ComplyChat Start free

Guide · Data protection

Subject access request policy

Anyone can ask an organisation for a copy of the personal data it holds about them, in any words, to any member of staff, and the clock starts when the request arrives. A subject access request policy is how a school, a charity or a care provider makes sure the request is recognised, logged, searched for properly, answered on time and recorded. This guide sets out what the policy should cover, how to respond step by step, which exemptions can apply, and what the Data (Use and Access) Act 2025 changed about searches and the time limit.

By ComplyChatPublished 13 minute read

A school data protection lead walking across a sunny academy car park with a lever-arch file under her arm, talking to the headteacher beside her
01

The right of access, and why the policy matters

In short

Respond without undue delay and within one month of receipt. You can extend by up to two further months for a complex request, if you tell the person why within the first month. You can pause the clock while you ask for clarification that is reasonably required. You must make a reasonable and proportionate search. In most cases you cannot charge a fee.

The policy's job is to make those rules happen in your organisation: who recognises a request, who logs it, which systems are searched, who decides on exemptions, and what record is kept of each response.

The right of access is in Article 15 of the UK General Data Protection Regulation (UK GDPR). A request under it is usually called a subject access request (SAR), sometimes a data subject access request (DSAR). A person, the data subject, is entitled to confirmation that the organisation is processing their personal data, a copy of that data, and supplementary information about the processing. The exemptions sit in the Data Protection Act 2018. Both have been amended by the Data (Use and Access) Act 2025, whose data protection changes were brought into force in stages; the ICO's summary, dated 19 June 2026, says all of them are now in force.

The law does not require a document called a subject access request policy. It does require the organisation, as data controller, to comply and to be able to show how it complies, and for anything larger than a very small charity that means writing the procedure down. The ICO's guidance on preparing for a subject access request is effectively a checklist for one. Maintained schools and academies, as public authorities, must appoint a data protection officer, and the policy should name that role; charities and care providers that have not appointed one should name whoever leads on data protection.

A subject access request policy usually sits alongside the data protection policy and the retention schedule, and is written using clear and plain language, because it is read by staff who will receive requests and often published for the people who make them.

02

What the policy should cover

A useful subject access request procedure answers each of these for your organisation, by role rather than by name so it survives staff changes:

  1. Scope. Who can make a request (staff, former staff, volunteers, pupils, parents, residents, families, donors, anyone), and that it covers all personal data held, in every system: files, email, databases, CCTV, and work messages wherever they are held.
  2. Recognising a request. A request can be made verbally or in writing, including via social media, to any member of staff, and does not have to mention "subject access" or the law. A verbal request is as valid as a written one; write it down and, if you can, confirm it back to the individual making the request. You may offer a subject access request form, but a request is valid without one. The ICO's page on recognising a request is worth giving to every receptionist and team leader.
  3. Logging and passing on. The date of receipt, and who it goes to, the same day.
  4. Identity and authority. When to ask for proof of identity, and what is proportionate; how to check that someone requesting on another's behalf, a solicitor or a relative, is authorised.
  5. Clarification. When asking the requester what they want is reasonably required, and how the pause in the clock is recorded.
  6. Searching. Which systems are searched, by whom, and how the organisation decides what is reasonable and proportionate.
  7. Exemptions and third parties. Who decides whether information is withheld, and how the reasons are recorded.
  8. The response. What is sent, in what format, how securely, and who signs it off.
  9. Refusals, fees and extensions. When a request may be treated as manifestly unfounded or excessive, and who decides.
  10. Complaints. How the person can complain to the organisation and to the ICO.
  11. Records and review. The SAR log, how long response files are kept, and when the policy is reviewed.

Schools should add two things that apply only to them: a pupil's own right of access, and the separate right of a parent to see their child's educational record, both covered in section 03.

03

Responding to a subject access request, step by step

The ICO's guidance on what to consider when responding to a request sets out the timings. In order:

  1. Log the date of receipt. You "must comply with a SAR without undue delay and at the latest within one month of receipt of the request". The month runs to the corresponding date in the next month; if that falls on a weekend or bank holiday, the deadline is the next working day.
  2. Check the identity of the data subject if you need to. Be "reasonable and proportionate about what you ask for"; a member of staff emailing from their work account rarely needs to send a passport. The clock does not start until you have the information you reasonably need to confirm identity or authority.
  3. Clarify only where it is reasonably required. Since the Data (Use and Access) Act, the ICO's guidance says that when you ask for clarification "the time limit pauses on the day you request clarification and resumes on the day after you receive it". It is not to be used on a blanket basis, and you should still search for what the request clearly covers.
  4. Search. "You must make a reasonable and proportionate search to respond to a SAR." The ICO's page on finding and retrieving the information lists what bears on that: "the circumstances of the request; the volume of information you may need to search in order to respond; any difficulties involved in finding the information; and the fundamental nature of the right of access." Record what you searched for the information requested, and why you stopped where you did.
  5. Decide on extension early. If the request is complex, or the person has made a number of requests, you may extend by up to two further months, but you "must let the person know that you are extending the time limit and explain your reasons why within one month".
  6. Apply exemptions item by item, and redact other people's information where required (section 04).
  7. Send the response. The personal data, and the supplementary information Article 15 requires: the purposes of processing, the categories of data, the recipients, the retention period or how it is decided, the rights to rectification, erasure, restriction and objection, the right to complain to your organisation and to the ICO, the source of the data if not from the person, and any automated decision-making. If the request was made electronically, provide the information in a commonly used electronic form unless the person asks otherwise.
  8. Close the log entry with what was sent, what was withheld and why, and the date.

On fees, the ICO's position is short: "In most cases, you cannot charge a fee." A reasonable fee for administrative costs is possible only where a request is manifestly unfounded or excessive, or for further copies.

Schools. Personal data about a pupil belongs to the pupil, and the ICO's education information guidance says "it is the pupil's right to make a SAR"; a parent can make one on the child's behalf only if the child is not competent to act for themselves or has consented. Separately, in maintained schools in England a parent has a right under the Education (Pupil Information) (England) Regulations 2005 to see their child's educational record, answered "within 15 school days". The two rights run on different clocks, and the policy should say which one a parent's request is being handled under.

04

Subject access request exemptions, and when you can refuse

The exemptions are in Schedules 2 to 4 of the Data Protection Act 2018, and the ICO's page on exemptions relevant to SARs describes each. The governing rule is that "You cannot routinely rely on exemptions or apply them in a blanket fashion." Where an exemption applies, it applies to specific personal information, for a reason you can write down, and the rest of the response still goes out. Those that most often arise in schools, charities and care are:

  • Information about other people (third parties). You need not disclose information that would identify someone else unless they consent or it is reasonable to disclose it without their consent. This is the exemption that does most of the work in email chains and message threads; our guide to subject access requests and WhatsApp messages walks through the ICO's three-step test and how to redact a group chat.
  • Legal professional privilege. Advice from your solicitor about the requester, and documents prepared for litigation.
  • Confidential references. A reference given in confidence about the person's employment, education or volunteering.
  • Management information. Management forecasting or planning, such as a proposed restructure, to the extent disclosure would prejudice the business.
  • Negotiations with the requester. A record of your intentions in negotiations with that person, such as a settlement position, to the extent disclosure would prejudice them.
  • Crime. Where disclosure would be likely to prejudice the prevention or detection of crime, for example while the police are investigating.
  • Serious harm: education, health and social work data. Where complying "would likely cause serious harm to the physical or mental health of any person", with specific conditions for each kind of data, including when a health professional must be consulted.
  • Child abuse data. Where a request is made on a child's behalf by someone with parental responsibility and disclosure would not be in the child's best interests.
  • Exam scripts and marks. Candidates have no right to a copy of their exam answers, and there are special rules on the timing of marks.

Separately from the exemptions, you may refuse a request, or charge a reasonable fee, if it is manifestly unfounded or excessive. The ICO says "there is a high threshold" for this, that you need "strong justifications that can be clearly explained to the person", and that "The purpose behind a request is not relevant in considering whether a request is valid". A request made in the middle of a grievance or a dispute is not manifestly unfounded for that reason alone.

When you withhold anything or refuse, tell the person the reasons, their right to complain to you and to the ICO, and their ability to seek to enforce the right through the courts. Under the Data (Use and Access) Act, organisations must also have a way for people to complain about how their data is used; the ICO says complaints must be acknowledged within 30 days. The subject access request policy should point to that procedure rather than duplicate it.

Two trustees of a small housing charity reading printed papers side by side at a café table by a window on a grey morning, coats still on
05

The SAR log, and the record of each response

The response to a subject access request is itself a record the organisation may have to defend, to the requester, to the ICO or in a tribunal where the request was the opening move in a dispute. Keep a log, and keep a response file for each request.

A SAR log row – fictional example

Ref SAR-2026-014 · Received 2 September 2026, verbally at reception, from a former teaching assistant; confirmed in writing 3 September · ID: work email and staff number matched, no documents requested · Clarification: none needed · Systems searched: HR file, payroll, email (staff mailboxes of line manager, head, business manager), Teams chats, staff messaging service, CCTV (none held) · Not searched: personal phones of two colleagues, who were asked to search and confirmed no work messages about her · Exemptions: third-party information redacted in 11 emails (reasons recorded); one confidential reference withheld · Response sent 29 September 2026, encrypted email, with supplementary information · Complaint: none.

The row shows the clock, the search, what was not searched and why, and each decision to withhold. That is the evidence that the search was reasonable and proportionate.

Keep the response file, what was disclosed and what was withheld with the reasons, for a set period in your retention schedule; a common approach is to keep it for as long as a complaint or claim about the response could reasonably arise. Review the log each term or quarter: patterns of late responses, repeated difficulty finding the same kind of information, or searches that always have to go outside the organisation's own systems are the policy telling you what to fix.

07

Official guidance and your next step

The ICO's right of access guidance is the authority, and the pages linked above cover each step. For the 2025 changes, read the ICO's summary of the data protection changes and the government's guidance on the Act. The Data (Use and Access) Act 2025 amended UK GDPR and the Data Protection Act 2018 in stages and the ICO has been updating its guidance to match, so check the date on any ICO page you rely on. Quotations here are from those pages as published on 25 September 2026. Schools should also read the Department for Education's data protection in schools guidance.

This guide is general information for UK schools, charities and care providers, not legal advice. A request connected to a grievance, a claim or a safeguarding matter is one to take advice on.

One step to take this term: write down, for your organisation, every place a conversation about a member of staff, a pupil or a resident could be held, and mark which of them your SAR procedure actually searches. Then give the list to whoever handles your next request.

Why we publish this

Most of the difficulty in a subject access request is the search, and most of the difficulty in the search is conversations held where the organisation cannot reach them. We build ComplyChat so that work conversations sit in the organisation's own record from the first message, and we would rather every policy named that gap honestly than discovered it on the clock.

Explore Free · How it works · Compare plans

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. Data (Use and Access) Act 2025 legislation.gov.uk
  2. Preparing for a subject access request ico.org.uk
  3. Recognising a request ico.org.uk
  4. What to consider when responding to a request ico.org.uk
  5. Finding and retrieving the information ico.org.uk
  6. Education information guidance ico.org.uk
  7. Exemptions relevant to SARs ico.org.uk
  8. Right of access guidance ico.org.uk
  9. Summary of the data protection changes ico.org.uk
  10. Guidance on the Act gov.uk
  11. Data protection in schools gov.uk