Get In
Touch:


5 Days a Week From
9:00am to 5:30pm

Rights To Your Data

Thursday, Sep-17, 2026

Rights To Your Data

Lana Wilks

Can you find out what data is held about you? Trainee Solicitor Lana Wilks of our Commercial Litigation team gives an overview of what subject access requests are, and when organisations can partially or wholly refuse a request.

A subject access request, often referred to as a “SAR” or “DSAR”, is a statutory right that enables an individual to obtain access to their personal data held by an organisation, so that they can understand what information is held about them and why. This right arises under the UK GDPR and the Data Protection Act 2018, as amended, including by the Data (Use and Access) Act 2025 where relevant.

What is a subject access request?

A subject access request is an application, usually made in writing, by an individual for access to the personal data an organisation holds about them. A valid application does not need to refer expressly to data protection legislation, nor does it need to use any particular wording, and this, therefore, makes it simple for most individuals to submit a SAR.

In this context, “personal data” means any information relating to an identifiable individual. This includes information which identifies the person directly, such as their name, address, date of birth, or an identification number used by the organisation. It also includes information which may identify them indirectly, such as IP addresses, location data, cookies, or other online identifiers, where that information can be linked back to the individual. Personal data can also include opinions about a person, internal comments concerning them, and assessments or inferences drawn from other information held.

In practice, this means that organisations often hold more personal data than an individual may expect. Information generated through website use, online tracking, account activity, and internal correspondence may all fall within the scope of a SAR.

What duties does an organisation have upon receipt of a subject access request?

An organisation must ordinarily respond to a SAR without undue delay and, in any event, within one month of receipt.

There are, however, circumstances in which an organisation may require further information before it is obliged to provide a substantive response. For example, it may request:

  • proof of the requester’s identity, where this is reasonably necessary;
  • clarification of the scope of the request, particularly where the request is broad or unclear; and/or
  • further information needed to locate the relevant personal data, especially where the organisation processes a large volume of information relating to the requester.

Where the organisation reasonably requires further information of this kind, the time for responding may be paused until that information is provided.

The one-month time limit may also be extended by up to a further two months where the request is complex or where a number of requests have been made by the same individual. This commonly arises where the material requested is extensive, where there is mixed personal data relating to other individuals, or where careful review and redaction are required. If the organisation intends to extend time, it must notify the requester within the initial one-month period and explain why the extension is necessary.

In complying with a SAR, organisations must generally provide a copy of the requester’s personal data, together with certain supplementary information. This may include details of the purposes for which the data is being processed and the recipients, or categories of recipient, with whom the data has been shared, along with other requirements in accordance with the requestor’s rights.

What can be disclosed?

Organisations do not necessarily have to provide every document in full simply because it contains the requester’s personal data. The right of access is to the requester’s personal data, not automatically to complete, unredacted copies of all underlying documents.

Whilst SARs may be made by another person on an individual’s behalf, they cannot properly be made without authority to do so. Where authority is in doubt, the organisation is entitled to seek evidence that the representative is authorised to act.

Where documents contain mixed personal data, meaning the requester’s personal data is intertwined with that of another individual, the organisation may need to redact third-party information or, in some cases, withhold the relevant document altogether. The organisation must balance the requester’s right of access against the rights and freedoms of others.

Organisations may also be entitled to withhold some or all personal data by relying on one or more statutory exemption. Where an exemption is relied upon to refuse a request in whole or in part, the organisation should explain the basis of the refusal and inform the requester of the avenues available to challenge that decision. In some circumstances, an organisation may also be entitled neither to confirm nor deny whether it holds the requested information.

There are a number of exemptions available to organisations such as:

  • Crime and taxation
  • Legal professional privilege
  • Regulatory functions and functions designed to protect the public
  • Judicial appointments, judicial independence and judicial proceedings
  • Journalism, academia, art and literature
  • Research and statistics
  • Archiving in the public interest
  • Health, education and social work information
  • Child abuse information
  • Management information
  • Negotiations with the requester
  • Confidential references
  • Exam scripts and exam marks
  • Manifestly unfounded or excessive requests
  • Information about other people

 

The most common exemptions which are not specific to particular industries or organisations, are legal professional privilege, information about other people and manifestly unfounded or excessive requests. These are set out below in more information:

Legal professional privilege

If a requester’s personal data is contained in confidential communications between the organisation and its legal advisers, that information is usually exempt from disclosure as privileged communications are confidential even where they contain the personal data of the requester.

Information about other people

Responding to a SAR may involve documents that contain personal data relating both to the requester and to other individuals.

Organisations must respect the requester’s right of access, but they must also protect the rights of third parties. As a result, if another person’s information appears within the requested material, the organisation may redact that information before disclosure. In some cases, if redaction is not possible or would not adequately protect the third party, the organisation may refuse to disclose that part of the information altogether.

Manifestly unfounded requests

A request may be considered ‘manifestly unfounded’ where the organisation is of the view that the individual is not genuinely seeking to exercise their right of access but is instead using the request for an improper purpose, such as to harass the organisation, cause disruption, or pursue a collateral objective in a plainly abusive manner.

Excessive requests

This is one of the more difficult exemptions to apply and, as with the exemptions above, its availability is highly fact-sensitive. Relevant considerations include whether the requester has made previous requests, whether the new request substantially overlaps with information already provided, how broad the request is, whether the organisation has already asked the requester to narrow its scope, and whether the burden of compliance is proportionate in the circumstances.

This exemption is often raised where there is ongoing litigation or an active dispute, particularly where a SAR appears to be used as a means of harassment, duplication, or as a tool to obtain material for a separate purpose outside the proper scope of the right of access. However, organisations should exercise caution: neither litigation nor a contentious background will, without more evidence, justify refusal. Any decision to rely on this exemption must be reasoned, evidence-based, and defensible on the facts.

The information provided in this article is broad and non-specific and does not amount to legal advice. McCormicks welcomes new instructions in relation to subject access requests and has a wealth of experience on the topic including making requests on an individual’s behalf, advising on or responding to a request received, and dealing with refusals of requests.

Comments are closed.