GetMySAR

Check your subject access request response

A subject access request is also called a data subject access request, or DSAR. Use this free SAR response checker if an organisation replied late, supplied only some of your data, left out required information, refused your request or did not respond.

Answer the questions below to check the response time and what you received. You will get a list of what appears to be missing and a follow-up letter you can send. Nothing is uploaded — the checker works from your answers, not from the response itself.

The request

Whoever answered your request, or their data protection officer. Only used to address the follow-up — it stays on this device.

How did you send it?

A request sent electronically has to be answered in a common electronic format. One sent by post does not, so that question is left out below.

Who did you send it to?

Nearly always the first one. Choose the second only if the request concerned policing, prosecution, criminal penalties or another law-enforcement purpose. It can include prosecutors, prisons, HMRC investigations and some regulators. The same body answering about recruitment or another administrative matter is an ordinary organisation.

Did they respond?
Timing
What you received

Answer for the response as a whole. “Not sure” is a fine answer — it goes in the letter as a request to confirm.

Did they send you a copy of your personal data?

The data itself, not just a description of it or a promise to send it.

Did you get all the data you expected?

Records, periods, systems or departments you expected to see and did not. Answer yes if what arrived looks complete to you.

Was it in a form you can actually read and understand?

Internal codes, unexplained abbreviations and unusable file formats all count as no.

Did they reply in a common electronic format?

Paper, or scans of paper, when you asked by email or online form.

Did they tell you what they use your data for?

The purposes of the processing.

Did they tell you what categories of data they hold?

For example contact details, financial records, call recordings, correspondence.

Did they tell you who they have shared it with?

Named recipients or categories of recipient, including any outside the UK.

Did they tell you how long they will keep it?

Either a period, or how they decide the period.

Did they tell you about your rights to correct, erase, restrict or object?

A statement that these rights exist. A link to a privacy notice that covers them counts.

Did they tell you that you can complain to the Information Commissioner?

A statement of the right to complain to the supervisory authority.

Did they tell you where they got data they did not get from you?

Answer yes if everything they hold came directly from you.

Did they tell you whether they use it for automated decisions or profiling?

And if they do, the logic involved and what it means for you.

If your data goes outside the UK, did they explain the safeguards?

Answer yes if none of your data is transferred outside the UK, or you do not know of any transfer.

What they held back
Were parts blacked out?
Did they say an exemption applied?

For an ordinary UK GDPR request, the exemption should identify the relevant provision in Schedule 2, 3 or 4 to the Data Protection Act 2018.

Nothing flagged so far.

0 of 13 answered

Work through the questions on the left. Anything missing, or anything you are not sure about, shows up here. Saying a response arrived is not the same as checking what came with it, so nothing is assumed either way until you answer.

Every article above links to the text on legislation.gov.uk, so you can read the wording yourself rather than take ours for it.

This tool tells you what a response should normally contain and helps you ask for what is missing. It is information, not legal advice, and it cannot tell you whether a particular exemption has been applied correctly. You can make a subject access request, and follow it up, yourself for free.

What a subject access request response must contain

Article 15 of the UK GDPR gives you a copy of your personal data and, separately, a set of information about how it is being used. A response that hands over documents but says nothing about purposes, recipients, retention or sources has answered half the request.

Subject access request response time

An organisation must respond without undue delay and within one month. It may extend by up to two further months where the request is complex or you have made a number of requests, but it must tell you within the first month that it is doing so, and why.

Fees

There is normally no fee. A reasonable fee may only be charged where a request is manifestly unfounded or excessive, or where you ask for further copies.

Identity and narrowing down

An organisation may ask you to verify your identity, but only where it has reasonable doubts about who you are, and it should ask for the minimum needed. Where it needs further information to deal with your request, the one-month clock pauses until you provide it.

How hard they have to look

An organisation has to carry out a reasonable and proportionate search — not an exhaustive one. What counts as reasonable depends on the volume of information, the difficulty of locating it, and the size and resources of the organisation. This is a common reason for a partial response, and it is worth being specific about what you want.

Common problems with a subject access request response

What if information is missing from the response?

Use the checker above to identify what appears to be missing and create a follow-up letter asking the organisation to complete its response.

What if the organisation does not respond?

The checker calculates whether the response deadline has passed. Complain to the organisation first. Since 19 June 2026 every organisation has had a legal duty to give you a clear way to raise a data protection complaint, to acknowledge it within 30 days, to look into it properly and to tell you the outcome. If it does not, or the answer is incomplete, you can then complain to the Information Commissioner's Office.

Can an organisation refuse a subject access request?

The checker asks what reason the organisation gave and helps you identify what to raise in a follow-up. It does not decide whether a particular refusal or exemption is lawful.

How to complain about a subject access request response

Complain to the organisation first. Since 19 June 2026 every organisation has had a legal duty to give you a clear way to raise a data protection complaint, to acknowledge it within 30 days, to look into it properly and to tell you the outcome. If it does not, or the answer is incomplete, you can then complain to the Information Commissioner's Office.

Rather not do the chasing?

You can send the letter above yourself, for nothing. If you would rather hand it over, we chase the organisation, handle the replies and tell you what your options are if it stays incomplete.

Sources: UK GDPR Articles 12, 12A, and 15; Data Protection Act 2018; ICO guidance on the right of access. Last checked 5 August 2026. This page provides general information, not legal advice.