← All postsHow-to

Data subject access request: one month, everything you hold, no charge

A DSAR is not a support ticket. The clock starts on receipt, the scope is everything, and the exemptions are narrower than most teams assume.

How-toD

A data subject access request — a DSAR — is a person asking what personal data you hold about them, why, who you share it with, and for a copy of it. Under the GDPR and the UK equivalent it must normally be answered within one month, free of charge, and it can arrive in any form: an email, a phone call, a sentence at the end of a complaint.

That last point causes most of the failures. There is no required wording and no form the requester must use. A message saying "send me everything you have on me" is a valid DSAR, and the month starts when it reaches any part of your organisation — not when it reaches the person who knows what to do with it.

What a data subject access request covers

  • A copy of the personal data itself, in an intelligible form.
  • The purposes of processing and the lawful basis relied on.
  • The categories of data, and the recipients or categories of recipients it is disclosed to.
  • The retention period, or the criteria used to set it.
  • The source of the data, where it was not collected from the person.
  • The existence of automated decision-making, with meaningful information about the logic.
  • The person’s other rights: rectification, erasure, restriction, objection, and to complain to a supervisory authority.

Personal data is broader than a record with their name on it. Emails discussing them, meeting notes mentioning them, CCTV, call recordings, internal messages about a complaint they raised — all of it is in scope if it identifies them and you still hold it.

Running one without panic

  1. Log the request the day it arrives, with the date received, and start the clock from that date.
  2. Verify identity proportionately — enough to be sure, not a passport for a customer already logged in.
  3. Clarify scope only if genuinely necessary; a clarification request does not automatically pause the deadline in every regime, so check before relying on it.
  4. Search everywhere the data could be, including mailboxes, chat, ticketing and backups you can actually retrieve.
  5. Review for third-party data: other people’s personal data must be redacted or their consent obtained.
  6. Send the response securely, with the supplementary information, not just the files.
  7. Record what was searched, what was withheld and why — this is what a regulator asks for if the requester complains.

The one-month deadline may be extended by two further months where the request is complex or there are several — but you must tell the requester within the original month, and say why. An extension taken silently is a breach even if the eventual response is complete.

Where teams get caught

Three patterns recur. The request sits in a shared inbox for three weeks because nobody recognised it. The search misses email, which is where most of the relevant material actually is. And third-party data is disclosed in a rush to meet the deadline, turning a routine request into a personal data breach of somebody else.

A fourth is less obvious: treating a DSAR as adversarial. Many arrive from ex-employees or during a dispute, and the temptation is to minimise. Regulators look at whether the search was reasonable and the reasoning documented — not at whether the answer suited you.

Because a DSAR ends in an evidence question — what did you search, what did you withhold, when did you respond — it belongs in a record rather than in an email thread. Ettex Records holds the request log, the searches performed, the redaction decisions and the response, so the file that answers a regulator exists as a by-product of doing the work. The data retention policy matters here too: data you no longer hold is data you do not have to disclose.

Frequently asked

How long do I have to respond to a DSAR?

One month from receipt, extendable by two months for complex or numerous requests, provided you inform the requester of the extension and the reason within the first month.

Can I charge for a data subject access request?

Not normally. A reasonable fee may be charged for manifestly unfounded or excessive requests, or for further copies — and the bar for calling a request excessive is high.

Can I refuse a DSAR?

Only in limited circumstances: manifestly unfounded or excessive requests, or where an exemption applies. Refusal has to be explained, with the person told of their right to complain.

Do emails count as personal data?

Yes, where they identify the person — including emails about them rather than to them. Excluding mailboxes from the search is one of the most common reasons a response is later found inadequate.

SL
Written by Sofia L.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.