Subject Access Request (SAR) policy template

£9.99
UK-specific Editable Instant download 12 months' updates

This Subject Access Request (SAR) Policy sets out how the organisation will recognise, record, investigate and respond to requests from individuals seeking access to their personal information. It provides a clear process for managing SARs consistently, securely and within the applicable UK data protection requirements.

Use this policy to:

  • Explain how employees and other individuals can make a subject access request
  • Ensure SARs are identified and passed to the appropriate person promptly
  • Set out responsibilities for searching, reviewing and disclosing information
  • Manage third-party information, exemptions and redactions appropriately
  • Protect personal information throughout the SAR process
  • Ensure responses, refusals and decisions are properly recorded
Subject Access Request (SAR) policy template
2026 Reviewed
Get the complete resource

Don't just buy one policy — get the complete Security and information policy templates

If you are strengthening information security, these security and information policy templates give you a practical set of policies covering information handling, access, employee responsibilities, monitoring and leavers.

8 templates • £24.99 • 12 months' access & updates
View the policy templates

What's included in this template?

This template brings together the key information, sections and considerations you need to create a clear, comprehensive and professional HR document. Preview the document below.

  • Recognising and submitting a SAR
  • SAR ownership, recording and response times
  • Identity verification and clarification
  • Searching HR, email and other information systems
  • Third-party information, exemptions and redactions
  • Response, security, records and complaints
Template

Download .doc

Copy [to paste]

Email

Subject Access Request (SAR) policy

1   Overview

1.1   [Company Name] recognises that individuals have rights under UK data protection law to access personal information held about them.

1.2   This policy sets out how [Company Name] will recognise, record, investigate and respond to Subject Access Requests (SARs) in a consistent, secure and timely manner.

1.3   The organisation will seek to provide individuals with the information to which they are entitled while protecting confidential information, the rights of other individuals and information that is subject to applicable exemptions or restrictions.

2   Scope

2.1   This policy applies to all employees and workers of [Company Name] and to other individuals whose personal information is processed by the organisation where the right of access applies.

2.2   It applies to SARs relating to information held in any relevant format or system, including:

  • HR and personnel records
  • Payroll and benefits information
  • Absence and attendance records
  • Performance and appraisal records
  • Disciplinary and grievance records
  • Recruitment records
  • Emails and electronic communications
  • Business systems and databases
  • Paper and manual records where applicable
  • Other personal information held by the organisation

3   General principles

3.1   What is a Subject Access Request?

3.1.1   A Subject Access Request is a request by an individual for access to their personal information.

3.1.2   A valid SAR does not need to use the words "Subject Access Request", "SAR", "right of access" or "Article 15". It may be made verbally or in writing and may be received through any part of the organisation.

3.1.3   Examples include:

  • "Please send me my HR file."
  • "What information do you hold about me?"
  • "Can I have copies of my performance records?"
  • "Please send me the emails relating to my complaint."

3.2   Recognising a SAR

3.2.1   All employees should understand that a request for personal information may constitute a SAR even if the requester does not use formal data protection terminology.

3.2.2   Where an employee receives a potential SAR, they should not attempt to deal with it themselves. They should forward it promptly to [SAR Contact / HR / Data Protection Lead].

3.2.3   Managers should not search through their own records and provide information directly to an employee without following the organisation's SAR process.

3.3   Making a SAR

3.3.1   Individuals may make a SAR:

  • By email
  • By letter
  • Verbally
  • Through another communication channel where the request can be identified and recorded

3.3.2   Requests should be directed to:

[SAR Contact Name / Team]
[Email Address]
[Postal Address if applicable]

However, a request sent to another employee or department must still be recognised

PREVIEW ENDS HERE

This is the end of the preview

You've seen 20% of how the Subject Access Request (SAR) policy template is structured. Get the complete editable template instantly and customise it for your organisation.

£9.99
Specifications
Access 12 months, with updates
Length 5 pages • 1,988 words
Jurisdiction England, Wales, Scotland
Based on UK law, ACAS guidance
Last review 23/09/2026
Next review 23/03/2027
Delivery Instant digital delivery
Formats .doc · .txt · email

What is a subject access request (SAR) policy?

Subject Access Request (SAR) policy template preview

This policy provides a practical framework for handling subject access requests across the organisation. It is particularly relevant to employers because employee SARs can involve HR files, emails, performance records, absence information, investigation documents, payroll information and other sources containing personal data.

Recognising a subject access request

A SAR does not need to use the words "subject access request" or refer to data protection legislation. A request can be verbal or written and can be made to any part of the organisation if it is clear that the individual is asking for access to their personal information.

Managing the response process

The policy establishes a central process for recording requests, checking identity where necessary, clarifying the scope where appropriate, allocating responsibility and monitoring the statutory response deadline. It helps prevent requests from being overlooked when they are received by managers or other employees.

Finding and reviewing information

A reasonable and proportionate search should be undertaken for information within scope. Depending on the circumstances, this may involve HR systems, personnel files, email, messaging systems, shared drives, absence records, performance records and other relevant information sources.

Reviewing information before disclosure

Information should be reviewed to identify personal information belonging to the requester and any information that may be subject to an exemption or restriction. Information relating to other people may require particular consideration, and appropriate redaction may sometimes allow information to be disclosed while protecting other individuals.

Responding securely and maintaining records

The response should be clear, accessible and provided securely. Where information is withheld or the request is refused, the organisation should record the reason and applicable exemption or restriction and explain the individual's available complaint and challenge rights, subject to any legal restrictions on disclosure.

Example

An employee emailed their manager asking, "Can I have everything the company holds about me, including emails and notes about my performance?" The manager recognised that the request was potentially a subject access request and forwarded it to HR rather than attempting to deal with it personally.

HR recorded the date the request was received and confirmed the employee's identity. HR then contacted the employee to clarify whether there were particular areas of information they were especially interested in, while making clear that clarification was not required for the request to be valid.

The organisation carried out proportionate searches across the employee's HR records, relevant email accounts and other systems. The information was reviewed to identify the employee's personal data, information relating to other individuals and any material potentially covered by an applicable exemption.

HR prepared the response securely, providing the information that could properly be disclosed and applying appropriate redactions where necessary. The organisation retained a record of the request, searches undertaken, decisions made and information provided so that it could demonstrate how the SAR had been handled.

Implementation guidance

Use these best practice actions, recommended timescales and process stages to understand when and how the Subject Access Request (SAR) policy should be used, helping ensure each step is handled consistently and appropriately documented.

Step Description Responsibility Timing
1 Recognise the request as a potential SAR, record the date received and immediately refer it to the designated HR or data protection contact. All employees / HR Same working day where practicable
2 Confirm the requester's identity where reasonably necessary, establish the scope of the request and identify the people, systems and records likely to contain relevant information. HR / Data Protection Lead Within 5 working days
3 Carry out reasonable and proportionate searches and collect the information falling within the scope of the request. HR / IT / Managers / Relevant teams As soon as practicable
4 Review the information, consider third-party information and applicable exemptions, apply necessary redactions and prepare the response. HR / Data Protection Lead Before the response deadline
5 Provide the response securely, record what was disclosed or withheld and retain the relevant decision-making and search records. HR / Data Protection Lead Within 1 month unless a lawful extension applies
Premium content

To continue reading, purchase this item or a parent toolkit, library or our full library.

Common mistakes

Understand the common mistakes to avoid when using this HR template, helping you reduce risk, prevent unnecessary costs and ensure the process is handled correctly.

  • Failing to recognise a SAR because the individual did not use the words "subject access request"
  • Allowing a request to sit with a manager or department without referring it to the designated contact
  • Searching only the employee's HR file and ignoring other relevant information systems
  • Assuming that every document mentioning the requester must automatically be disclosed in full
  • Applying exemptions or redactions without documenting the reasoning
  • Failing to monitor the statutory response deadline and provide information securely
Premium content

To continue reading, purchase this item or a parent toolkit, library or our full library.

HR considerations

UK employment law and best practice

This template is designed to support the process, but the document should be used alongside the relevant HR procedure and applied to the circumstances of the individual case.

Right of access

Individuals have a right to access their personal information and obtain a copy of it, together with certain supplementary information. A SAR can be made verbally or in writing and does not need to use particular wording or refer to Article 15 of the UK GDPR. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/subject-access-requests/a-guide-to-subject-access/ https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/right-of-access/how-do-we-recognise-a-subject-access-request-sar/

Recognising requests

Employees do not have to send a SAR to a particular person or department. Organisations should have a process for ensuring that employees who receive potential SARs know how to recognise and refer them. A request can be valid even where the individual simply asks for their HR file or other personal information. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/employment/subject-access-request-q-and-as-for-employers/

Response timescale

Organisations must respond to a SAR without undue delay and normally within one month of receipt. The period can be extended by up to a further two months where necessary because the request is complex or multiple requests have been received, provided the individual is informed within the first month and the reason for the extension is explained. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/subject-access-requests/a-guide-to-subject-access/

Reasonable and proportionate searches

The organisation must make a reasonable and proportionate search for the requested information. The appropriate search will depend on the circumstances and may involve relevant HR systems, email, electronic records, manual files and other information sources. Organisations should document their approach sufficiently to demonstrate compliance. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/subject-access-requests/a-guide-to-subject-access/

Identity verification

An organisation may ask for information to confirm the identity of the requester where this is reasonably necessary and proportionate. It should not routinely demand excessive identification information where identity can reasonably be established through less intrusive means. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/subject-access-requests/a-guide-to-subject-access/

Clarifying the request

Where a request is unclear or covers a large amount of information, the organisation may seek clarification to help locate the information the individual wants. However, a broad request does not automatically become invalid simply because it is broad, and the organisation should not use clarification as an unnecessary barrier to responding. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/subject-access-requests/a-guide-to-subject-access/

Information about other people

Where information also identifies another individual, the organisation must consider the rights of that person before disclosure. The fact that information appears in a document concerning the requester does not necessarily mean the entire document must be disclosed. Appropriate redaction or other steps may be necessary. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/subject-access-requests/a-guide-to-subject-access/

Exemptions

There are exemptions and restrictions that may apply to particular information, including information relating to management forecasting or planning in certain circumstances, confidential references, legal professional privilege, information about other people and requests that are manifestly unfounded or excessive. Exemptions must be considered on the facts of the particular request and should not be applied as a blanket policy. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/right-of-access/what-exemptions-are-relevant-for-sars/

Manifestly unfounded or excessive requests

An organisation may refuse a SAR wholly or partly where it is manifestly unfounded or excessive, or may in appropriate circumstances charge a reasonable fee. There is a high threshold for relying on these provisions. Each request must be considered individually and the organisation should have strong justification and clear evidence supporting its decision. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/right-of-access/when-can-we-consider-a-sar-to-be-manifestly-unfounded-or-excessive/

Litigation and employment disputes

An employee's involvement in an employment dispute or potential litigation does not, by itself, invalidate a SAR or justify refusing it. The organisation should continue to consider the request under data protection law and apply any relevant exemption only where the legal requirements are met. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/right-of-access/when-can-we-consider-a-sar-to-be-manifestly-unfounded-or-excessive/

Secure disclosure

The organisation must take reasonable steps to ensure that information provided in response to a SAR is secure and is disclosed to the correct person. The method used should be appropriate to the sensitivity of the information being provided. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/subject-access-requests/a-guide-to-subject-access/

Records and accountability

The organisation should maintain appropriate records demonstrating how SARs have been handled, including relevant searches, decisions, exemptions and responses. This supports the accountability principle and enables the organisation to demonstrate compliance if its handling of a request is challenged. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/subject-access-requests/a-guide-to-subject-access/

You may also need these resources

FAQs

What counts as a Subject Access Request?

A SAR is a request from an individual for access to their personal information. It does not have to use the words "Subject Access Request" or refer to data protection law. For example, an employee asking for their HR file or information held about their performance may have made a SAR.

Can an employee make a SAR verbally?

Yes. A SAR can be made verbally or in writing, including through electronic communications or social media. The organisation should have a process for recording verbal requests and referring them to the person responsible for handling SARs.

How long does an employer have to respond to a SAR?

The normal response period is one month from receipt. This can be extended by up to a further two months where the request is complex or multiple requests have been received, provided the individual is informed within the first month and the reason for the extension is explained.

Can an employer ask an employee to narrow their SAR?

An employer can ask for clarification where this would help identify the information the employee wants, particularly where the request is broad. However, an individual is not generally required to narrow a valid SAR simply because the organisation would prefer a narrower request.

Can an employer refuse a SAR because it relates to an employment dispute?

No, not simply for that reason. The existence of an employment dispute does not remove the individual's right of access. The organisation must consider whether any specific exemption or restriction applies to the information requested.

Why use HRDocBox rather than AI?

HRDocBox policies are designed around practical UK HR processes and current data protection requirements. This policy provides a structured framework covering the end-to-end SAR process, including employee requests, searches, exemptions, redaction, secure disclosure and record keeping, rather than relying on a generic AI-generated policy.

How this content is developed and reviewed

The Subject Access Request (SAR) policy template is developed using a practical HR methodology that considers current UK employment legislation, ACAS guidance, CIPD good practice and the real-world HR process it supports. Templates and supporting information are regularly reviewed and updated, with additional reviews triggered by significant changes to legislation, guidance or established HR practice, helping ensure each document remains practical, relevant and suitable for UK employers.

About the author

Darryl Horn, Chartered HR Director

Darryl is a Chartered HR professional with over 25 years' experience in senior HR and employee relations roles.

He has extensive practical experience of managing security and information HR processes and founded hrdocbox to provide businesses with practical, professionally developed HR resources grounded in UK employment law and best practice.

HRDocBox has been creating practical UK HR documents since 2009.

Executive recommendation

"Darryl provides support and advice with excellent judgement, and has a strong understanding of people, policies and UK employment legislation."

"He is someone I trust; consistent, dependable, and committed to doing things properly."

RB
Ruth Brock Chief Executive Officer The Hygiene Bank
Get started today

HR confidence starts here

Whether you employ 5 people or 50, hrdocbox gives you the structure, documents and expertise needed to manage employees professionally and legally.

Download your FREE UK employment contract template

Professionally written and fully compliant with UK employment law

Download FREE contract
Free UK employment contract template