Subject Access Request Check: Ensure UK GDPR Compliance
Review your data processes to avoid fines and streamline DSAR responses with our expert compliance gap analysis
A clear, compliant Subject Access Request (SAR) process is no longer optional. Since the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018 (DPA2018) came into force, individuals have the right to access their personal data held by organisations—without charge in most cases and within strict deadlines. For small businesses, landlords, letting agents, and service providers, a single mishandled SAR can lead to complaints to the Information Commissioner’s Office (ICO), reputational damage, or even enforcement action.
Yet many organisations still treat SARs as an afterthought. Response deadlines are missed, identity checks are skipped, or exemptions are misapplied—often because internal policies and documents aren’t aligned with the law. A Subject Access Request Check document (such as a SAR policy, response template, or internal procedure) is the first line of defence. If it’s unclear, incomplete, or outdated, the risk of non-compliance rises sharply.
This guide explains how to audit your SAR documents for compliance, what the law actually requires, and where the most common gaps appear. Whether you’re a letting agent handling tenant data, a small business processing customer records, or a freelancer managing client information, getting this right protects you—and your reputation.
Is your data subject access request check document in good shape?
A strong SAR check document does more than list legal requirements—it guides your team through every step of a request, from receipt to response. A well-structured document should:
- Clearly define what counts as a valid SAR (scope)
- Set a realistic internal deadline (well before the legal 30-day limit)
- Include a secure, proportionate identity verification process
- List lawful exemptions (with examples relevant to your sector)
- Provide template responses for common scenarios
If your current document is vague, missing key sections, or hasn’t been updated since 2018, it’s time for a review.
UK GDPR and the Data Protection Act 2018 — plain English
The Data Protection Act 2018 (DPA2018) and UK GDPR give individuals the right to access their personal data held by organisations. This is called a Subject Access Request (SAR). The law doesn’t require requests to be made in writing—verbal requests count too, which is why clear internal procedures matter.
Key legal requirements for SARs
- No fee (usually): You can’t charge for providing the data unless the request is manifestly unfounded or excessive (e.g., repeated requests for the same information).
- 30-day response deadline: You must respond without undue delay, and in any case within one month of receiving the request. This can be extended by two months for complex requests, but you must notify the individual within the first month.
- Identity verification: You must be reasonably sure the requester is who they claim to be. However, you can’t demand excessive proof—a passport or utility bill is usually enough.
- Exemptions apply: Some data doesn’t have to be disclosed, such as legal professional privilege, management forecasts, or information that would reveal someone else’s personal data without their consent.
Who must comply?
- Businesses of all sizes (including sole traders)
- Landlords and letting agents (tenant data, references, deposit records)
- Service providers (customer records, contracts, communications)
- Employers (employee data, performance reviews, disciplinary records)
If you process personal data, you must have a SAR process in place—even if you’ve never received a request.
Five privacy-document checks organisations miss
A Subject Access Request Check document should cover these five critical areas. If any are missing or unclear, your compliance is at risk.
1. SAR scope: What counts as a valid request?
Why it matters: Not every question about data is a SAR. If your document doesn’t define scope clearly, you might waste time responding to non-SARs or miss legitimate requests.
What the law says:
- A SAR is any request where an individual asks for their personal data (e.g., "Please send me all the information you hold about me").
- It doesn’t have to mention "SAR" or "GDPR"—verbal requests count too.
- You don’t have to comply if the request is manifestly unfounded or excessive (e.g., repeated requests for the same data without reason).
Practical tip:
- Include examples of valid and invalid SARs in your document. For instance:
- ✅ "Please send me all emails you have about my tenancy."
- ❌ "Why did you reject my rental application?" (This is a complaint, not a SAR.)
- Train staff to flag potential SARs even if they’re not in writing.
VetroCheck can help: Our Subject Access Request Check flags unclear scope definitions in your document and suggests wording to align with DPA2018.
2. Response deadline: Are you leaving it too late?
Why it matters: The 30-day deadline starts the day you receive the request (or the day you verify identity, if that’s later). Many organisations underestimate how long it takes to gather data, especially if it’s spread across emails, spreadsheets, and third-party systems.
What the law says:
- You must respond without undue delay, and in any case within one month.
- If the request is complex, you can extend the deadline by two months, but you must notify the requester within the first month and explain why.
- Bank holidays and weekends don’t pause the clock—the deadline is calendar days, not working days.
Practical tip:
- Set an internal deadline of 20 days to allow time for delays.
- Document where data is stored (e.g., CRM, email archives, cloud storage) so you can retrieve it quickly.
- If you need an extension, email the requester before day 30—don’t wait until the last minute.
VetroCheck can help: Our check highlights unrealistic deadlines in your document and suggests adjustments to avoid last-minute rushes.
3. Identity verification: Are you asking for too much—or too little?
Why it matters: If you skip identity checks, you risk disclosing data to the wrong person. If you demand excessive proof, you could breach the law by making the process unnecessarily difficult.
What the law says:
- You must be reasonably sure the requester is who they claim to be.
- You can’t demand unnecessary or intrusive proof (e.g., a passport for a low-risk request).
- If the requester has already verified their identity (e.g., through an online portal), you may not need to ask again.
Practical tip:
- Create a tiered verification system based on risk:
- Low risk (e.g., a tenant requesting their own tenancy agreement): Email from a known address + one piece of ID (e.g., utility bill).
- High risk (e.g., a former employee requesting sensitive HR data): Passport or driving licence + additional checks.
- Never ask for more than necessary—if a utility bill is enough, don’t demand a passport.
VetroCheck can help: Our review checks if your identity verification process is proportionate and flags overreach or gaps.
4. Exemptions: Are you applying them correctly?
Why it matters: Some data doesn’t have to be disclosed in a SAR, but exemptions are narrow and specific. If your document lists exemptions vaguely (e.g., "we don’t have to disclose confidential data"), you risk over-applying them and breaching the law.
What the law says: Common exemptions include:
- Legal professional privilege: Data covered by solicitor–client confidentiality.
- Management forecasts: Information about future business plans (e.g., restructuring).
- Third-party data: Information that would reveal someone else’s personal data without their consent.
- Crime prevention: Data that could prejudice a criminal investigation.
Practical tip:
- List exemptions with examples relevant to your sector. For example:
- Letting agents: "We may withhold references from other landlords if they contain personal data about the referee."
- Employers: "We may redact disciplinary notes if they include personal data about another employee."
- Document your reasoning if you withhold data—you may need to justify it to the ICO.
VetroCheck can help: Our check identifies missing or misapplied exemptions in your document and suggests sector-specific examples.
5. Template responses: Are you prepared for common scenarios?
Why it matters: A standardised response saves time and reduces errors. If your document doesn’t include templates, your team might miss key details (e.g., the right to complain to the ICO) or use inconsistent language.
What the law says:
- You must include:
- A confirmation that you’re processing the request.
- The data you’re providing (or an explanation if you’re withholding some).
- The right to complain to the ICO if the requester is unhappy.
- Contact details for follow-up questions.
Practical tip:
- Create three template responses:
- Acknowledgement email (sent within 24 hours of receiving the request).
- Full response (sent within the deadline, with the data attached).
- Extension notice (if you need more time).
- Personalise templates for your sector (e.g., letting agents should include tenancy-specific details).
VetroCheck can help: Our review flags missing template elements and suggests compliant wording.
Data-protection mistakes that create complaint risk
Even well-meaning organisations make these three costly errors when handling SARs:
1. Ignoring verbal requests
What happens: A tenant asks for their data in person or over the phone, but the request isn’t logged. 30 days later, the tenant complains to the ICO, and the organisation is found in breach for failing to respond. Consequence: A formal reprimand from the ICO, plus reputational damage.
2. Demanding excessive ID
What happens: A small business asks a customer to post a certified copy of their passport for a low-risk SAR (e.g., a copy of their invoice). The customer complains to the ICO, arguing the process was unnecessarily difficult. Consequence: The ICO rules the request was mishandled, and the business must reprocess it under supervision.
3. Missing the deadline without notifying the requester
What happens: A letting agent receives a SAR but forgets to set a reminder. On day 31, the tenant emails to ask where their data is. The agent panics and sends an incomplete response, missing key documents. Consequence: The tenant complains to the ICO, which issues a warning and orders the agent to redo the process at their own expense.
FAQ
What does the Subject Access Request Check: compliance and gap review review?
The Subject Access Request Check is an information-only audit of your data subject access request check document (e.g., SAR policy, response template, or internal procedure). It focuses on four key areas:
- SAR scope: Does your document clearly define what counts as a valid request?
- Response deadline: Are your deadlines realistic and legally compliant?
- Identity verification: Is your process secure but not overly intrusive?
- Exemptions: Are you applying exemptions correctly and with clear examples?
Each finding is backed by a citation from your document, so you can see exactly where improvements are needed.
Which legal sources are used in the review?
The analysis is based on the Data Protection Act 2018 (DPA2018) and UK GDPR. These are the primary legal frameworks governing Subject Access Requests in the UK. Where relevant, we also reference ICO guidance to ensure your document aligns with best practice.
Which specific points are checked?
The agent checks the following (among others):
- SAR scope: Does your document define valid requests clearly? Are examples provided?
- Response deadline: Does your document set a realistic internal deadline (e.g., 20 days) to avoid last-minute rushes?
- Identity verification: Does your process balance security with proportionality?
- Exemptions: Are exemptions listed with sector-specific examples (e.g., for letting agents or employers)?
- Template responses: Does your document include compliant templates for acknowledgements, full responses, and extensions?
Each finding is linked to a specific part of your document, so you can see exactly where changes are needed.
Which documents can I upload?
The Subject Access Request Check accepts PDF files up to 20 MB. Suitable documents include:
- SAR policies or procedures
- Response templates (e.g., acknowledgement emails, full responses)
- Internal guidance for staff handling SARs
- Data protection impact assessments (DPIAs) that mention SARs
If your document is in Word or another format, convert it to PDF before uploading.
How much does the review cost and how long does it take?
The full analysis costs £12.99. Results are usually ready within a few minutes as a downloadable PDF report. The report includes:
- A compliance score for your document
- Specific gaps with page references
- Actionable recommendations to fix issues
Check your privacy paperwork — £12.99
Your next steps
- Locate your SAR document (policy, template, or procedure).
- Check it covers the five key areas (scope, deadline, identity verification, exemptions, templates).
- Upload it to VetroCheck for a compliance and gap review.
- Review the report and make the recommended changes.
- Train your team on the updated process.
How VetroCheck helps
- Fast, affordable checks: For just £12.99, you get a detailed audit of your SAR document in minutes.
- Sector-specific insights: Our analysis includes examples tailored to letting agents, small businesses, and employers.
- No legal jargon: We explain gaps in plain English, so you can fix them quickly.
- Peace of mind: Know your SAR process is compliant with DPA2018 before the ICO comes knocking.
VetroCheck is not a law firm and is not SRA-regulated. Our reviews are information-only and do not constitute legal advice. For legal advice, consult a qualified solicitor.
Get your Subject Access Request Check now
Also see the agent topic page for statute themes and related checks.
Check your document now — £12.99
Upload your PDF for a structured review. One-time analysis from £12.99 — not legal advice.