Gdpr request (UK)
A GDPR request, formally known as a Subject Access Request (SAR), is a data subject's exercise of the right under UKGDPR Article 15 to obtain confirmation of whether personal data concerning them is being processed and, if so, to receive a copy of that data along with specified information about the processing under UK law. This right enables individuals to understand what information organisations hold about them and how it is used, subject to certain exemptions and conditions set out in the DPA2018 and UKGDPR framework.
What data protection covers
A Subject Access Request (SAR) is a mechanism established under the UK General Data Protection Regulation (UKGDPR) and the Data Protection Act 2018 (DPA2018) that allows individuals to request access to their personal data held by organisations. Under UKGDPR Article 15, data subjects may have a right to obtain confirmation as to whether their personal data is being processed and, where applicable, access to that data along with detailed information about the processing activities. This includes the purposes of processing, categories of data involved, recipients of the data, storage periods, and any automated decision-making logic applied. The framework provides for this right to apply regardless of whether the data was collected directly from the individual or from another source. Organisations acting as data controllers are required to respond to SARs without undue delay and within one month of receipt, although extensions are permitted in specific circumstances under DPA2018 provisions. The scope of information that must be provided is delineated in UKGDPR Article 15(1) and includes safeguards for international data transfers.
Key legal requirements
- The request must be made in writing or another durable form and clearly identify the data subject, though no specific form is mandated under UKGDPR Article 12.
- Data controllers must provide confirmation of processing and a copy of the personal data within one month of receipt, extendable by up to two further months for complex or numerous requests as permitted by UKGDPR Article 12(3).
- The response must include all requested information specified in UKGDPR Article 15(1), such as processing purposes, data categories, recipients, storage periods, and details of automated decision-making.
- Organisations may refuse or charge a reasonable fee for manifestly excessive or repetitive requests, provided they demonstrate the request's unreasonableness under UKGDPR Article 12(5).
- Controllers must verify the identity of the requester where necessary to prevent unauthorised disclosure, in line with data protection principles under UKGDPR Article 5.
- Requests for third-party data must be handled with care to avoid disclosing information that would adversely affect the rights and freedoms of others, as outlined in DPA2018 Schedule 2 paragraph 1.
Why this matters
Failure to comply with a GDPR request can expose organisations to significant risks, including regulatory enforcement action by the Information Commissioner's Office (ICO) under the DPA2018 and UKGDPR. The ICO may issue assessment notices, enforcement notices, or penalty notices where organisations fail to respond appropriately, potentially resulting in substantial fines under DPA2018 s.164A and s.165. Inadequate or delayed responses may also lead to reputational damage, loss of customer trust, and potential civil claims for compensation under UKGDPR Article 82, particularly if the data subject suffers harm due to the breach. Organisations that mishandle SARs risk undermining transparency obligations and may face challenges in demonstrating compliance with accountability principles under UKGDPR Article 5(2). Poor record-keeping or failure to provide requested information can also hinder an organisation's ability to defend its processing activities during regulatory investigations or legal disputes. Additionally, non-compliance may result in negative publicity and operational disruptions, particularly where SARs relate to high-risk processing activities or involve large volumes of data. Under UK law, the framework for handling SARs is designed to balance individual rights with organisational responsibilities, and deviations from these requirements can have serious consequences for data controllers.
Next step with VetroCheck
Use the Subject Access Request agent if you want a structured review of the relevant documents and supporting record.
Related reading
Compliance note
This glossary content is provided for informational and educational purposes only. It does not constitute formal legal advice, does not create a solicitor-client relationship, and should be checked against current legislation, official guidance, and the facts of the specific case.
At a glance
- Definition
- A GDPR request, formally known as a Subject Access Request (SAR), is a data subject's exercise of the right under UKGDPR Article 15 to obtain confirmation of whether personal data concerning them is being processed and, if so, to receive a copy of that data along with specified information about the processing under UK law. This right enables individuals to understand what information organisations hold about them and how it is used, subject to certain exemptions and conditions set out in the DPA2018 and UKGDPR framework.
- Term
- Gdpr request (UK)
- Category
- Public Law
- Published
- Keywords
- UK, Public Law, public