possible only where a request is manifestly unfounded or excessive, or for further copies.
Schools. Personal data about a pupil belongs to the pupil, and the ICO's education information guidance says "it is the pupil's right to make a SAR"; a parent can make one on the child's behalf only if the child is not competent to act for themselves or has consented. Separately, in maintained schools in England a parent has a right under the Education (Pupil Information) (England) Regulations 2005 to see their child's educational record, answered "within 15 school days". The two rights run on different clocks, and the policy should say which one a parent's request is being handled under.
Subject access request exemptions, and when you can refuse
The exemptions are in Schedules 2 to 4 of the Data Protection Act 2018, and the ICO's page on exemptions relevant to SARs describes each. The governing rule is that "You cannot routinely rely on exemptions or apply them in a blanket fashion." Where an exemption applies, it applies to specific personal information, for a reason you can write down, and the rest of the response still goes out. Those that most often arise in schools, charities and care are:
- Information about other people (third parties). You need not disclose information that would identify someone else unless they consent or it is reasonable to disclose it without their consent. This is the exemption that does most of the work in email chains and message threads; our guide to subject access requests and WhatsApp messages walks through the ICO's three-step test and how to redact a group chat.
- Legal professional privilege. Advice from your solicitor about the requester, and documents prepared for litigation.
- Confidential references. A reference given in confidence about the person's employment, education or volunteering.
- Management information. Management forecasting or planning, such as a proposed restructure, to the extent disclosure would prejudice the business.
- Negotiations with the requester. A record of your intentions in negotiations with that person, such as a settlement position, to the extent disclosure would prejudice them.
- Crime. Where disclosure would be likely to prejudice the prevention or detection of crime, for example while the police are investigating.
- Serious harm: education, health and social work data. Where complying "would likely cause serious harm to the physical or mental health of any person", with specific conditions for each kind of data, including when a health professional must be consulted.
- Child abuse data. Where a request is made on a child's behalf by someone with parental responsibility and disclosure would not be in the child's best interests.
- Exam scripts and marks. Candidates have no right to a copy of their exam answers, and there are special rules on the timing of marks.
Separately from the exemptions, you may refuse a request, or charge a reasonable fee, if it is manifestly unfounded or excessive. The ICO says "there is a high threshold" for this, that you need "strong justifications that can be clearly explained to the person", and that "The purpose behind a request is not relevant in considering whether a request is valid". A request made in the middle of a grievance or a dispute is not manifestly unfounded for that reason alone.
When you withhold anything or refuse, tell the person the reasons, their right to complain to you and to the ICO, and their ability to seek to enforce the right through the courts. Under the Data (Use and Access) Act, organisations must also have a way for people to complain about how their data is used; the ICO says complaints must be acknowledged within 30 days. The subject access request policy should point to that procedure rather than duplicate it.

The SAR log, and the record of each response
The response to a subject access request is itself a record the organisation may have to defend, to the requester, to the ICO or in a tribunal where the request was the opening move in a dispute. Keep a log, and keep a response file for each request.
Ref SAR-2026-014 · Received 2 September 2026, verbally at reception, from a former teaching assistant; confirmed in writing 3 September · ID: work email and staff number matched, no documents requested · Clarification: none needed · Systems searched: HR file, payroll, email (staff mailboxes of line manager, head, business manager), Teams chats, staff messaging service, CCTV (none held) · Not searched: personal phones of two colleagues, who were asked to search and confirmed no work messages about her · Exemptions: third-party information redacted in 11 emails (reasons recorded); one confidential reference withheld · Response sent 29 September 2026, encrypted email, with supplementary information · Complaint: none.
The row shows the clock, the search, what was not searched and why, and each decision to withhold. That is the evidence that the search was reasonable and proportionate.
Keep the response file, what was disclosed and what was withheld with the reasons, for a set period in your retention schedule; a common approach is to keep it for as long as a complaint or claim about the response could reasonably arise. Review the log each term or quarter: patterns of late responses, repeated difficulty finding the same kind of information, or searches that always have to go outside the organisation's own systems are the policy telling you what to fix.
The search the policy cannot finish
Most subject access request policies list the systems to be searched: the personnel file, the pupil record, the care record, email. What the list rarely says is where the conversations about the person actually happened. The request from a member of staff who has raised a grievance will reach the messages their manager exchanged with HR on a Sunday evening. The request from a parent will reach the staff group in which their child's behaviour was discussed. The request from a resident's son will reach what the night carers said about his mother. Those are the pieces a requester most wants, and often already has one side of.
The ICO's guidance says you do not usually have to supply information that someone else holds on their own systems, but it makes an exception where staff have stored the requester's personal information on their personal devices: if you have good reason to think they have, you "should ask them to search their private emails, devices or instant messaging applications, as appropriate". "Reasonable and proportionate" is judged on the circumstances; it is not a way of setting aside a place where the organisation knows its staff discuss the people it serves. The practical result is a search that depends on colleagues' goodwill and cannot reach anyone who has left.
ComplyChat is built so that the organisation's work conversations are in its own record before a request arrives. Messages in a ComplyChat channel are recorded on the server as they are sent, everyone added is told the channel is on the record, and a mobile number verified by SMS is an identity, so staff without a work account, volunteers and families can be in the conversation. On paid plans the lasting record files into your own Microsoft 365 once your tenant is connected, where your subject access searches already reach, under your own retention rules. It does not reach conversations held elsewhere, and it does not answer the request for you: the exemptions and redactions are still your decisions. ComplyChat Free is one private group, direct messages, up to 25 staff and three calendar months of recent history, with no Microsoft 365 archive.
A question for the next leadership or board meeting: in your last three subject access requests, which of the conversations about the person did your search reach, and which did you have to ask colleagues to look for on their own phones?
Official guidance and your next step
The ICO's right of access guidance is the authority, and the pages linked above cover each step. For the 2025 changes, read the ICO's summary of the data protection changes and the government's guidance on the Act. The Data (Use and Access) Act 2025 amended UK GDPR and the Data Protection Act 2018 in stages and the ICO has been updating its guidance to match, so check the date on any ICO page you rely on. Quotations here are from those pages as published on 25 September 2026. Schools should also read the Department for Education's data protection in schools guidance.
This guide is general information for UK schools, charities and care providers, not legal advice. A request connected to a grievance, a claim or a safeguarding matter is one to take advice on.
One step to take this term: write down, for your organisation, every place a conversation about a member of staff, a pupil or a resident could be held, and mark which of them your SAR procedure actually searches. Then give the list to whoever handles your next request.
Most of the difficulty in a subject access request is the search, and most of the difficulty in the search is conversations held where the organisation cannot reach them. We build ComplyChat so that work conversations sit in the organisation's own record from the first message, and we would rather every policy named that gap honestly than discovered it on the clock.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- Data (Use and Access) Act 2025 legislation.gov.uk
- Preparing for a subject access request ico.org.uk
- Recognising a request ico.org.uk
- What to consider when responding to a request ico.org.uk
- Finding and retrieving the information ico.org.uk
- Education information guidance ico.org.uk
- Exemptions relevant to SARs ico.org.uk
- Right of access guidance ico.org.uk
- Summary of the data protection changes ico.org.uk
- Guidance on the Act gov.uk
- Data protection in schools gov.uk


