A former employee emails asking for “all the personal data you hold about me.” A customer contacts you wanting to know what information you have from their account. A job applicant whose application you rejected asks to see their interview notes.

Each of these is a Subject Access Request, and under UK GDPR you have 30 days to respond. There’s no charge you can levy for doing so. And if you ignore it or get it wrong, the ICO can investigate and issue a reprimand — or a fine.

This is the practical guide to handling SARs if you run a small business and haven’t had to deal with one before.

What a Subject Access Request Actually Is

A Subject Access Request is a formal request from an individual (called a “data subject”) to receive a copy of the personal data your organisation holds about them, along with supplementary information about how you’re using it.

“Personal data” covers anything that can identify a living individual, directly or indirectly. That includes names, email addresses, phone numbers, purchase history, employment records, CCTV footage, IP addresses if associated with an individual, call recordings, and communications like emails and messages.

The right to make a SAR comes from Article 15 of UK GDPR. It’s one of the most widely exercised of the data subject rights, and it applies to your business whether you have five employees or five hundred.

Importantly, the requester doesn’t have to call it a “Subject Access Request.” They don’t even have to mention GDPR. If someone asks what data you hold on them, or asks for a copy of records relating to them, you should treat it as a SAR.

The 30-Day Clock

Once you receive a SAR, you have one calendar month to respond — not 30 business days, one calendar month. If the request came in on 15 August, your deadline is 15 September.

You can extend this to three months total if the request is “complex or numerous,” but you must notify the person of the extension within the original one-month window and explain why you need more time. “We’re busy” isn’t a valid reason. Multiple simultaneous SARs, or a request spanning a very large volume of records going back many years, might qualify.

The clock starts when you receive the request, not when you identify it as a SAR. If a message arrives on a Friday evening asking about personal data, Monday isn’t the start date — the Friday is.

Verifying Identity

Before releasing any personal data, you need to be satisfied that the requester is who they say they are. You can ask for verification — but you can only ask for information you actually need to confirm identity, and you can’t use verification requests to delay or obstruct.

For someone you have an existing relationship with (a customer, former employee), you can usually verify identity using account details, employee reference numbers, or other information already in your records. Asking a former customer to provide their driving licence when you have their name, address and email on file is likely disproportionate.

If there’s genuine uncertainty about identity, ask for one or two pieces of identifying information. Document what you asked for and why.

The identity verification period pauses the 30-day clock, but only for as long as it takes to receive the verification. Once you receive it, the clock resumes.

What You Must Include in Your Response

Your response must provide:

A copy of the personal data. All personal data you hold about the individual, in a commonly used and readable format. This doesn’t have to be the original records — it can be a compilation or a summary, as long as it accurately represents all the data you hold.

The purposes for which you’re processing their data. Why are you holding and using their information?

The categories of recipients. Who have you shared their data with, or who will you share it with?

The retention period. How long do you keep their data, or what criteria you use to determine how long to keep it?

Information about their other rights. The right to rectification, erasure, restriction of processing, and the right to complain to the ICO.

The source of the data if you didn’t collect it directly from them.

Most small businesses can cover all of this in a cover letter accompanying the data itself. There’s no required format — clear, plain English is fine.

What You Can Withhold

You don’t have to hand over everything. UK GDPR includes exemptions, and some information can legitimately be withheld:

Third-party data. If your records about the requester also contain personal data about other identifiable individuals, you can redact those individuals’ information — unless they’ve consented to disclosure, or it’s reasonable in the circumstances to disclose without consent. Employment records often involve third parties. Email chains involve other people. Redact accordingly.

Legal professional privilege. Communications with your solicitor relating to actual or anticipated legal proceedings are exempt.

Confidential references. References given in confidence for employment, training or education purposes are exempt.

Management information. Data processed for management forecasting or management planning (like succession planning, redundancy planning) can be withheld if disclosure would prejudice the conduct of business.

Data about third parties’ negotiations. Information about the intentions of a party in negotiating with the data subject can be withheld if disclosure would prejudice those negotiations.

When you withhold information, you should tell the requester that information exists but is being withheld, and under which exemption. Don’t pretend the data doesn’t exist.

Practical Steps for Small Businesses

Most small businesses don’t have a dedicated Data Protection Officer or a sophisticated records management system. Here’s a workable process:

Step 1 — Acknowledge receipt immediately. Send a brief acknowledgment email the same day you receive the request. This documents when the clock started and reassures the requester their request has been received.

Step 2 — Search all your data stores. This is the difficult part. Work through every place you might hold information about this person: your email system, CRM or customer database, accounting software, employee records, cloud storage, CCTV recordings, physical files, WhatsApp messages, shared drives. Small businesses underestimate how dispersed their data is.

Step 3 — Compile and review. Bring together everything you’ve found. Review for third-party data that should be redacted. Identify any exemptions that apply.

Step 4 — Respond in writing. Cover letter explaining the response, accompanied by the data. Keep a copy.

Step 5 — Document everything. Record that you received the request, when, how you responded, and when. You’ll need this if the requester complains to the ICO.

When Things Go Wrong

If you miss the deadline, be transparent about it. Contact the requester, explain the delay, and set a new date. Document what happened. The ICO is more likely to be understanding about a business that tried and fell slightly short than one that ignored the request entirely.

If a requester complains to the ICO that you’ve failed to respond, or that your response was inadequate, the ICO will contact you for your account. Having clear documentation of your process matters here. The ICO’s initial response to most complaints from small businesses is to offer guidance rather than immediately pursue enforcement — but they will check whether you’ve actually complied.

Repeated or wilful failures are treated differently. If you routinely ignore SARs, or deliberately destroy records to avoid having to disclose them, the ICO does have enforcement powers up to £17.5 million or 4% of global turnover (whichever is higher) for serious breaches. In practice, most small business SAR failures result in formal reprimands rather than fines, but those reprimands are published on the ICO’s website.

The One Thing Most Small Businesses Get Wrong

The most common mistake is an incomplete search. Small businesses often respond quickly with customer-facing records and forget about:

  • Emails (searching for the person’s name and email address across your whole inbox)
  • Backup systems that retain old records
  • Accounting software that holds payment and address history
  • CCTV systems — footage is personal data if the person is identifiable
  • Staff WhatsApp groups where the person (often a former employee) may have been discussed
  • Paper records in physical files

A systematic checklist of all your data stores, created before you receive your first SAR, saves a lot of panic when one arrives.


The ICO has a useful Right of access guidance page with detailed guidance including how to handle complex cases. If you’re dealing with a particularly difficult SAR — involving legal proceedings, a disgruntled former employee making requests they’ve signalled they intend to use commercially, or requests you believe are made in bad faith — it’s worth reading the full guidance or taking brief legal advice before responding.