Data protection
Handling a subject access request inside the one-month clock
A subject access request rarely arrives looking official. It turns up as a line in an email - "please send me all the data you hold about me" - or a sentence in a complaint, sometimes from a customer, often from a departing employee. There is no form to fill in and no magic words required. And the moment it lands, a statutory clock starts: under the UK GDPR you have one calendar month to respond.
The response itself is usually manageable. The failure, when it comes, is almost never about the work - it is about the deadline slipping past unnoticed while the request sat in someone's inbox. So the discipline that matters is not doing the search faster; it is never losing the clock.
How the one-month deadline actually works
The month runs from the day you receive the request, and it is a calendar month - so a request received on the 3rd is due on the 3rd of the following month, whatever that does to the day count. You can extend it by a further two months where a request is complex or where someone has made a number of requests, but you must tell the person within the first month that you are extending, and why. The extension is a real tool, not a default; leaning on it for an ordinary request will not hold up.
One more wrinkle worth knowing: the clock does not truly start until you have confirmed the requester's identity, where you have reasonable doubt about it. If you need to verify who someone is, ask promptly - the pause is only reasonable while you genuinely cannot be sure, and dragging it out to buy time is exactly the kind of thing a regulator sees through.
The steps, in order
A dependable DSAR process is short and always the same:
- Recognise and record it. The instant a request is identified, log it - the date received is the single most important field you will ever enter, because every deadline hangs off it.
- Verify identity if needed. Confirm you are dealing with the right person before you hand over their data.
- Decide on scope and any extension. Work out what is being asked for and whether the two-month extension genuinely applies. If it does, tell them inside the first month.
- Find the data. This is where a current RoPA earns its keep - it tells you where that person's data lives.
- Review before you send. Check for third-party data, anything exempt, and information that needs redacting.
- Respond and close. Provide the data, record what you sent and when, and mark the request closed.
None of this is hard in isolation. The risk lives entirely in the gaps between the steps, where a request can go quiet.
Why a log beats a good memory
Most small organisations handle their first DSAR out of the inbox and get away with it. The trouble is the second one that arrives while the first is still open, or the request that lands the week the person handling it is on leave. Memory does not scale, and it does not hand over. A simple log fixes both: one row per request, with the date received, the type, whether identity is verified, and the outcome.
The part worth automating is the deadline. If the log works out the due date from the date received, applies the extension when you flag one, and counts the days remaining, the one number that actually matters is never something a busy person has to calculate under pressure. Better still, let the status decide itself - open, closed, or overdue - so a request that has quietly run past its month raises its hand instead of hiding. A dashboard that keeps the nearest deadline in front of you every time you open the file turns the whole thing from a memory test into a glance.
The mindset that keeps you clean
Treat every request as genuine and time-critical from the first minute, even the ones that look like a negotiating tactic in a dispute. The law does not care about the requester's motive, and the safest habit is to log first and assess afterwards. A request you recorded on arrival and answered a week early is a non-event. A request you found in an old email thread two days after the deadline is a breach of someone's rights - and one you cannot undo.
Get the logging habit and the computed clock in place, and DSARs stop being the thing that keeps you up at night. They become routine, which is exactly what they should be.
A DSAR log that runs the clock for you
Enter the date received and the request type; the log works out the one-month due date, applies the extension when you flag it, counts the days down and decides Open, Closed or Overdue on its own - with a dashboard that keeps the nearest deadline on top. A template, not legal advice.