DSAR Response Checklist Template

An access request lands in a sales inbox on a Friday and reaches the privacy team a week later. Then the mailbox search returns thousands of messages, many of them about other people.

This free data subject access request (DSAR) checklist is for privacy leads, DPOs and the HR and customer teams who handle requests under the EU GDPR, the UK GDPR or both. It runs one request from arrival to closure: logging, proportionate identity checks, the one-month clock and any extension or UK pause, the search, third-party data and exemptions, the response, approval and secure delivery. Each request leaves a dated case file showing who decided what, and when.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: October 2026

One Request, Two Clocks: EU and UK Access Rules

Article 15 gives a person confirmation, a copy of their data and supplementary information about its use. In FT v DW (C-307/22, October 2023) the Court of Justice confirmed that the requester need give no reason and that the first copy is free, even when the data is wanted for a claim against the controller. In C-487/21 (May 2023) it held that the copy must be a faithful and intelligible reproduction, sometimes whole documents rather than a summary table.

Most failures are procedural. The EDPB’s 2024 coordinated enforcement action on access covered 1,185 controllers; its January 2025 report found missing procedures, over-used exceptions and excessive identity demands. The annual GDPR compliance audit samples completed requests after the event; this template is the process those samples come from.

EU GDPR

Articles 12 and 15, read with EDPB Guidelines 01/2022

Clock: one month from receipt through any of your official channels. The EDPB treats it as suspended while you wait for identity information, or a narrower request, that you asked for promptly.

Extension: two further months for complex or numerous requests, notified with reasons inside the first month.

Search: no proportionality limit in the text. The EDPB says the effort required is not subject to a general proportionality reservation.

Watch: the Digital Omnibus proposal, which is not law.

UK GDPR after the DUAA

Articles 12A and 15(1A), with the complaints duty in DPA 2018 s.164A

Clock: one month from the latest of receipt, receipt of identity information and payment of any fee, in force from 5 February 2026.

Pause: stop the clock while you wait for clarification you reasonably need to identify what the request covers.

Search: the requester gets what a reasonable and proportionate search finds, treated as law from 1 January 2024.

Complaints: your own complaints procedure from 19 June 2026; the regulator has been the Information Commission since 30 September 2026.

A Californian request to know runs on a longer clock: confirm receipt within 10 business days and respond within 45 calendar days, extendable once to 90 with notice. Use the CCPA/CPRA Compliance Checklist for those.

What the DSAR Response Checklist Covers

Six phases, one checklist per request. Your answers decide which steps appear, and deadlines run from the dates you record.

Phase 1

Phase 1: Receive, Log & Preserve

The first task’s answers set the early due dates, show the UK-only steps and assign the release approval.

  • Log the request on the day it reaches the organisation — record the receipt date, channel, requester, regime and privacy lead; a phone call to a shop manager can count
  • Confirm what is being asked for — an access request needs no form, legal wording or reason; log any erasure or objection request separately
  • Check the authority of anyone acting for the requester — a solicitor, relative or claims firm needs written authority; the ICO starts the UK clock once you have it
  • Acknowledge receipt and state the deadline — the EDPB recommends confirming receipt in writing with the dates the month runs between
  • Suspend routine deletion of the requester’s data — the answer reflects what you held on receipt, so pause automated purges for this person
Phase 2

Phase 2: Identity, Clarification & Validity

The clarification step is UK-only. From Phase 3, due dates run from the clock start date recorded here.

  • Decide whether identity is genuinely in doubt — Article 12(6) allows extra checks only on reasonable doubts; a logged-in customer is usually already authenticated
  • Ask for the least information that settles the doubt, the same day — a matching account detail before a passport; let the requester black out what the check does not need
  • Record the clock start date — EU: the receipt date, not counting time spent waiting for identity details you asked for promptly; UK: the latest of receipt, identity information and any fee
  • UK: pause the clock only for clarification you reasonably need — typically where you hold a lot about the person; ask at once and record when the pause starts and ends
  • Screen for manifestly unfounded or excessive requests — read both terms narrowly and keep the evidence; the burden of proof is yours, and a refusal still needs reasons in time
Phase 3

Phase 3: Search & Collate

The extension notice appears only when the extension decision is answered Yes.

  • Map where the requester’s data could sit — start from the records of processing: CRM, HR, email, chat, tickets, call recordings, CCTV and processors
  • Send search instructions to each system owner — names, email addresses, IDs and the date range, with results due back within ten days
  • Ask processors to search their systems — Article 28(3)(e) obliges them to help, and data they hold for you is in scope
  • Run mailbox and messaging searches and keep a search log — record the terms, mailboxes, channels, date ranges and hit counts
  • UK: record why the search was reasonable and proportionate — Article 15(1A) limits the duty to what such a search finds; note why any location was left out
  • Decide by day 20 whether an extension is needed — the grounds are the complexity or number of the requester’s requests, not an internal backlog
  • Send the extension notice before the first month ends — tell the requester the new deadline and the reasons
Phase 4

Phase 4: Third-Party Data & Exemptions

The two redaction tasks appear only when the material identifies other people.

  • Review the collated material and flag third-party data — remove duplicates, keep what relates to the requester, including opinions about them, and note whether others are identifiable
  • Weigh disclosure for each identifiable third party — seek consent where practical, otherwise judge whether disclosure is reasonable given confidentiality and any refusal
  • Redact what you withhold and keep an unredacted master — remove the text rather than masking it, log each redaction and leave context for the rest
  • Apply exemptions only where the facts fit — for example legal privilege, negotiations or confidential references under DPA 2018 Schedule 2, or an EU member state’s Article 23 restrictions
  • Have a second person check the bundle — someone who did not run the search checks scope, redactions and exemptions
Phase 5

Phase 5: Response Content & Approval

The last task is an approval assigned to the privacy lead or DPO named in Phase 1.

  • Draft the Article 15 information for this requester — purposes, categories, recipients, retention, rights, source, automated decisions and transfer safeguards, tailored to this person
  • UK: include both complaint routes — to you under DPA 2018 section 164A and to the Information Commission, still known as the ICO, as Article 15(1)(ea) and (f) now require
  • Prepare the copy in a usable format — a commonly used electronic form if the request came electronically, with whole documents where extracts alone would not make sense
  • Explain anything withheld or refused — state the ground; where you take no action, Article 12(4) requires the reasons and the routes to complain and to seek a judicial remedy
  • Privacy lead or DPO approves the release — checks the bundle, letter and delivery method, then records Approved or Not approved
Phase 6

Phase 6: Release, Close & Record

The Phase 3 extension answer decides which delivery task appears. If the UK clock was paused, move its due date on by the paused days.

  • Send the response within one month of the clock start — use an agreed secure channel and confirm the address; a misdirected bundle is a personal data breach
  • Send the response by the extended deadline — within three months of the clock start, releasing what is ready earlier
  • Handle follow-up questions and further copies — a reminder that the answer was incomplete is not a new request; a fee is allowed only for further copies
  • UK: log any complaint about the handling — acknowledge it within 30 days, look into it and tell the requester the outcome without undue delay, under section 164A
  • Close the case file and lift the deletion hold — keep the response, logs and approval for the period your retention schedule sets
  • Record the outcome in the request log — clock start, paused days, extension, fee, exemptions and days taken, ready for the quarterly metrics review

Access Request Rules Mapped to the Checklist

The table maps each rule for a single request to its source in each regime and to the phase that records the evidence. Sector rules and national law can add to it, so treat the table as a starting point, not legal advice.

Requirement EU GDPR UK GDPR Evidenced in
Time limitArt. 12(3): one month from receiptArts. 12(3) and 12A(1)–(2): one month from the latest of receipt, identity information and feePhases 1, 2 and 6
ExtensionArt. 12(3): two further months, notice with reasons within one monthArt. 12A(3)–(4)Phase 3
IdentityArt. 12(6): additional information on reasonable doubtsArt. 12(6)(a)–(b): may also delay until identity is confirmedPhase 2
ClarificationRecital 63; EDPB Guidelines 01/2022Art. 12A(5)–(6): stop the clockPhase 2
Manifestly unfounded or excessiveArt. 12(5): fee or refusal, burden on the controllerSamePhase 2
SearchNo statutory proportionality limitArt. 15(1A): reasonable and proportionate searchPhase 3
Rights of others and exemptionsArt. 15(4); national restrictions under Art. 23Art. 15(4); DPA 2018 Sch. 2, incl. paras 16–17 and 19–24Phase 4
Response contentArt. 15(1)(a)–(h) and 15(2)Adds Art. 15(1)(ea): complaint to the controllerPhase 5
Copy and further copiesArt. 15(3): first copy free, fee for further copiesSamePhases 5 and 6
Refusal or no actionArt. 12(4): reasons, complaint to the authority, judicial remedyArt. 12(4): also complaint to the controllerPhase 5
Complaints to the controllerNo equivalent dutyDPA 2018 s.164A: acknowledge within 30 daysPhase 6

Two things were moving at the time of review. In Brillen Rottler (C-526/24, 19 March 2026) the Court of Justice held that even a first access request can be refused as excessive, but only where the controller proves an abusive intention, a narrow test. The Commission’s Digital Omnibus proposal of 19 November 2025 would write abusive requests into Article 12(5) and make excessiveness easier to show. It was still at first reading without a Council mandate in September 2026, so the current text applies. Nothing on this page is legal advice.

Why Handle Access Requests in CheckFlow?

1

The deadline is set when the request is logged

Dynamic due dates run from the dates you enter: the acknowledgement from the receipt date, then search returns, the day-20 extension decision and the response from the clock start date. Answer Yes to the extension question and the notice and three-month deadline appear.

2

One template for EU, UK or both

Conditional logic shows the stop-the-clock, proportionate-search and complaints steps only when the UK GDPR applies, and the redaction steps only when other people appear in the material. A Paris customer and a Leeds employee run on the same template.

3

A case file that answers the regulator

The identity decision, search log, redaction log and approval each sit on their task, with who completed it and when. If the requester complains, every decision and its date is already on file.

CheckFlow is not a case-management system, an e-discovery tool or a redaction tool, and it does not give legal advice. It runs the steps, tracks the clock and holds the evidence; searching and redacting happen in your own systems. For trends, a quarterly checklist on a recurring schedule reviews the request log: volumes, on-time rate, extensions, paused days, refusals and complaints. CheckFlow’s compliance checklist software covers the rest of the privacy calendar.

Neighbouring jobs have their own templates. The GDPR Compliance Audit Checklist tests rights-handling once a year, and the CCPA/CPRA Compliance Checklist covers Californian requests. The Website Privacy & Cookie Compliance Checklist checks your request route is easy to find, and the Data Retention & Disposal Review Checklist sets how long request files are kept.

Frequently Asked Questions

How long do you have to respond to a DSAR?

+

One month, and sooner if you can. The EDPB counts to the same date in the next month: a request received on 5 March is due by 5 April, one received on 31 August by 30 September, and a deadline falling on a weekend or public holiday moves to the next working day. Complex or numerous requests allow two further months if you explain why within the first month. Under the UK GDPR the month can also start later and pause, as described above.

Can we ask for ID before answering a subject access request?

+

Only when you have reasonable doubts about who is asking, and only for what resolves them. The EDPB regards demanding an identity document as disproportionate where the person is already authenticated, for example through their customer account. Ask as soon as the request arrives, because the EDPB treats the EU clock as suspended only if you asked without undue delay.

When can a DSAR be refused or a fee charged?

+

Under Article 12(5) of both texts, only when a request is manifestly unfounded or excessive, for example a repeat of an earlier one with nothing changed since. You may then charge a reasonable fee based on administrative costs or refuse, and you must be able to prove the ground. Wanting the data for a dispute is not enough on its own. Whatever you decide, reply within the deadline with your reasons and the requester’s right to complain.

What does ‘stop the clock’ mean for UK subject access requests?

+

Article 12A(5) of the UK GDPR, in force since 5 February 2026, lets you ask for information you reasonably need to identify which data or processing the request covers. The days from your question to the answer do not count towards the month or the extension-notice deadline. The Article’s own example is a controller holding a large amount of information about the person. Do not use it to buy time on a request that is already clear.

Do we have to search emails and chat messages for a DSAR?

+

Usually, yes. Personal data in emails, Teams or Slack messages and meeting notes is in scope, including what processors hold for you. In the UK, Article 15(1A) limits the duty to a reasonable and proportionate search, judged on the circumstances, the volume and the difficulty of finding the data. The EU text has no such limit. Either way, a written search log is your best evidence.

Does a DSAR have to be in writing or use our form?

+

No. The ICO’s guidance says a request can be made verbally or in writing, including on social media, in any wording and to any contact. Insisting on a form was among the barriers the EDPB’s 2024 enforcement action criticised. Train front-line staff to pass requests on the same day, because the clock may already be running.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Answer Every Access Request on Time, With the Evidence to Prove It

Free trial — no credit card required.