Subject Access Request
(SAR)
A Subject Access Request is a right under UK GDPR allowing any individual to ask an organisation for a copy of all the personal data it holds about them. Organisations must respond within one month (extendable to three months for complex requests) and provide the information free of charge in most cases. The right can be limited where disclosure would adversely affect the rights and freedoms of others.
Under Article 15 of the UK GDPR, data subjects have the right to obtain confirmation of whether their personal data is being processed, access to that data, and supplementary information (including purposes, categories, recipients, and retention periods). Organisations must respond within one calendar month; for complex or numerous requests this can be extended by a further two months with notice. There is no fee for most SARs — a reasonable fee can only be charged for manifestly unfounded or excessive requests. Organisations can refuse clearly unfounded or excessive requests. The response must be provided in an accessible format. If the organisation fails to respond adequately, the individual can complain to the ICO, which can issue enforcement notices. Employees frequently use SARs in the context of disciplinary proceedings or tribunal claims to obtain relevant communications.
In practice, you do not need to use the words "subject access request" or fill in a form. A clear written request for your personal data is enough, and it can be made to any part of the organisation — the clock starts when it is received, not when it reaches the right department. Being specific helps you rather than the organisation: naming date ranges, systems and individuals narrows the search and usually produces a faster, more useful response than a request for "everything you hold".
Worked example: Nadia is in a grievance process and wants to see what managers wrote about her. She emails HR asking for all personal data relating to her held in emails, HR files and meeting notes between January and June, naming the three managers involved. The employer responds within a month with a bundle in which some passages are redacted because they identify a colleague who has not consented and whose rights would be affected. That is a legitimate limit, but it applies to the other person's data, not to Nadia's own — so where an opinion is about her, it should be disclosed even though a manager wrote it.
The misconceptions matter. A SAR gives you personal data about you, not copies of every document you would like, so a request for a whole contract file or a project archive will properly be narrowed. Organisations cannot refuse simply because litigation is contemplated, and they cannot make you pay unless the request is manifestly unfounded or excessive. Legal professional privilege and the negotiations exemption can withhold specific material, but they must be applied item by item and explained, not used as a blanket refusal. And a SAR is not a substitute for disclosure in tribunal or court proceedings, which follows separate rules.
Subject access is one of the rights under UK GDPR, supplemented by the Data Protection Act 2018 and enforced by the Information Commissioner's Office. If a request has been ignored or heavily redacted, read our guide to making a subject access request and then the ICO complaints process.
Related guides
Data Subject Access Requests
A Subject Access Request (SAR) is a formal request you can make to any organisation asking them to provide a copy of all personal data they hold about you and information about how it is used. It is one of your most powerful rights under UK GDPR and is entirely free in most cases.
6 min
UK GDPR Rights for Individuals
The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018) give individuals in the UK eight legally enforceable rights over how organisations collect, store, and use their personal data. These rights apply whether the data is held by a business, public body, or online platform.
6 min
Complaining to the Information Commissioner about a Data Breach
The Information Commissioner's Office (ICO) regulates data protection in the UK. They handle complaints about misuse of personal data, failure to respond to Subject Access Requests, marketing breaches under PECR, and breaches of UK GDPR. Many complaints are resolved with a written reminder to the organisation; serious breaches lead to fines up to £17.5 million. This guide explains how to use the ICO and how to claim separately for compensation.
10 min