A subject access request (SAR in the UK and EU; a "right to know" or access request under other privacy laws) is a request by a person for the personal data you hold about them. It arrives by email, by letter, or as a line in an angry message, and the clock starts when it does — usually one month, sometimes 30 or 45 days, occasionally extendable. Here is how to handle one without panic.
Step 1 — Recognise it and log it
A request does not have to use the magic words. "Send me everything you have on me" counts. Log the date received, the requester, what they asked for, and calculate the deadline. Give the request its own record — a case — so every step below is dated and in one place.
Step 2 — Verify identity
You must be sure you are sending personal data to the right person. Ask for proof in proportion to the sensitivity: an existing client confirming from their known email address may be enough; a stranger asking for HR files is not. Ask promptly — the clock may pause while you wait, depending on jurisdiction, but only if you asked in good time.
Step 3 — Search everywhere
Email (including sent items and archives), the case or matter system, HR systems, CRM, shared drives, chat tools, paper files, backups if reasonably accessible. The search must be reasonable and proportionate, and you should record where you searched and what terms you used. This is the step that takes days in a firm with scattered records and an hour in one where records are per person, per matter, with search across fields.
Step 4 — Assess and redact
Personal data about the requester goes in. Third parties' personal data mixed in with it may need redaction or their consent. Legal privilege, confidential references, negotiation positions and some crime-prevention material may be exempt — check your jurisdiction's list. Record every exemption relied on and why.
Step 5 — Respond
Provide the data in a commonly used electronic format, together with the information the law requires: the purposes of processing, the recipients, the retention periods, the source of the data, and the person's other rights. Send it securely — a verified portal share, not an attachment. Log the date sent.
Step 6 — Close and learn
Record the outcome on the request's record. If the search was painful, note why: which system was hard to search, which records were duplicated in three places. That note is the input to the next fix.
Making the next one easy
The firms that answer access requests in an afternoon share three properties. Records are organised per person and per matter, so "everything about X" is a search, not an archaeology dig. Email is filed to the matter it belongs to, so it is found with the matter rather than in someone's mailbox. And retention is enforced, so there is simply less to find — see writing a retention policy. Each of these is also just good practice; the access request is the exam.