Subject access requests — GDPR family
Tier 1 ArchetypeHow a subject access request works anywhere the rules descend from Article 15 GDPR. Everything here is the shared base: a jurisdiction override states only what differs, so a national guide is a short delta rather than a rewritten guide.
Applies to
Any jurisdiction whose SAR rules descend from Art 15 GDPR — the ~30 EU/EEA states, the UK, and GDPR-modelled laws elsewhere (Serbia, Albania, Georgia, Brazil's LGPD access right, and others noted on each instrument page).
Mechanics
| Item | Position |
|---|---|
| Deadline | One calendar month from receipt of a valid request |
| Extension | A further two months for complex or numerous requests, notified within the first month |
| Cost | Free by default |
| Form required | No — any clear indication the individual is asking for their personal data counts |
| Reason required | No — the requester never has to justify why they want their data |
Steps
-
Log and acknowledge
Record the date received — this date drives the deadline. Acknowledge receipt. Do not require a specific form or a stated reason. There is no prescribed form: a request made verbally, by email, via a form, or embedded in a complaint letter all count, and the clock starts on receipt of a valid request, not on receipt of a form.
-
Verify identity
Ask for identification only where there is genuine doubt about who is asking, and only for proportionate evidence — not a full KYC pack for a routine request. Over-verification is itself a common complaint upheld by regulators.
-
Clarify scope, if genuinely necessary
Where a request is manifestly broad, the controller may ask the requester to specify the information or processing activities it relates to. This must be a genuine ambiguity, not a delay tactic. On the archetype default it pauses rather than resets the clock — confirm per jurisdiction, since some codify this more firmly than others.
-
Search and collate
Search all reasonably locatable systems: email, case management, HR systems, CCTV where relevant, and backups only if reasonably accessible. The GDPR-family standard is not "search literally everywhere regardless of cost" — proportionality applies — but the bar for what counts as reasonable has generally been read strictly by regulators and courts.
-
Apply exemptions, if any
Common GDPR-family exemptions: data revealing information about another identifiable individual (balance the requester's right against the third party's rights, and redact the third party's data where it cannot reasonably be separated, rather than refusing the whole request); legal privilege; management forecasting where disclosure would prejudice the business; and certain regulatory or crime-prevention purposes. Always work from the instrument's own exemption schedule and its trigger conditions, not a generic list.
-
Respond
Provide a copy of the personal data plus the Article 15(1) supplementary information: purposes of processing, categories of data, recipients, retention period (or the criteria used to set it), the existence of the rights to rectification, erasure, restriction and objection, the right to complain to the supervisory authority, the source of the data if it was not collected from the subject, and the existence and logic of any automated decision-making.
-
Timing
One calendar month from receipt of a valid request. Extendable by a further two months for complex or numerous requests, provided the extension and its reason are communicated to the requester within the original month.
-
Cost
Free by default. A reasonable fee is permitted only for manifestly unfounded or excessive requests, or for additional copies of the same information.
-
Refusal
Manifestly unfounded or excessive requests may be refused or charged for. The controller must be able to demonstrate why, and must still tell the requester of their right to complain to the regulator and to a judicial remedy.
Sources
- Primary Regulation (EU) 2016/679 (GDPR), Article 15 EUR-Lex
Last verified 25 July 2026 by Owen S