Create a bespoke document in minutes, or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Subject Access Request
I need a subject access request document to request all personal data held by a company about me, including any processing activities, data sources, and third-party sharing. The document should include a clear request for a response within the statutory timeframe and specify the preferred format for receiving the data.
What is a Subject Access Request?
A Subject Access Request lets you ask organizations to share all the personal information they have about you - it's your fundamental right under India's proposed data protection laws. Think of it as a formal way to peek behind the curtain and see exactly what data companies are storing about you.
When you submit this request, organizations must respond within a reasonable timeframe, typically 30 days. They need to tell you what information they hold, how they use it, and who else might have access to it. This transparency tool helps Indians exercise control over their personal data, following principles similar to those in the Personal Data Protection Bill.
When should you use a Subject Access Request?
Submit a Subject Access Request when you need to understand exactly what personal information an organization holds about you in India. It's particularly useful before taking legal action, when applying for jobs and want to see your records, or if you suspect your data has been mishandled or shared without permission.
Common triggers include discovering unexpected entries on your credit report, needing to verify your medical history across healthcare providers, or wanting to check what information schools or employers maintain about you. Many Indians use these requests to protect their privacy rights, especially when dealing with financial institutions or technology companies that process large amounts of personal data.
What are the different types of Subject Access Request?
- Dsar Form: A streamlined format commonly used in India for requesting personal data from private companies and tech firms, focusing on basic identification and specific data categories.
- Data Subject Access Request Form GDPR: A comprehensive version aligned with international standards, particularly useful when dealing with multinational companies or Indian firms handling EU resident data, including detailed sections for data processing activities and cross-border transfers.
Who should typically use a Subject Access Request?
- Data Subjects: Any individual in India can submit a Subject Access Request to view their personal information, from students checking education records to employees reviewing work files.
- Data Controllers: Organizations that collect and process personal data must respond to these requests, including banks, hospitals, tech companies, and government departments.
- Privacy Officers: Professionals who handle incoming requests, verify identities, gather requested information, and ensure compliance with response deadlines.
- Legal Teams: Lawyers and compliance specialists who review requests, advise on disclosure obligations, and handle complex cases involving multiple data sources.
How do you write a Subject Access Request?
- Personal Details: Gather your full name, contact information, and any relevant ID numbers (Aadhaar, PAN) to prove your identity to the organization.
- Organization Information: Note the exact name and contact details of the company holding your data, including their data protection officer if possible.
- Data Specifics: List the exact information you're seeking - be specific about time periods and types of data.
- Supporting Documents: Attach copies of your ID proof and any previous correspondence with the organization.
- Timeline Planning: Our platform helps generate precise requests while tracking response deadlines, ensuring you meet all legal requirements under Indian data protection laws.
What should be included in a Subject Access Request?
- Identity Verification: Clear proof of who you are, including government-issued ID details and current contact information.
- Request Scope: Specific description of the personal data you're seeking, with relevant time periods and data categories.
- Legal Authority: Reference to India's data protection laws establishing your right to access personal data.
- Response Timeline: Statement requesting response within the legally mandated timeframe (usually 30 days).
- Format Preference: Your preferred method of receiving the information (digital or physical copies).
- Declaration: Statement confirming the request's legitimacy and your identity as the data subject.
What's the difference between a Subject Access Request and an Access Agreement?
A Subject Access Request differs significantly from an Access Agreement. While both deal with access rights, they serve distinct purposes in Indian law and business practice.
- Legal Purpose: Subject Access Requests are individual rights-based tools to view personal data held by organizations, while Access Agreements are contractual documents governing ongoing access to facilities, systems, or information.
- Timing and Duration: Subject Access Requests are one-time requests requiring response within 30 days, whereas Access Agreements establish long-term arrangements and permissions.
- Party Dynamics: Subject Access Requests involve a data subject demanding information from a data controller, while Access Agreements typically involve mutual obligations between business entities or organizations.
- Enforcement Mechanism: Subject Access Requests are backed by data protection laws with specific compliance requirements, while Access Agreements rely on standard contract law for enforcement.
Download our whitepaper on the future of AI in Legal
Genie’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; Genie’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our Trust Centre for more details and real-time security updates.
Read our Privacy Policy.