Data Subject Access Request Form GDPR Template for England and Wales

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Data Subject Access Request Form GDPR?

The Data Subject Access Request Form GDPR is a crucial tool for implementing data protection rights under UK law. Created in response to GDPR requirements and maintained under the UK GDPR and Data Protection Act 2018, this form enables individuals in England and Wales to exercise their fundamental right to access personal data. Organizations must respond to these requests within one month, making this standardized form essential for efficient processing and compliance with data protection obligations.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

England and Wales

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Data Subject Access Request Form GDPR

A Data Subject Access Request Form GDPR is your legal tool for requesting access to personal data that organizations hold about you. Under England and Wales law, this form helps you exercise fundamental data protection rights established by the UK GDPR and Data Protection Act 2018, ensuring you can obtain information about how your data is processed, stored, and used.

When do you need this document?

You need this form when requesting access to personal data from any organization operating in England and Wales. Common situations include requesting your employment records from current or former employers, obtaining medical records from healthcare providers, accessing financial information from banks or insurance companies, or retrieving customer data from online retailers. The form is also essential when you suspect data breaches, want to verify information accuracy, or need documentation for legal proceedings. Organizations across all sectors - from small businesses to large corporations, government agencies to charities - must respond to properly submitted requests.

Key legal considerations

Your request must be specific and reasonable in scope, clearly identifying the personal data you seek and any relevant time periods. Organizations can request additional information to verify your identity, but cannot charge fees unless your request is manifestly unfounded or excessive. The data controller must respond within one month, though this can be extended to three months for complex requests. You have the right to receive information in a commonly used electronic format, and organizations must provide clear explanations of any technical terms or data processing activities. Be aware that certain exemptions may apply, including national security, law enforcement, or where disclosure would affect others' rights. Organizations cannot refuse requests simply because they find them inconvenient.

Legal requirements in England and Wales

Under the UK GDPR Article 15 and Data Protection Act 2018 Section 45, organizations must provide comprehensive information including confirmation of data processing, purposes of processing, categories of personal data, retention periods, and sources of information. The Information Commissioner's Office (ICO) provides specific guidance on handling these requests, emphasizing that organizations must have clear procedures and staff training. Failure to respond appropriately can result in ICO enforcement action, including fines up to £17.5 million or 4% of annual turnover. Organizations must also inform you of your right to lodge complaints with the ICO and your rights to rectification, erasure, or restriction of processing. The form must accommodate reasonable adjustments for individuals with disabilities and be available in accessible formats when requested.

GOVERNING LAW

Applicable law

This Data Subject Access Request Form GDPR is drafted to comply with England and Wales law. Key legislation includes:

UK GDPR: The United Kingdom General Data Protection Regulation - primary legislation governing data protection in the UK post-Brexit, particularly Article 15 (Right of access) and Article 12 (Transparent information and communication)

DPA 2018: Data Protection Act 2018 - the UK's implementation of data protection laws, particularly Section 45 regarding right of access by data subjects and Schedule 2 exemptions

ICO Guidance: Information Commissioner's Office regulatory guidance on handling Data Subject Access Requests, including practical implementation and best practices

EDPB Guidelines: European Data Protection Board guidelines - while not binding post-Brexit, these remain influential for UK data protection practices

Time Limits: Legal requirement to respond to DSARs within one month, with possible extension under specific circumstances

Identification Requirements: Legal obligation to verify the identity of the person making the DSAR to ensure data security and prevent unauthorized access

Fee Regulations: Rules regarding DSAR processing fees - generally free of charge, except for manifestly unfounded or excessive requests

Verification Methods: Legitimate means of verifying the identity of the data subject making the request

Response Format: Requirements for the format in which personal data should be provided to the data subject

DPA Exemptions: Exemptions under Schedule 2 of Data Protection Act 2018 where certain data may be withheld from DSAR responses

Plain Language Requirement: Legal obligation to provide information in clear and plain language, in a concise, transparent, intelligible and easily accessible form

Submission Methods: Acceptable methods for submitting DSARs, including verbal, written, electronic, and third-party requests

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it