
Data subject request policy
- Ensures clear and efficient procedures are in place
- Quick and easy to complete
- Clear and easy to understand
- Helps you comply with UK GDPR requirements
This Data subject request policy will allow you to set up a policy that staff can refer to when responding to a request from an individual about their personal data that your business holds (a data subject request).
Under the UK GDPR, individuals can make requests about their personal data that you collect, including requests to correct or delete personal data, or a request for a copy of the data and details of how your business uses it (known as a subject access request).
There are both practical and legal steps that you need to take in order to minimise any disruption and fulfil your obligations under the UK GDPR when responding to a data subject request.
Having this Data subject request policy in place will assist your business in identifying and responding appropriately to a data subject request.
You can also purchase this policy as part of the Data protection policy toolkit.
Q&A
When should I use this document?
Use this data subject request policy to generate a policy your staff can use when they are dealing with data subject requests.
What does this document cover?
This data subject request policy sets out the procedures for your staff to follow when dealing with data subject requests, including identifying each type of request and responding appropriately to each one.
Why do I need this document?
Having a data subject request policy in place reduces the risk of staff failing to deal with a data subject request properly and any resulting sanctions from the ICO or legal action from the individual concerned.
Where can I find out more?
See Individuals’ access to personal data for more information on dealing with data subject requests in general.
Related Toolkits
Data breach toolkit
Personal data breach policy
Template personal data breach register
Notice of a personal data breach (affected individuals)
- How-to guide: Data breach toolkit
Data protection policy toolkit
- How-to guide: Data protection policy toolkit
Privacy policy
Cookie policy
Data protection policy
Staff privacy notice
Staff recruitment privacy notice
Data subject request policy
Data protection impact assessment policy
Personal data breach policy
Data subject request toolkit
- How-to guide: Data subject request toolkit
Data subject request policy
Subject access request form
Data transfer request form
Request form to correct inaccurate or incomplete data
Request form to delete data
Request form to stop using data
Letter acknowledging receipt of data subject request (and requesting verification of ID)
Letter asking for further information about a data subject request
Letter confirming no data held in response to data subject request
Letter explaining reasons for extension of time to respond to data subject requests
Letter to third party seeking consent to disclosure of information
Subject access request response template
Letter confirming that data processing has ceased
Letter explaining why data processing will continue
Letter confirming that data has been corrected
Letter explaining why data will not be corrected
Letter to party who has been supplied with data to confirm its correction
Letter confirming that data has been deleted
Letter explaining why data will not be deleted
Letter to party who has been supplied data to confirm its deletion
Letter supplying data in response to a portability request
Letter supplying data to a third party in response to a portability request
Small claims toolkit
- How-to guide: Small claims toolkit
Letter before action
Witness statement
Letter of non-attendance for small claims hearing