An access request lands in a sales inbox on a Friday and reaches the privacy team a week later. Then the mailbox search returns thousands of messages, many of them about other people.
This free data subject access request (DSAR) checklist is for privacy leads, DPOs and the HR and customer teams who handle requests under the EU GDPR, the UK GDPR or both. It runs one request from arrival to closure: logging, proportionate identity checks, the one-month clock and any extension or UK pause, the search, third-party data and exemptions, the response, approval and secure delivery. Each request leaves a dated case file showing who decided what, and when.
Article 15 gives a person confirmation, a copy of their data and supplementary information about its use. In FT v DW (C-307/22, October 2023) the Court of Justice confirmed that the requester need give no reason and that the first copy is free, even when the data is wanted for a claim against the controller. In C-487/21 (May 2023) it held that the copy must be a faithful and intelligible reproduction, sometimes whole documents rather than a summary table.
Most failures are procedural. The EDPB’s 2024 coordinated enforcement action on access covered 1,185 controllers; its January 2025 report found missing procedures, over-used exceptions and excessive identity demands. The annual GDPR compliance audit samples completed requests after the event; this template is the process those samples come from.
EU GDPR
Articles 12 and 15, read with EDPB Guidelines 01/2022
Clock: one month from receipt through any of your official channels. The EDPB treats it as suspended while you wait for identity information, or a narrower request, that you asked for promptly.
Extension: two further months for complex or numerous requests, notified with reasons inside the first month.
Search: no proportionality limit in the text. The EDPB says the effort required is not subject to a general proportionality reservation.
Watch: the Digital Omnibus proposal, which is not law.
UK GDPR after the DUAA
Articles 12A and 15(1A), with the complaints duty in DPA 2018 s.164A
Clock: one month from the latest of receipt, receipt of identity information and payment of any fee, in force from 5 February 2026.
Pause: stop the clock while you wait for clarification you reasonably need to identify what the request covers.
Search: the requester gets what a reasonable and proportionate search finds, treated as law from 1 January 2024.
Complaints: your own complaints procedure from 19 June 2026; the regulator has been the Information Commission since 30 September 2026.
A Californian request to know runs on a longer clock: confirm receipt within 10 business days and respond within 45 calendar days, extendable once to 90 with notice. Use the CCPA/CPRA Compliance Checklist for those.
What the DSAR Response Checklist Covers
Six phases, one checklist per request. Your answers decide which steps appear, and deadlines run from the dates you record.
Phase 1
Phase 1: Receive, Log & Preserve
The first task’s answers set the early due dates, show the UK-only steps and assign the release approval.
Log the request on the day it reaches the organisation — record the receipt date, channel, requester, regime and privacy lead; a phone call to a shop manager can count
Confirm what is being asked for — an access request needs no form, legal wording or reason; log any erasure or objection request separately
Check the authority of anyone acting for the requester — a solicitor, relative or claims firm needs written authority; the ICO starts the UK clock once you have it
Acknowledge receipt and state the deadline — the EDPB recommends confirming receipt in writing with the dates the month runs between
Suspend routine deletion of the requester’s data — the answer reflects what you held on receipt, so pause automated purges for this person
Phase 2
Phase 2: Identity, Clarification & Validity
The clarification step is UK-only. From Phase 3, due dates run from the clock start date recorded here.
Decide whether identity is genuinely in doubt — Article 12(6) allows extra checks only on reasonable doubts; a logged-in customer is usually already authenticated
Ask for the least information that settles the doubt, the same day — a matching account detail before a passport; let the requester black out what the check does not need
Record the clock start date — EU: the receipt date, not counting time spent waiting for identity details you asked for promptly; UK: the latest of receipt, identity information and any fee
UK: pause the clock only for clarification you reasonably need — typically where you hold a lot about the person; ask at once and record when the pause starts and ends
Screen for manifestly unfounded or excessive requests — read both terms narrowly and keep the evidence; the burden of proof is yours, and a refusal still needs reasons in time
Phase 3
Phase 3: Search & Collate
The extension notice appears only when the extension decision is answered Yes.
Map where the requester’s data could sit — start from the records of processing: CRM, HR, email, chat, tickets, call recordings, CCTV and processors
Send search instructions to each system owner — names, email addresses, IDs and the date range, with results due back within ten days
Ask processors to search their systems — Article 28(3)(e) obliges them to help, and data they hold for you is in scope
Run mailbox and messaging searches and keep a search log — record the terms, mailboxes, channels, date ranges and hit counts
UK: record why the search was reasonable and proportionate — Article 15(1A) limits the duty to what such a search finds; note why any location was left out
Decide by day 20 whether an extension is needed — the grounds are the complexity or number of the requester’s requests, not an internal backlog
Send the extension notice before the first month ends — tell the requester the new deadline and the reasons
Phase 4
Phase 4: Third-Party Data & Exemptions
The two redaction tasks appear only when the material identifies other people.
Review the collated material and flag third-party data — remove duplicates, keep what relates to the requester, including opinions about them, and note whether others are identifiable
Weigh disclosure for each identifiable third party — seek consent where practical, otherwise judge whether disclosure is reasonable given confidentiality and any refusal
Redact what you withhold and keep an unredacted master — remove the text rather than masking it, log each redaction and leave context for the rest
Apply exemptions only where the facts fit — for example legal privilege, negotiations or confidential references under DPA 2018 Schedule 2, or an EU member state’s Article 23 restrictions
Have a second person check the bundle — someone who did not run the search checks scope, redactions and exemptions
Phase 5
Phase 5: Response Content & Approval
The last task is an approval assigned to the privacy lead or DPO named in Phase 1.
Draft the Article 15 information for this requester — purposes, categories, recipients, retention, rights, source, automated decisions and transfer safeguards, tailored to this person
UK: include both complaint routes — to you under DPA 2018 section 164A and to the Information Commission, still known as the ICO, as Article 15(1)(ea) and (f) now require
Prepare the copy in a usable format — a commonly used electronic form if the request came electronically, with whole documents where extracts alone would not make sense
Explain anything withheld or refused — state the ground; where you take no action, Article 12(4) requires the reasons and the routes to complain and to seek a judicial remedy
Privacy lead or DPO approves the release — checks the bundle, letter and delivery method, then records Approved or Not approved
Phase 6
Phase 6: Release, Close & Record
The Phase 3 extension answer decides which delivery task appears. If the UK clock was paused, move its due date on by the paused days.
Send the response within one month of the clock start — use an agreed secure channel and confirm the address; a misdirected bundle is a personal data breach
Send the response by the extended deadline — within three months of the clock start, releasing what is ready earlier
Handle follow-up questions and further copies — a reminder that the answer was incomplete is not a new request; a fee is allowed only for further copies
UK: log any complaint about the handling — acknowledge it within 30 days, look into it and tell the requester the outcome without undue delay, under section 164A
Close the case file and lift the deletion hold — keep the response, logs and approval for the period your retention schedule sets
Record the outcome in the request log — clock start, paused days, extension, fee, exemptions and days taken, ready for the quarterly metrics review
The table maps each rule for a single request to its source in each regime and to the phase that records the evidence. Sector rules and national law can add to it, so treat the table as a starting point, not legal advice.
Requirement
EU GDPR
UK GDPR
Evidenced in
Time limit
Art. 12(3): one month from receipt
Arts. 12(3) and 12A(1)–(2): one month from the latest of receipt, identity information and fee
Phases 1, 2 and 6
Extension
Art. 12(3): two further months, notice with reasons within one month
Art. 12A(3)–(4)
Phase 3
Identity
Art. 12(6): additional information on reasonable doubts
Art. 12(6)(a)–(b): may also delay until identity is confirmed
Phase 2
Clarification
Recital 63; EDPB Guidelines 01/2022
Art. 12A(5)–(6): stop the clock
Phase 2
Manifestly unfounded or excessive
Art. 12(5): fee or refusal, burden on the controller
Same
Phase 2
Search
No statutory proportionality limit
Art. 15(1A): reasonable and proportionate search
Phase 3
Rights of others and exemptions
Art. 15(4); national restrictions under Art. 23
Art. 15(4); DPA 2018 Sch. 2, incl. paras 16–17 and 19–24
Phase 4
Response content
Art. 15(1)(a)–(h) and 15(2)
Adds Art. 15(1)(ea): complaint to the controller
Phase 5
Copy and further copies
Art. 15(3): first copy free, fee for further copies
Same
Phases 5 and 6
Refusal or no action
Art. 12(4): reasons, complaint to the authority, judicial remedy
Art. 12(4): also complaint to the controller
Phase 5
Complaints to the controller
No equivalent duty
DPA 2018 s.164A: acknowledge within 30 days
Phase 6
Two things were moving at the time of review. In Brillen Rottler (C-526/24, 19 March 2026) the Court of Justice held that even a first access request can be refused as excessive, but only where the controller proves an abusive intention, a narrow test. The Commission’s Digital Omnibus proposal of 19 November 2025 would write abusive requests into Article 12(5) and make excessiveness easier to show. It was still at first reading without a Council mandate in September 2026, so the current text applies. Nothing on this page is legal advice.
Why Handle Access Requests in CheckFlow?
1
The deadline is set when the request is logged
Dynamic due dates run from the dates you enter: the acknowledgement from the receipt date, then search returns, the day-20 extension decision and the response from the clock start date. Answer Yes to the extension question and the notice and three-month deadline appear.
2
One template for EU, UK or both
Conditional logic shows the stop-the-clock, proportionate-search and complaints steps only when the UK GDPR applies, and the redaction steps only when other people appear in the material. A Paris customer and a Leeds employee run on the same template.
3
A case file that answers the regulator
The identity decision, search log, redaction log and approval each sit on their task, with who completed it and when. If the requester complains, every decision and its date is already on file.
CheckFlow is not a case-management system, an e-discovery tool or a redaction tool, and it does not give legal advice. It runs the steps, tracks the clock and holds the evidence; searching and redacting happen in your own systems. For trends, a quarterly checklist on a recurring schedule reviews the request log: volumes, on-time rate, extensions, paused days, refusals and complaints. CheckFlow’s compliance checklist software covers the rest of the privacy calendar.
One month, and sooner if you can. The EDPB counts to the same date in the next month: a request received on 5 March is due by 5 April, one received on 31 August by 30 September, and a deadline falling on a weekend or public holiday moves to the next working day. Complex or numerous requests allow two further months if you explain why within the first month. Under the UK GDPR the month can also start later and pause, as described above.
Can we ask for ID before answering a subject access request?
+
Only when you have reasonable doubts about who is asking, and only for what resolves them. The EDPB regards demanding an identity document as disproportionate where the person is already authenticated, for example through their customer account. Ask as soon as the request arrives, because the EDPB treats the EU clock as suspended only if you asked without undue delay.
When can a DSAR be refused or a fee charged?
+
Under Article 12(5) of both texts, only when a request is manifestly unfounded or excessive, for example a repeat of an earlier one with nothing changed since. You may then charge a reasonable fee based on administrative costs or refuse, and you must be able to prove the ground. Wanting the data for a dispute is not enough on its own. Whatever you decide, reply within the deadline with your reasons and the requester’s right to complain.
What does ‘stop the clock’ mean for UK subject access requests?
+
Article 12A(5) of the UK GDPR, in force since 5 February 2026, lets you ask for information you reasonably need to identify which data or processing the request covers. The days from your question to the answer do not count towards the month or the extension-notice deadline. The Article’s own example is a controller holding a large amount of information about the person. Do not use it to buy time on a request that is already clear.
Do we have to search emails and chat messages for a DSAR?
+
Usually, yes. Personal data in emails, Teams or Slack messages and meeting notes is in scope, including what processors hold for you. In the UK, Article 15(1A) limits the duty to a reasonable and proportionate search, judged on the circumstances, the volume and the difficulty of finding the data. The EU text has no such limit. Either way, a written search log is your best evidence.
Does a DSAR have to be in writing or use our form?
+
No. The ICO’s guidance says a request can be made verbally or in writing, including on social media, in any wording and to any contact. Insisting on a form was among the barriers the EDPB’s 2024 enforcement action criticised. Train front-line staff to pass requests on the same day, because the clock may already be running.
Is CheckFlow free for this template?
+
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.
Answer Every Access Request on Time, With the Evidence to Prove It
Free trial — no credit card required.
Do you like cookies? 🍪 We use cookies to ensure you get the best experience on our website. Learn more