Preparing secure exchange

01 Anonymise02 Shard03 Restore

Initialising protected session

How to Handle Subject Access Requests Without Losing Control

A subject access request can arrive through an inbox, a phone call, a social media message or an ordinary conversation with a member of staff. The request does not need to mention UK GDPR or use the words…

In this guide

A subject access request can arrive through an inbox, a phone call, a social media message or an ordinary conversation with a member of staff. The request does not need to mention UK GDPR or use the words "subject access request". If someone is clearly asking for their own personal information, your organisation may already be on the clock.

Handling the request well depends on control at every stage: recognition, identity checking, search, review, redaction and disclosure. Treating it as a frantic document hunt usually creates duplication, missed deadlines and a serious risk of releasing information about somebody else.

RecogniseCapture requests wherever they enter the organisation.
ScopeConfirm identity, authority and what information is sought.
ReviewSeparate relevant personal data from unrelated material.
DiscloseDeliver the response securely and retain evidence.

Under the right of access, an individual can ask whether you are processing their personal data, obtain a copy of that data and receive supporting information about how it is used. The Information Commissioner's Office (ICO) explains that requests may be made verbally or in writing, can reach any part of the organisation and usually need a response without undue delay and within one month. Its guide to subject access is a useful reference for the legal detail.

Do not wait for a formal form.A standard form can make requests easier to manage, but an individual cannot normally be required to use it. Reception teams, managers, customer service staff and social media administrators all need to know how to recognise a possible request and pass it to the correct owner.

WorkflowOne controlled case record

Build the response around a clear chain of custody

01

Log the request immediately

Record when it arrived, how it was received, the requester's contact details, the wording used and the person responsible for the case. Calculate the deadline and create reminders before any searching begins.

02

Confirm identity and authority

Check identity only to the degree needed for the risk. Asking a known employee for excessive documents can be disproportionate. A third party acting for someone else should provide suitable evidence of authority before personal data is released.

03

Clarify a broad or unclear request

Where your organisation holds a large amount of information and cannot reasonably identify what is wanted, ask focused questions about dates, teams, systems, incidents or document types. Clarification should help the requester, not create an obstacle.

04

Issue a structured search plan

Name the systems, custodians and locations to be searched. That may include HR platforms, CRM records, shared drives, email, call recordings, messaging tools, archives, paper records and information held by processors on your behalf.

05

Collect into a restricted workspace

Keep gathered material in one access controlled case area. Preserve original files, note their source and avoid emailing working copies between reviewers. The case record should show who supplied each item and what happened to it.

06

Review, redact and quality check

Identify the requester's personal data, remove duplicates and consider third party information, confidentiality and any relevant exemption. A second reviewer should check difficult redactions and confirm that hidden text or document metadata cannot be recovered.

07

Approve and disclose securely

Confirm the delivery address or account, provide the data in an intelligible form and include the required supporting information. Record the exact package released, the approval decision, the delivery method and the date sent.

The deadline deserves active management. A complex request, or several requests from the same person, may justify an extension of up to a further two months. The individual must be told within the original one month period and given the reason. Current ICO guidance on responding to a request also explains when clarification can pause the response clock, although information that can reasonably be supplied without clarification may still be due. These decisions should sit with a trained owner rather than being improvised by whichever team holds the most records.

Search controlFind what relates to the person

A complete search does not mean exporting every file with their name in it

A common mistake is to confuse keyword matches with responsive personal data. An employee may be copied into thousands of routine emails, but the whole contents of each email will not automatically be their personal data. Context matters. The review must establish what information relates to the individual, what is merely present in the same record and what falls outside the request.

Search terms still help, especially when combined with email addresses, employee numbers, customer references, date ranges and project names. Keep the method reproducible. Record which systems were checked, who searched them, the terms used, the date of the search and any limitation that affected the result. This creates a defensible account of a reasonable and proportionate search rather than a vague statement that "IT checked the emails".

Control pointWeak approachBetter evidence
Request intakeForwarded through several inboxesCentral log with receipt date, owner and deadline
SearchInformal messages asking teams to "send everything"Documented systems, custodians, terms and results
RedactionOne reviewer edits the only working copyPreserved source, review copy and quality check
DisclosureLarge attachment sent to an unverified addressNamed recipient, secure access and delivery record

Good records also expose information governance problems. Repeated difficulty locating data may point to poor naming, unclear retention, uncontrolled exports or personal information scattered across private mailboxes. The SAR process can therefore become a practical test of the wider governance programme. The article on building a reliable file audit trail explains why activity evidence matters beyond an individual request.

ReviewDisclosure needs judgement

Redaction is a decision process, not a black marker

Third party data is often the hardest part of a response. Meeting notes, complaint records and email threads may contain intertwined information about several people. The aim is still to provide the requester's personal data where possible, while considering whether disclosing another person's information is reasonable. Consent, confidentiality, the nature of the information and its importance to the requester may all affect that decision.

Exemptions must be applied to the information concerned, not used as a blanket reason to hold back a whole file. Legal professional privilege, confidential references and certain management information are examples that may be relevant in particular circumstances. Document the exemption considered, the material affected, the reason it applies and who approved the decision. Seek specialist legal advice where the position is uncertain.

Before approving the response package

  • Check the scope. Make sure the response matches the clarified request and that obvious systems or date ranges have not been missed.
  • Test every redaction. Copy and paste from redacted PDFs, inspect comments, layers, tracked changes, filenames and document properties.
  • Remove unrelated duplicates. A large, disorganised dump can obscure the personal data and create avoidable disclosure risk.
  • Include the supporting information. Explain purposes, categories, recipients, retention and relevant rights in clear language.
  • Verify the destination. A careful search can still end in a breach if the final package goes to the wrong address.

This is also where data classification helps. Teams that can distinguish routine internal information from personal, confidential or highly sensitive material are better placed to choose the right reviewers and controls. See the practical guide to identifying sensitive files for a useful starting point.

DisclosureKeep control of the final handoff

The response is still sensitive after the review is complete

A finished SAR package may contain payroll information, health details, complaint material, addresses, identifiers and internal correspondence. Ordinary email attachments and open links may provide too little assurance for that handoff, particularly where the organisation cannot confirm who accessed the material or whether the link was forwarded.

My MX Data is a secure B2B file exchange platform designed for controlled delivery to named recipients. MX can support a disclosure workflow with recipient based access, multi factor authentication, expiry settings and an activity record showing what happened during the exchange. That can help the organisation retain evidence of delivery without treating the SAR package as a permanent collaboration space.

"

The organisation should be able to show not only what it disclosed, but who approved it, who received it and when access occurred.

SAR disclosure principle

Technology does not decide whether information should be disclosed, make redaction decisions or make an organisation compliant. Those responsibilities remain with the controller and its trained staff. A controlled business to business file exchange can, however, make the final delivery more consistent, visible and easier to evidence.

FAQsPractical points

Common questions about handling a SAR

They do not normally have to explain their reason. You may ask helpful questions to clarify the information sought, especially where the request is broad or unclear, but clarification should not be used to discourage the request.

Information that remains readily accessible, including material sitting in a deleted items folder, may still need to be searched. The ICO does not generally expect organisations to use extreme technical measures to reconstruct data that was genuinely deleted through normal records management.

Not necessarily. One accountable owner should control the case, while system owners, HR, legal, security and operational teams contribute where needed. Escalation criteria should cover complex scope, sensitive data, disputed identity, third party information and possible exemptions.

Legal noteThis article offers practical operational guidance and is not a substitute for legal advice. Organisations should apply current UK data protection law, ICO guidance and any sector specific duties relevant to the request.

Michael Byrne
Written by

Michael Byrne

I'm a dynamic professional with extensive experience in project and business management across automotive, construction, and aerospace sectors. Currently, as Head of Digital at Majenta, I lead transformative projects, focusing on maintaining and enhancing MX as a high-performance file sharing platform. My role involves strategic project delivery and aligning digital initiatives with core business values. I excel in stakeholder management, problem-solving, and fostering strategic partnerships. Passionate about continuous learning, I thrive in high-pressure environments and enjoy contributing to MX's market presence through innovative solutions and robust project execution.

Advanced Features
MYMXDATA

Give sensitive files a clearer, more defensible route.

Start a seven-day trial with named-user access, detailed audit trails, unlimited file sizes and the patented ASR methodology.