Data Protection Atlas

Subject access requests — GDPR family

Tier 1 Archetype

How a subject access request works anywhere the rules descend from Article 15 GDPR. Everything here is the shared base: a jurisdiction override states only what differs, so a national guide is a short delta rather than a rewritten guide.

Applies to

Any jurisdiction whose SAR rules descend from Art 15 GDPR — the ~30 EU/EEA states, the UK, and GDPR-modelled laws elsewhere (Serbia, Albania, Georgia, Brazil's LGPD access right, and others noted on each instrument page).

Mechanics

Item Position
Deadline One calendar month from receipt of a valid request
Extension A further two months for complex or numerous requests, notified within the first month
Cost Free by default
Form required No — any clear indication the individual is asking for their personal data counts
Reason required No — the requester never has to justify why they want their data

Steps

  1. Log and acknowledge

    Record the date received — this date drives the deadline. Acknowledge receipt. Do not require a specific form or a stated reason. There is no prescribed form: a request made verbally, by email, via a form, or embedded in a complaint letter all count, and the clock starts on receipt of a valid request, not on receipt of a form.

  2. Verify identity

    Ask for identification only where there is genuine doubt about who is asking, and only for proportionate evidence — not a full KYC pack for a routine request. Over-verification is itself a common complaint upheld by regulators.

  3. Clarify scope, if genuinely necessary

    Where a request is manifestly broad, the controller may ask the requester to specify the information or processing activities it relates to. This must be a genuine ambiguity, not a delay tactic. On the archetype default it pauses rather than resets the clock — confirm per jurisdiction, since some codify this more firmly than others.

  4. Search and collate

    Search all reasonably locatable systems: email, case management, HR systems, CCTV where relevant, and backups only if reasonably accessible. The GDPR-family standard is not "search literally everywhere regardless of cost" — proportionality applies — but the bar for what counts as reasonable has generally been read strictly by regulators and courts.

  5. Apply exemptions, if any

    Common GDPR-family exemptions: data revealing information about another identifiable individual (balance the requester's right against the third party's rights, and redact the third party's data where it cannot reasonably be separated, rather than refusing the whole request); legal privilege; management forecasting where disclosure would prejudice the business; and certain regulatory or crime-prevention purposes. Always work from the instrument's own exemption schedule and its trigger conditions, not a generic list.

  6. Respond

    Provide a copy of the personal data plus the Article 15(1) supplementary information: purposes of processing, categories of data, recipients, retention period (or the criteria used to set it), the existence of the rights to rectification, erasure, restriction and objection, the right to complain to the supervisory authority, the source of the data if it was not collected from the subject, and the existence and logic of any automated decision-making.

  7. Timing

    One calendar month from receipt of a valid request. Extendable by a further two months for complex or numerous requests, provided the extension and its reason are communicated to the requester within the original month.

  8. Cost

    Free by default. A reasonable fee is permitted only for manifestly unfounded or excessive requests, or for additional copies of the same information.

  9. Refusal

    Manifestly unfounded or excessive requests may be refused or charged for. The controller must be able to demonstrate why, and must still tell the requester of their right to complain to the regulator and to a judicial remedy.

Sources

Last verified 25 July 2026 by Owen S