← Back to guides

SAR Response Template UK: Free Template + What to Include

A response that skips the wrong details is as risky as a late one. Here's a free acknowledgement template, plus what every SAR response actually needs to cover.

Start with an acknowledgement, not the full response

The moment you recognise a Subject Access Request, send a short acknowledgement. It buys clarity, starts building your audit trail, and — if you need to confirm identity — gives you a clean, documented starting point for the one-month clock. It is not your final response.

Free acknowledgement template

Copy and adapt the wording below:

Dear [Name],

Thank you for your request of [date] asking what personal data [Business Name] holds about you. We're treating this as a Subject Access Request under UK GDPR.

[If identity verification is needed:] Before we can proceed, we need to confirm your identity. Could you please provide [specific, minimal proof requested]? We'll begin the one-month response period once we receive this.

[If no verification needed:] We aim to respond in full by [date — one calendar month from receipt], in line with our legal obligations.

If you have any questions in the meantime, please contact us at [contact email].

Kind regards,
[Name / Business]

What the full response needs to include

A legally sound SAR response should cover:

  • Confirmation that you're processing their data (or a clear statement if you're not).
  • A copy of the personal data itself, in an accessible format — redacting any third parties' personal data mixed in with it.
  • The purposes of processing — why you hold and use the data.
  • The categories of data involved (e.g. contact details, purchase history, HR records).
  • Who you've shared it with, or the categories of recipient.
  • How long you'll keep it, or the criteria used to decide.
  • Their other rights — to rectification, erasure, restriction, and the right to complain to the ICO.
  • Where the data came from, if it wasn't collected directly from them.

Before you send anything, search everywhere the data could be

The most common gap in SAR responses isn't tone or wording — it's incomplete searching. Check every system that could plausibly hold the person's data:

  • Email (including individual staff inboxes, not just shared ones)
  • CRM and support-ticket systems
  • HR and payroll records, if they're a current or former employee
  • Accounting/invoicing software
  • Physical/paper files
  • Backups, if reasonably accessible

Common mistakes to avoid

  • Redacting too much or too little. You must remove other people's personal data, but you can't use that as an excuse to withhold the requester's own information.
  • Charging a fee by default. Most SARs are free. A fee is only permitted if the request is manifestly unfounded or excessive — and that's a high bar, not a judgement call to make lightly.
  • No audit trail. If a complaint reaches the ICO, being able to show exactly when the request arrived, what you sent, and when, is the difference between a quick resolution and a drawn-out investigation.

Want this without rebuilding it from scratch every time?

DataDeadline's Pro plan includes editable acknowledgement, clarification, final response, and refusal templates with auto-filled placeholders, plus a timestamped audit trail exported per request. See pricing, or start free to track requests against their deadline first:

For guidance only — this isn't legal advice, and you should verify anything deadline-critical against current ICO guidance.

Stop tracking deadlines by hand

DataDeadline receives every SAR and complaint through your own form, starts the legal clock automatically, warns you before it's due, and keeps the audit trail. Free to receive and track.