Data Protection ChecklistChecklist and Decision Guide

Subject Access Request First Response Checklist

7 minutes to completeEvergreen guide — kept up to date

Use this checklist when a customer, employee or other individual asks what personal data your business holds about them. Keep the SAR, any data-protection complaint, direct-marketing objection and erasure request connected but separate; record the decision trail from first receipt through to secure response.

Use this guide when a data-rights request lands in an inbox. It is a practical operating tool, not legal advice. Check current ICO guidance and take specialist advice for difficult, contentious or high-risk cases.

The first mistake is treating a data-rights request like an ordinary customer-service email. Do not panic. Do not delete data. Do not reply casually.

One message may contain several processes

  • A subject access request — “what information do you hold about me?”
  • A data-protection complaint — “I never agreed to this marketing”
  • An objection to direct marketing — “stop emailing me”
  • An erasure request — “delete everything”

Link the requests in one evidence log, but do not treat them as one deadline or one decision.

1 Receive

  • □ Save the original request unchanged
  • □ Record the date, time and channel received
  • □ Identify the requester and their relationship to the business
  • □ Treat plain-language requests for personal information seriously, even without the phrase “SAR”
  • □ Avoid deleting or tidying relevant data after receipt

2 Log

  • □ Give the request a reference and name an owner
  • □ Record the normal one-month SAR due date
  • □ Note any separate data-protection complaint acknowledgement date
  • □ Link complaint, marketing-objection and erasure requests without merging their processes
  • □ Create an evidence log from the start

3 Verify

  • □ Decide whether identity verification is genuinely needed
  • □ Use a known account email or authenticated login where suitable
  • □ Ask for further evidence only where the disclosure risk justifies it
  • □ Store and protect any identity evidence proportionately
  • □ Do not automatically ask everyone for a passport

Clarify with a purpose

If a broad request concerns a large amount of information, ask specific, prompt clarification where it is needed to understand scope. Current ICO guidance has specific rules around timing. Clarification is for understanding the request, not buying time.

4 Search

Start with the data map. The appropriate search depends on the request, data types and systems used. Search reasonably and proportionately — not lazily, and not theatrically.

Data typePossible places to checkOwner / action
Email and correspondenceMicrosoft 365, Outlook, shared mailboxes, archivesIdentify mailbox owners and search terms
Notes and service historyCRM, helpdesk, spreadsheetsExport or record results with the system owner
Files and collaborationSharePoint, OneDrive, Teams, cloud storageIdentify relevant sites, folders and message channels
Calls and messagingVoIP, call recordings, business WhatsApp, SMSCheck whether the channel is approved and mapped
Supplier-held dataPayroll, marketing, cloud, IT-support platformsUse the processor contact route and record the request

If staff use a system to talk about customers or employees, that system may contain personal data. Do not forget Teams, business WhatsApp, AI summaries or processor platforms when they are relevant.

5 Review

  • □ Check whether each item is relevant personal data
  • □ Identify third-party information and internal opinions
  • □ Consider whether consent, redaction, exemptions or specialist advice are needed
  • □ Keep a reviewed copy of the final response material
  • □ Treat backup and archived-system questions cautiously; accessibility and proportionality can be nuanced

Review is not optional

A SAR gives someone access to their data, not unrestricted access to everybody else’s. Finding the record is only the first step.

6 Respond

  • □ Respond using the correct SAR process and the current ICO guidance
  • □ Use a delivery method appropriate to the sensitivity and volume of the information
  • □ Check recipient details before delivery
  • □ Provide passwords or access instructions separately where appropriate
  • □ Stop direct marketing promptly where the person has objected and preserve suppression information
  • □ Assess any erasure request separately — do not erase records automatically

A SAR response should not create the data breach you are trying to avoid. Black highlighting is not redaction if the text is still underneath it.

7 Record

  • □ Systems searched, staff involved and processors contacted
  • □ Identity and clarification decisions
  • □ Review, redaction and specialist-advice decisions
  • □ Response date, delivery method and proof of delivery
  • □ Separate complaint, marketing-objection and erasure outcomes
  • □ Follow-up actions to improve the data map or process

SAR Readiness Outcome

OutcomeMeaningNext action
CONTROLLEDOwner, process, data map, secure delivery and evidence log are known.Run a periodic sample test.
REVIEWThe process exists, but a recent system, staff or supplier change needs checking.Update the map and confirm the owner.
ACTION REQUIREDA gap is known: no clear owner, data location, safe redaction or secure delivery method.Assign an owner and target date.
UNKNOWNThe business cannot yet explain how it would find or handle the data.Start with the first-hour workflow and data map.

Operational Heartbeat

Data-rights requests need an Operational Heartbeat: systems, processors, data locations, response procedures and staff awareness should be reviewed before a real request exposes the gaps.

  • Quarterly — review the data map, system inventory, processor list, request log and complaint log
  • Annually — review the SAR procedure, staff awareness, secure response method and a sample exercise
  • After change — add new apps, AI tools, collaboration spaces, marketing platforms and suppliers to the map

Official Guidance to Recheck

ICO: A guide to subject access

ICO: What should we consider when responding to a request?

ICO: How to deal with data protection complaints

Read the full IT Club Ask the Advisor guide

Plain-English Takeaway

Receive, log, classify, verify, search, review, respond and record. A small business does not need an enterprise privacy team to control an ordinary SAR, but it does need a named owner, a living data map, a repeatable process and evidence of what it did.

Downloadable guide

Subject Access Request First Response Checklist (PDF)

A two-page A4, selectable-text first-response checklist covering receipt, logging, classification, verification, search, review, redaction, secure response, evidence and a qualitative readiness outcome.

Download SAR First Response Checklist (PDF)

A4 portrait, two pages, selectable text.

Still unsure what applies to your business?

Ask the IT Club Advisor about Microsoft 365, browsers, cyber security, productivity or any everyday technology problem.

Free to ask. No credit card. No sales pressure. Fair usage applies.