Knowella

Subject Access Request Record

A subject access request record's most common failure is a search that is thorough within the systems the privacy lead controls and blind to everything outside them. HR searches the personnel file and email, answers within the deadline, and the complaint that follows is not about what was redacted but the camera footage or manager's private notes nobody thought to search for.

KnowComplyRecordCMP-03446 fields across 6 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 27701 cl.7.3
Workspace
KnowComply
Form type
Record
Raised
On receipt, with a statutory deadline from day one
Completed by
The privacy lead, from receipt through search, preparation and response

The short version

  • The search is the part most likely to fail, not the redaction. A search stopping at the primary HR system routinely misses exactly the material a requester wants: private notes, camera footage, a message thread.
  • Health and monitoring data need naming as their own search step, since they are the categories most often held outside the system the privacy lead controls directly, and a search that does not ask for them explicitly tends not to find them.
  • An extension has to be justified and communicated, not just applied. The same extra time reads as diligence when the requester was told, and as delay when they were not.
  • Exemptions apply to the specific material they cover, not the whole response: redacting a colleague's name from a paragraph is not the same act as withholding the paragraph or the document.

What this is

What is a subject access request record?

What is a subject access request record?

It documents a request from an individual for the personal data held about them: what was searched, what was withheld and why, and whether the response met the statutory deadline. It stays open until search, preparation and response are complete.

What does the search have to cover?

Every location personal data might be held, not only the primary HR or CRM system: email, paper files, manager's notes, occupational health records and monitoring or camera data. These are the most often requested and hardest to assemble, since they rarely live with the system searched first.

Can a request be refused or delayed?

A response can be extended, not refused outright, where the request is complex or numerous, provided the requester is told of the extension and reason within the deadline. Specific material can be withheld under a defined exemption, such as third-party data or legal privilege, but that applies to the material concerned, not the whole request.

Scope

When is a subject access request record required?

This record is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.

Use this template when

  • An individual has requested confirmation of, or access to, the personal data held about them
  • The workspace is being set up, or the register needs an entry added or retired
  • You are running the Data Protection and Information Security programme and this is one step
  • A linked record needs this one to exist: links personal data record, health records
  • A response, extension or exemption decision needs to be defensible afterwards rather than reconstructed from memory

Do not use it for

  • Personal Data Processing Record, the register a search should be checked against to confirm nothing held has been missed.
  • Data Breach Record, which handles an unauthorised disclosure or loss of data, a different duty with a different clock and no search-and-redact obligation.
  • Data Protection Impact Assessment, which assesses a new system before it processes personal data, not a request about data already held.
  • An employment grievance or disciplinary record, which the search may surface material from but does not replace; redacting it is this record's job, not a reason to route the request there.
  • Anything outside KnowComply, which belongs in the workspace that owns that process

Compliance mapping

Which ISO 27701 cl.7.3 requirements does this satisfy?

ISO 27701 frames access as an obligation owed to the individual directly, distinct from general security controls, and GDPR and equivalent regimes attach a fixed, short deadline and narrow exemptions to that obligation.

ClauseRequirementWhere it lands
ISO 27701 cl.7.3Identity of the requester verified before personal data is disclosed, since disclosure to the wrong person is itself a breachHeader
GDPR Art.12(3)Response provided within one calendar month of receipt, extendable by two further months for complex requests, with the requester told of the extension and reasonHeader
ISO 27701 cl.7.3Search extended across every location personal data may be held, including systems outside the primary recordSearch
GDPR Art.15Access provided to the personal data itself, together with specified supplementary information about how it is processedResponse
UK DPA 2018 Sch.2Exemptions, including third-party data and legal privilege, applied narrowly to the specific material they cover, not the whole responsePreparation
ISO 27701 cl.7.3Fulfilment of the request evidenced and retained, including what was searched, what was withheld and whyOutcome

What it does not cover

  • Personal Data Processing Record, the register a search should be checked against to confirm nothing held has been missed.
  • Data Breach Record, which handles an unauthorised disclosure or loss of data, a different duty with a different clock and no search-and-redact obligation.
  • Data Protection Impact Assessment, which assesses a new system before it processes personal data, not a request about data already held.
  • An employment grievance or disciplinary record, which the search may surface material from but does not itself replace; redacting it is this record's job.
  • Anything outside KnowComply, which belongs in the workspace that owns that process

Global

Subject Access Request Record requirements by country

The right of access is close to universal. What varies is the deadline length, whether extension is permitted, and how narrowly exemptions such as third-party data are drawn.

United States

State consumer privacy laws such as CCPA/CPRA; no general federal access right for employment records

Access rights are patchy and mostly consumer-facing; an employment request is often company policy or state law, not a single federal right.

The deadline and scope can differ by state and by whether the requester is a consumer or an employee, so the record needs a per-case distinction, not one rule.

United Kingdom

UK GDPR Art.15; Data Protection Act 2018, Schedule 2 exemptions

One calendar month to respond, extendable by two further months for complex requests, with narrowly drawn exemptions for third-party data and specific categories.

The ICO treats the one-month clock as running from receipt regardless of whether identity has yet been verified, so verification needs to happen fast.

International

EU GDPR Art.15

The one-month, extendable-to-three-month standard most non-EU access regimes have converged toward.

Even outside the EU's direct reach, GDPR's access deadline has become the practical benchmark a response is measured against.

How to complete it

How to complete a subject access request record, step by step

The template walks the request through search, preparation and response. What decides whether the response satisfies it is judgement none of those sections enforce by themselves.

Search every location before starting the clock on preparation

All Systems Searched, Occupational Health Records Considered and Monitoring And Camera Data Considered are separate fields because a search stopping at HR routinely misses the material a requester actually wants. A response prepared against an incomplete search is incomplete, not faster.

Apply exemptions to the material they cover, not to the whole request

Third Party Data Redacted and Exemptions Applied Correctly force a narrow application: redact the third party's name from a paragraph, not the paragraph, and never the whole document, unless the two are inseparable.

Treat health and monitoring data as the material most likely to be mishandled, not skipped

Health Data Handled Appropriately exists because occupational health records carry a stricter handling duty than general personnel data, and monitoring data is easy to forget since it does not live in HR. Both categories are named explicitly because searches routinely miss them.

Record days taken honestly, including a justified extension

Extension Applied distinguishes a justified extension, properly communicated, from an unjustified one reflecting a late response. Days Taken should reflect actual elapsed time regardless, since that honest figure is what scoring and any complaint will be measured against.

What auditors find

Most common subject access request record findings

The findings below concern whether the search was complete and the response answers the request, not whether the form was filled in on time.

FindingClauseWhat fixes it
Occupational health or monitoring data excluded from the search with no note explaining why.ISO 27701 cl.7.3Require a reason wherever Occupational Health Records Considered or Monitoring And Camera Data Considered is marked No or Partly.
Third-party data redacted by withholding the entire document rather than the specific material.UK DPA 2018 Sch.2Redact at the level of the specific reference, and require a note on what was withheld and why.
Identity Verified recorded as Assumed for a request involving sensitive data.ISO 27701 cl.7.3Do not allow disclosure on Assumed identity where the request scope includes health or special category data.
Response sent without Rights Explained or Complaint Route Explained.GDPR Art.15Include the standard notice on further rights and the complaint route in every response, not only a partial refusal.
Extension Applied marked Yes, justified, with no evidence the requester was actually told.GDPR Art.12(3)Retain the communication to the requester as evidence alongside the extension decision, not just the internal record.
Days Taken recorded but Responded Within The Deadline marked Yes on a request that was, on the dates given, late.GDPR Art.12(3)Calculate Responded Within The Deadline from Request Received and Statutory Deadline directly, not as a manual judgement.

Case in point

Case in point: the response that answered the request and missed the footage

A former employee raised a subject access request after a disciplinary process, asking for everything held about them. HR searched the personnel file, case notes and email, redacted two colleagues' names, and responded within the one-month deadline. Response Complete and Rights Explained were both recorded Yes.

The complaint that followed was not about the redactions. It was about CCTV footage the requester knew existed, mentioned in a meeting, which nobody had searched for because it lived with facilities management, not HR. The response was thorough within systems HR controls, and incomplete against the request as understood. The fix was making Monitoring And Camera Data Considered its own required field, so a request cannot close without someone outside HR confirming camera data was checked.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

46fields
6 sections
Reference
CMP-034
Archetype
Record
Record ID
SAR-2026-000
Scoring
Responded on time
Direction
High is good
Singleton
Yes
Basis
ISO 27701 cl.7.3
Links
Links Personal data record, Health records
Tags
Privacy, Access
Sections
6
Fields
46
Follow up fields
3
Repeating sections
0
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

13 fields
Text

Request ID*

Generated on save

Auto sequence. Format SAR-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Date & Time

Request Received*

Single Choice

Requester Type*

Current workerFormer workerContractorVisitorThird party
Single Choice

Identity Verified*

Scored
  • Yes3 pts
  • Assumed0 pts
Single Choice

Request Scope*

All dataSpecific categorySpecific period
Date & Time

Statutory Deadline*

Single Choice

Extension Applied*

Scored
  • No3 pts
  • Yes, justified2 pts
  • Yes, unjustified0 pts
Info

Health And Monitoring Records Are The Hard Ones

Assembling everything held about one person means occupational health, camera footage, telematics and every manager's notes. Start early.

Search

6 fields
Single Choice

All Systems Searched*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Occupational Health Records Considered*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Monitoring And Camera Data Considered*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Email And Messaging Searched*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Paper Records Searched*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Manager Notes Included*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Preparation

6 fields
Single Choice

Third Party Data Redacted*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Exemptions Applied Correctly*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Health Data Handled Appropriately*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Legal Privilege Considered*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Response Reviewed Before Release*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Format Accessible To The Requester*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Response

6 fields
Single Choice

Responded Within The Deadline*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Response Complete*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Explanation Of Processing Provided*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Rights Explained*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Complaint Route Explained*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Record Of The Response Retained*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Related records

1 field
Text

Processing Register ID

OptionalLinked

The register that says what is held about this person.

Links to CMP-031 Register ID

Outcome

14 fields
Single Choice

Responded On Time*

Scored
  • Yes3 pts
  • Late0 pts
Numeric Answer

Days Taken*

Scored
Single Choice

Complaint Received*

Scored
  • No3 pts
  • Yes0 pts
Single Choice

Process Improvement Identified*

Scored
  • No3 pts
  • Yes1 pt
Single Choice

Register Updated*

Scored
  • Yes3 pts
  • No0 pts
Date & Time

Record Retention Until

Optional
Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Privacy Lead*

Signature

Signature*

Users

HR*

Signature

Second Signature*

CMP-034 · record IDs look like SAR-2026-000 · Links Personal data record, Health records

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The form captures the response. What determines whether a request is answered in full is whether the search reaches systems outside the privacy lead's own view.

KnowComply

Holds the request register against the processing register, starts the statutory deadline on receipt, and flags a request approaching it.

KnowHealth

Surfaces occupational health records the moment a request scope could include them, so the search does not stop at the general file.

KnowFleet

Extends the search to telematics and vehicle monitoring data where the requester is a driver or the scope names it.

Ella
Ella

Checks a completed search against the processing register for gaps, and raises a request nearing its deadline before it becomes late.

This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.

Meet KnowComply→

Glossary

Subject Access Request Record definitions and key terms

Subject access request
A request from an individual for confirmation that their personal data is processed, access to it, and specified information about how it is processed, made under the access right in data protection law.
Third-party data
Personal data in the response identifying someone other than the requester, such as a colleague named in a note, which must generally be redacted unless disclosed with consent or inseparable from the requester's own data.
Statutory deadline
The legal time limit for responding, typically one calendar month from receipt, extendable in defined circumstances rather than at the responder's discretion.
Exemption
A narrowly defined ground in data protection law for withholding particular material, such as legal professional privilege, applied to that material only, not the whole request.
Monitoring data
Data generated by watching or tracking activity, including CCTV footage, access logs and telematics, which is in scope for a request even though it rarely lives in an HR system.

FAQ

Frequently asked questions about subject access request record

What is a subject access request record?+

It documents a request from an individual for the data held about them: what was searched, what was withheld and why, and whether the response met the statutory deadline, one record per request.

How long is there to respond?+

One calendar month from receipt in most regimes modelled on GDPR, extendable by up to two further months for complex requests, provided the requester is told of the extension and reason within the original month.

What does the search have to cover?+

Every system that might hold personal data about the requester, not only HR or CRM: email, paper files, manager's notes, occupational health and monitoring or camera data, the material most often missed.

Can data about other people be included?+

Only with redaction where it identifies a third party, applied to the specific material rather than the whole document, unless that information genuinely cannot be separated from the requester's own or they consent.

How is a subject access request record scored?+

Responded on time, high is good. It rewards a complete search and a response within the statutory deadline, whether or not an extension was needed, over a fast but incomplete one.

Who owns this record?+

The privacy lead, from receipt through search, preparation and response, with HR and a second signature required to close it, reflecting how often the material sits in employment records.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO/IEC 27701:2019, clause 7.3, Obligations to PII principals
  • Regulation (EU) 2016/679 (GDPR), Articles 15 and 12(3)
  • UK Data Protection Act 2018, Schedule 2
  • ICO, Right of access guidance

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.