What Actually Counts as a Subject Access Request?
Most businesses picture a formal legal letter. In practice, a Subject Access Request is usually an ordinary-sounding email — and that's exactly why so many get missed.
Ask most small business owners what a Subject Access Request (SAR) looks like, and they'll describe something formal: a solicitor's letter, official-looking paperwork, maybe the word “GDPR” in bold. In reality, the vast majority of SARs don't look anything like that.
The legal definition is broader than most people expect
Under UK GDPR, a Subject Access Request is simply someone exercising their right of access — asking what personal data your business holds about them, and why. There's no required wording, no required format, and no need for the person to even know the term “Subject Access Request” exists.
The ICO's own guidance is explicit on this: a SAR can be made verbally, in writing, by email, through social media, or via a third party acting on someone's behalf. It doesn't need to mention GDPR, and it doesn't need to be addressed to a specific person or department.
What actually counts — real examples
Each of the following is a legally valid Subject Access Request:
- A customer emailing, “Can you send me everything you have on me?”
- A former employee messaging your company's Instagram account asking what's in their personnel file.
- A comment on a customer service ticket: “What information do you hold about me?”
- A phone call where someone verbally asks what data you hold on them.
- A solicitor's letter written on behalf of a client — the classic case everyone pictures, but statistically one of the rarer ones.
Why this is the actual cause of most SAR complaints
Most ICO complaints about SAR handling aren't about a business refusing a request outright. They're about a request that was never recognised as one in the first place — it sat in a general inbox, or reached a junior staff member who didn't know it needed escalating, and by the time anyone senior saw it, weeks of the one-month deadline had already passed.
SAR-related complaints are consistently the single most common reason people complain to the ICO at all — and “we didn't realise” is not a defence the ICO accepts, because the clock starts on receipt, not on recognition.
What this means for your business
If any member of staff — reception, social media, customer support, anyone — could plausibly receive a message from a customer or ex-employee, they need to know how to spot a SAR when it doesn't look like one. The safest approach is simple: anything that could be read as “what data do you have on me,” treat it as a SAR and start the clock immediately, rather than waiting for it to be confirmed by someone senior.
Want to work out the exact legal deadline once you've spotted one? Use the free SAR deadline calculator — it handles weekend and bank-holiday roll-forward automatically.
For guidance only — this isn't legal advice, and you should verify anything deadline-critical against current ICO guidance.