
A company‘s first Subject Access Request is not uncommonly a red alert moment. An employee, customer, or former staff member writes in asking for ‘all personal data relating to me,’ and management suddenly realises that the organisation may now have to search years of emails, CCTV footage, HR files, internal reports, and other records.
Having advised organisations on GDPR compliance since the Regulation came into force in 2018, and having acted for Irish, multinational, and international businesses in data protection matters, I have found the organisations that struggle are usually not struggling because the request itself is legally complicated; they are struggling because their internal systems, retention policies, and reporting structures were never designed with Subject Access Requests in mind.
What Is a Subject Access Request?
A Subject Access Request, often referred to as a SAR or DSAR (Data Subject Access Request), is a request made by someone looking for copies of personal data held about them by an organisation.
SARs and DSARs are an area where businesses can get themselves into difficulty quite quickly. The Data Protection Commission is generally unsympathetic to arguments such as:
- ‘We keep data across too many systems’
- ‘The search will take too long’
- ‘We don’t know where everything is stored’
- ‘We don’t have any staff who can deal with this’
From the Data Protection Commission’s perspective, the organisation’s obligation is to structure its own data processing systems in such a way that it can comply with these requests. But in practice, many organisations do not seriously examine their retention policies, data storage systems, or internal reporting procedures until faced with their very first SAR.
Tip 1: Your First SAR Will Almost Certainly Be More Work Than You Expect
Many businesses underestimate how much personal data they actually hold until a Subject Access Request arrives.
At that point, whoever is charged with dealing with the SAR begins to contemplate how to respond, and often realises with mounting horror that personal data may exist across:
- Email accounts
- CCTV systems
- HR records
- Multiple messaging platforms
- Shared drives
- CRM systems
- Security logs
- Call recordings
- Internal reports
- Messaging apps
- Handwritten notes
And once a request arrives, all of that material will need to be searched, reviewed, assessed, and in some cases redacted before disclosure.
(Redaction is what happens where the data also contains information about third parties or other requirements for data to be held back. When customers or other employees are discussed, you may then need to blank out or redact other people’s information before producing the records.)
In practice, that can become extremely time-consuming if your organisation has poor retention policies or years of accumulated records.
Tip 2: Better Retention Policies Mean Less Data to Trawl
Which brings us nicely to our next point: one of the recurring themes in GDPR compliance generally (and Subject Access Requests specifically) is that businesses should not hold data longer than necessary for the purpose for which it was collected.
The difficulty is that digital storage is cheap, and organisations tend to accumulate huge volumes of material because someone decides ‘I’d better hang on to that in case I need it later.’
The problem is that once a Subject Access Request arrives, every relevant WhatsApp group, retained email, or old CCTV file potentially becomes material that has to be searched and reviewed.
Good retention policies therefore do not simply reduce storage volumes; they reduce future compliance burdens.
In short, a business with rational retention policies is often in a vastly better position to respond efficiently to Subject Access Requests than one that has accumulated years of unnecessary material.
Tip 3: Work with the Requester Whenever Possible
One of the biggest mistakes businesses make is treating the request as a hostile shot across the bow of the organisation, rather than understanding that this is a person exercising a right recognised under the GDPR and, ultimately, under the Charter of Fundamental Rights itself.
This defensiveness is particularly common where an organisation has never dealt with a Subject Access Request before and management immediately assumes the request signals litigation or a formal dispute.
However, one of the points I regularly emphasise when advising businesses is that the requester is not necessarily your opponent here. In many cases, both sides can actually help each other through the process. One of the most effective things an organisation can do after receiving a Subject Access Request is acknowledge it promptly and open a dialogue with the requester.
That has several benefits.
First, it reassures the individual that the request has been received and is being dealt with.
Second, and more importantly from a practical perspective, it creates an opportunity to ask whether there is anything in particular the requester is actually looking for. This matters because many people submit extremely broad requests simply because they do not know how to narrow them.
It is common and understandable for individuals who need a piece of data from an organization to consult the internet on how to make a subject access request; the internet will in turn supply endless templates for requesting “all personal data.”
Without opening up a dialogue, your organisation can then find itself burdened with:
- Searching years of emails
- Reviewing internal correspondence
- Identifying every mention of the employee
- Assessing exemptions
- Redacting third-party data
- Reviewing large volumes of unnecessary material
Whereas if you simply acknowledge the SAR and use the opportunity to ask the question, the requester may say:
‘Actually, what I’m looking for is the CCTV footage between 3pm and 4pm on this particular date.’
At that point, both parties are happier. The requester receives the information they actually wanted much more quickly, and the organisation avoids unnecessary time and cost.
Tip 4: You Do Not Have to Search Backup Systems
One question that frequently causes concern is whether organisations must restore archived backup systems in order to comply with a Subject Access Request.
In practice, there is an important distinction between live operational systems and archival backup systems maintained purely for disaster recovery purposes.
Generally speaking, organisations are not expected to restore historical backups simply to conduct broad searches for Subject Access Requests. That distinction is important because otherwise the burden of compliance could become technically and operationally enormous.
It is also important because it goes back to Tip #2: Better Retention Policies Mean Less Data to Trawl. The more data relegated to archives, the less data you need to assess, redact, and supply in response to a SAR.
You can hang onto it, and you may need it later, but you can always get it from a backup.
Tip 5: Turn Your First SAR Into a Better GDPR Process
Subject Access Requests are not unusual events under the GDPR; they are ordinary exercises of legal rights that organisations should expect to receive from time to time.
The reality, however, is that many businesses will only seriously examine their internal data governance procedures after receiving their very first SAR. In practice, organisations are often trying to build the compliance process at the same time as they are attempting to respond to the request itself.
That is certainly not ideal, but it is also not unusual.
The important thing is to treat the SAR as both an immediate compliance exercise and a learning opportunity for improving future responses.
| If You Are Dealing With a SAR Right Now | What You Can Improve for Future SARs |
| Attempt to determine who is responsible for coordinating the response | Assign clear responsibility for GDPR and SAR compliance internally |
| Deal reactively with broad or unclear requests | Build procedures around acknowledging requests quickly and opening a dialogue with the requester |
| Discover that unnecessary data has been retained for years | Apply data minimisation principles and retention schedules consistently across systems |
| Conduct a survey of all systems where personal data may be stored | Maintain an up-to-date data map showing where personal data is held across the organisation |
| Search years of accumulated emails, CCTV footage, and archived records | Implement defined retention periods for different categories of personal data |
| Review documents individually for third-party information requiring redaction | Develop standardised review and redaction procedures |
In my experience advising organisations on GDPR compliance and data subject rights, businesses that use early Subject Access Requests as an opportunity to improve procedures, retention policies, and internal governance structures are usually in a much stronger position the next time a request arrives.
The most effective Subject Access Request response process begins long before the request itself arrives, but for many organisations, the first SAR is the moment that process finally begins.

