What this is
What is a subject access request record?
What is a subject access request record?
It documents a request from an individual for the personal data held about them: what was searched, what was withheld and why, and whether the response met the statutory deadline. It stays open until search, preparation and response are complete.
What does the search have to cover?
Every location personal data might be held, not only the primary HR or CRM system: email, paper files, manager's notes, occupational health records and monitoring or camera data. These are the most often requested and hardest to assemble, since they rarely live with the system searched first.
Can a request be refused or delayed?
A response can be extended, not refused outright, where the request is complex or numerous, provided the requester is told of the extension and reason within the deadline. Specific material can be withheld under a defined exemption, such as third-party data or legal privilege, but that applies to the material concerned, not the whole request.
Scope
When is a subject access request record required?
This record is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.
Use this template when
- An individual has requested confirmation of, or access to, the personal data held about them
- The workspace is being set up, or the register needs an entry added or retired
- You are running the Data Protection and Information Security programme and this is one step
- A linked record needs this one to exist: links personal data record, health records
- A response, extension or exemption decision needs to be defensible afterwards rather than reconstructed from memory
Do not use it for
- Personal Data Processing Record, the register a search should be checked against to confirm nothing held has been missed.
- Data Breach Record, which handles an unauthorised disclosure or loss of data, a different duty with a different clock and no search-and-redact obligation.
- Data Protection Impact Assessment, which assesses a new system before it processes personal data, not a request about data already held.
- An employment grievance or disciplinary record, which the search may surface material from but does not replace; redacting it is this record's job, not a reason to route the request there.
- Anything outside KnowComply, which belongs in the workspace that owns that process
Compliance mapping
Which ISO 27701 cl.7.3 requirements does this satisfy?
ISO 27701 frames access as an obligation owed to the individual directly, distinct from general security controls, and GDPR and equivalent regimes attach a fixed, short deadline and narrow exemptions to that obligation.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 27701 cl.7.3 | Identity of the requester verified before personal data is disclosed, since disclosure to the wrong person is itself a breach | Header |
| GDPR Art.12(3) | Response provided within one calendar month of receipt, extendable by two further months for complex requests, with the requester told of the extension and reason | Header |
| ISO 27701 cl.7.3 | Search extended across every location personal data may be held, including systems outside the primary record | Search |
| GDPR Art.15 | Access provided to the personal data itself, together with specified supplementary information about how it is processed | Response |
| UK DPA 2018 Sch.2 | Exemptions, including third-party data and legal privilege, applied narrowly to the specific material they cover, not the whole response | Preparation |
| ISO 27701 cl.7.3 | Fulfilment of the request evidenced and retained, including what was searched, what was withheld and why | Outcome |
What it does not cover
- Personal Data Processing Record, the register a search should be checked against to confirm nothing held has been missed.
- Data Breach Record, which handles an unauthorised disclosure or loss of data, a different duty with a different clock and no search-and-redact obligation.
- Data Protection Impact Assessment, which assesses a new system before it processes personal data, not a request about data already held.
- An employment grievance or disciplinary record, which the search may surface material from but does not itself replace; redacting it is this record's job.
- Anything outside KnowComply, which belongs in the workspace that owns that process
Global
Subject Access Request Record requirements by country
The right of access is close to universal. What varies is the deadline length, whether extension is permitted, and how narrowly exemptions such as third-party data are drawn.
State consumer privacy laws such as CCPA/CPRA; no general federal access right for employment records
Access rights are patchy and mostly consumer-facing; an employment request is often company policy or state law, not a single federal right.
The deadline and scope can differ by state and by whether the requester is a consumer or an employee, so the record needs a per-case distinction, not one rule.
UK GDPR Art.15; Data Protection Act 2018, Schedule 2 exemptions
One calendar month to respond, extendable by two further months for complex requests, with narrowly drawn exemptions for third-party data and specific categories.
The ICO treats the one-month clock as running from receipt regardless of whether identity has yet been verified, so verification needs to happen fast.
EU GDPR Art.15
The one-month, extendable-to-three-month standard most non-EU access regimes have converged toward.
Even outside the EU's direct reach, GDPR's access deadline has become the practical benchmark a response is measured against.
How to complete it
How to complete a subject access request record, step by step
The template walks the request through search, preparation and response. What decides whether the response satisfies it is judgement none of those sections enforce by themselves.
All Systems Searched, Occupational Health Records Considered and Monitoring And Camera Data Considered are separate fields because a search stopping at HR routinely misses the material a requester actually wants. A response prepared against an incomplete search is incomplete, not faster.
Third Party Data Redacted and Exemptions Applied Correctly force a narrow application: redact the third party's name from a paragraph, not the paragraph, and never the whole document, unless the two are inseparable.
Health Data Handled Appropriately exists because occupational health records carry a stricter handling duty than general personnel data, and monitoring data is easy to forget since it does not live in HR. Both categories are named explicitly because searches routinely miss them.
Extension Applied distinguishes a justified extension, properly communicated, from an unjustified one reflecting a late response. Days Taken should reflect actual elapsed time regardless, since that honest figure is what scoring and any complaint will be measured against.
What auditors find
Most common subject access request record findings
The findings below concern whether the search was complete and the response answers the request, not whether the form was filled in on time.
| Finding | Clause | What fixes it |
|---|---|---|
| Occupational health or monitoring data excluded from the search with no note explaining why. | ISO 27701 cl.7.3 | Require a reason wherever Occupational Health Records Considered or Monitoring And Camera Data Considered is marked No or Partly. |
| Third-party data redacted by withholding the entire document rather than the specific material. | UK DPA 2018 Sch.2 | Redact at the level of the specific reference, and require a note on what was withheld and why. |
| Identity Verified recorded as Assumed for a request involving sensitive data. | ISO 27701 cl.7.3 | Do not allow disclosure on Assumed identity where the request scope includes health or special category data. |
| Response sent without Rights Explained or Complaint Route Explained. | GDPR Art.15 | Include the standard notice on further rights and the complaint route in every response, not only a partial refusal. |
| Extension Applied marked Yes, justified, with no evidence the requester was actually told. | GDPR Art.12(3) | Retain the communication to the requester as evidence alongside the extension decision, not just the internal record. |
| Days Taken recorded but Responded Within The Deadline marked Yes on a request that was, on the dates given, late. | GDPR Art.12(3) | Calculate Responded Within The Deadline from Request Received and Statutory Deadline directly, not as a manual judgement. |
Case in point
Case in point: the response that answered the request and missed the footage
A former employee raised a subject access request after a disciplinary process, asking for everything held about them. HR searched the personnel file, case notes and email, redacted two colleagues' names, and responded within the one-month deadline. Response Complete and Rights Explained were both recorded Yes.
The complaint that followed was not about the redactions. It was about CCTV footage the requester knew existed, mentioned in a meeting, which nobody had searched for because it lived with facilities management, not HR. The response was thorough within systems HR controls, and incomplete against the request as understood. The fix was making Monitoring And Camera Data Considered its own required field, so a request cannot close without someone outside HR confirming camera data was checked.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
6 sections
- Reference
- CMP-034
- Archetype
- Record
- Record ID
- SAR-2026-000
- Scoring
- Responded on time
- Direction
- High is good
- Singleton
- Yes
- Basis
- ISO 27701 cl.7.3
- Links
- Links Personal data record, Health records
- Tags
- Privacy, Access
- Sections
- 6
- Fields
- 46
- Follow up fields
- 3
- Repeating sections
- 0
- Links out
- 3
Header
13 fieldsRequest ID*
Auto sequence. Format SAR-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Request Received*
Requester Type*
Identity Verified*
- Yes3 pts
- Assumed0 pts
Request Scope*
Statutory Deadline*
Extension Applied*
- No3 pts
- Yes, justified2 pts
- Yes, unjustified0 pts
Health And Monitoring Records Are The Hard Ones
Assembling everything held about one person means occupational health, camera footage, telematics and every manager's notes. Start early.
Search
6 fieldsAll Systems Searched*
- Yes3 pts
- Partly1 pt
- No0 pts
Occupational Health Records Considered*
- Yes3 pts
- Partly1 pt
- No0 pts
Monitoring And Camera Data Considered*
- Yes3 pts
- Partly1 pt
- No0 pts
Email And Messaging Searched*
- Yes3 pts
- Partly1 pt
- No0 pts
Paper Records Searched*
- Yes3 pts
- Partly1 pt
- No0 pts
Manager Notes Included*
- Yes3 pts
- Partly1 pt
- No0 pts
Preparation
6 fieldsThird Party Data Redacted*
- Yes3 pts
- Partly1 pt
- No0 pts
Exemptions Applied Correctly*
- Yes3 pts
- Partly1 pt
- No0 pts
Health Data Handled Appropriately*
- Yes3 pts
- Partly1 pt
- No0 pts
Legal Privilege Considered*
- Yes3 pts
- Partly1 pt
- No0 pts
Response Reviewed Before Release*
- Yes3 pts
- Partly1 pt
- No0 pts
Format Accessible To The Requester*
- Yes3 pts
- Partly1 pt
- No0 pts
Response
6 fieldsResponded Within The Deadline*
- Yes3 pts
- Partly1 pt
- No0 pts
Response Complete*
- Yes3 pts
- Partly1 pt
- No0 pts
Explanation Of Processing Provided*
- Yes3 pts
- Partly1 pt
- No0 pts
Rights Explained*
- Yes3 pts
- Partly1 pt
- No0 pts
Complaint Route Explained*
- Yes3 pts
- Partly1 pt
- No0 pts
Record Of The Response Retained*
- Yes3 pts
- Partly1 pt
- No0 pts
Related records
1 fieldProcessing Register ID
The register that says what is held about this person.
Links to CMP-031 Register ID
Outcome
14 fieldsResponded On Time*
- Yes3 pts
- Late0 pts
Days Taken*
Complaint Received*
- No3 pts
- Yes0 pts
Process Improvement Identified*
- No3 pts
- Yes1 pt
Register Updated*
- Yes3 pts
- No0 pts
Record Retention Until
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Privacy Lead*
Signature*
HR*
Second Signature*
CMP-034 · record IDs look like SAR-2026-000 · Links Personal data record, Health records
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The form captures the response. What determines whether a request is answered in full is whether the search reaches systems outside the privacy lead's own view.
Holds the request register against the processing register, starts the statutory deadline on receipt, and flags a request approaching it.
Surfaces occupational health records the moment a request scope could include them, so the search does not stop at the general file.
Extends the search to telematics and vehicle monitoring data where the requester is a driver or the scope names it.

Checks a completed search against the processing register for gaps, and raises a request nearing its deadline before it becomes late.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Subject Access Request Record definitions and key terms
- Subject access request
- A request from an individual for confirmation that their personal data is processed, access to it, and specified information about how it is processed, made under the access right in data protection law.
- Third-party data
- Personal data in the response identifying someone other than the requester, such as a colleague named in a note, which must generally be redacted unless disclosed with consent or inseparable from the requester's own data.
- Statutory deadline
- The legal time limit for responding, typically one calendar month from receipt, extendable in defined circumstances rather than at the responder's discretion.
- Exemption
- A narrowly defined ground in data protection law for withholding particular material, such as legal professional privilege, applied to that material only, not the whole request.
- Monitoring data
- Data generated by watching or tracking activity, including CCTV footage, access logs and telematics, which is in scope for a request even though it rarely lives in an HR system.
FAQ
Frequently asked questions about subject access request record
What is a subject access request record?+
It documents a request from an individual for the data held about them: what was searched, what was withheld and why, and whether the response met the statutory deadline, one record per request.
How long is there to respond?+
One calendar month from receipt in most regimes modelled on GDPR, extendable by up to two further months for complex requests, provided the requester is told of the extension and reason within the original month.
What does the search have to cover?+
Every system that might hold personal data about the requester, not only HR or CRM: email, paper files, manager's notes, occupational health and monitoring or camera data, the material most often missed.
Can data about other people be included?+
Only with redaction where it identifies a third party, applied to the specific material rather than the whole document, unless that information genuinely cannot be separated from the requester's own or they consent.
How is a subject access request record scored?+
Responded on time, high is good. It rewards a complete search and a response within the statutory deadline, whether or not an extension was needed, over a fast but incomplete one.
Who owns this record?+
The privacy lead, from receipt through search, preparation and response, with HR and a second signature required to close it, reflecting how often the material sits in employment records.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Data Protection and Information Security
Personal Data Processing Record
Records what personal data the organisation holds, why, on what basis and for how long
Data Protection Impact Assessment
Assesses the privacy impact of a new system or monitoring activity before it is introduced
Data Breach Record
Records loss, exposure or unauthorised access to personal data, with the assessment of harm and notification decision
Information Security Risk Assessment
Assesses threats to systems, data and operational technology, including plant control systems
System Access Review
Reviews who has access to which systems and at what privilege level
Cyber Incident Record
Records a cyber event affecting systems, data or plant operation, with containment, recovery and notification
More in Data and Privacy
Personal Data Processing Record
Records what personal data the organisation holds, why, on what basis and for how long
Data Protection Impact Assessment
Assesses the privacy impact of a new system or monitoring activity before it is introduced
Data Breach Record
Records loss, exposure or unauthorised access to personal data, with the assessment of harm and notification decision

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO/IEC 27701:2019, clause 7.3, Obligations to PII principals
- Regulation (EU) 2016/679 (GDPR), Articles 15 and 12(3)
- UK Data Protection Act 2018, Schedule 2
- ICO, Right of access guidance
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.