SAR Data Protection: UK Employer Guide to the Legal Framework
Published 16 July 2026
"SAR" and "data protection" are tightly linked — a subject access request is a data subject right under UK data protection law. But the specific obligations employers face come from three overlapping pieces of legislation, not one. Understanding which statute does what is the foundation for responding correctly.
This guide explains the legal framework behind SARs in the UK — what UK GDPR requires, what the Data Protection Act 2018 adds, and what changed in 2025.
This guide covers the UK data protection legal framework for subject access requests. It is not legal advice.
The three-layer UK data protection framework
UK data protection law for SARs works across three statutes that interact:
1. UK GDPR — the primary right and basic obligations
UK GDPR Article 15 creates the right of access — the right for any individual to obtain confirmation that you process their personal data and a copy of it, alongside supplementary information about the processing.
UK GDPR is the "retained" version of the EU General Data Protection Regulation, incorporated into UK law after Brexit. It sits as retained EU law and is amended by Parliament, not the EU.
Key Article 15 obligations:
- Provide a copy of personal data within one calendar month
- Provide supplementary information: purposes, categories, recipients, retention periods, the individual's rights
- Do so free of charge in almost all cases
- Respond in a concise, intelligible, and easily accessible form
2. Data Protection Act 2018 — UK-specific detail and exemptions
The Data Protection Act 2018 (DPA 2018) provides the UK-specific scaffolding around UK GDPR. For SARs, its most important function is defining the exemptions in Schedule 2, Part 4.
The DPA 2018 exemptions that matter most for employers:
| Exemption | DPA 2018 reference | What it covers |
|---|---|---|
| Legal professional privilege | Schedule 2, para 19 | Information that would be protected by legal privilege in proceedings (solicitor advice, litigation-privileged docs) |
| Management forecasts | Schedule 2, para 22 | Data for management planning purposes where disclosure would prejudice the business |
| Negotiations | Schedule 2, para 23 | Records of intentions in negotiations with the data subject |
| Confidential references | Schedule 2, para 24 | References given in confidence by the data controller about the individual |
Each exemption applies to specific data items, not to categories. "All our legal files are exempt" is not a valid approach. See SAR Exemptions Explained for how to apply each correctly.
3. Data (Use and Access) Act 2025 — the 2025 amendments
The Data (Use and Access) Act 2025 (DUAA 2025) received Royal Assent on 19 June 2025, with most data protection provisions in force from 5 February 2026. It amends UK GDPR rather than replacing it.
Two DUAA 2025 changes affect SAR handling directly:
Stop the clock (section 76): Section 76 amends UK GDPR Article 12 to allow the response period to pause while you:
- Wait for identity verification from the requester
- Wait for clarification to narrow a broad request
Before DUAA 2025, the one-month clock ran continuously from receipt even if you were waiting for the requester to confirm identity. Now the "applicable time period" starts only once the requester provides what you have asked for.
Reasonable and proportionate search (section 78): Section 78 codifies that the data subject is entitled to the personal data the controller is able to provide "based on a reasonable and proportionate search." This reflects long-standing ICO guidance and case law, now placed on a statutory footing.
Practically: you do not need to restore every backup tape or search decommissioned systems. You do need to document what you searched and why that scope was reasonable.
What "personal data" means for SARs
A SAR covers all personal data the employer holds about the requester — not just what they think is in their file. Under UK GDPR Article 4(1), personal data is any information relating to an identified or identifiable natural person.
In a typical employee SAR, that includes:
- HR records and personnel files
- Payroll and benefits data
- Emails where the requester is named or identifiable (including emails about them in others' mailboxes)
- Performance management and disciplinary records
- Instant messaging logs
- CCTV footage — see CCTV Subject Access Request: What UK Employers Must Disclose
- Occupational health records (subject to specific conditions)
The ICO uses the phrase "all the data" — not just what was formally filed or stored in your HRIS.
The relationship between data protection law and SAR process
Knowing the legal framework is the first step. The second is turning it into a consistent response process. The Subject Access Request Process guide covers how to set up a repeatable workflow across data categories and systems. For the complete step-by-step response guide see How to Respond to a Subject Access Request from an Employee.
Key process requirements that flow from data protection law:
Deadline tracking. One calendar month from receipt (DUAA 2025 stop-the-clock applies). See Subject Access Request Time Limit UK.
Audit trail. The ICO expects you to be able to demonstrate what you did: which systems you searched, which exemptions you applied, why. No audit trail means no defence if a complaint is filed.
Response completeness. The response must include supplementary information (Article 15(1)(b)-(h)) — not just the data. Many employer responses fail on this point.
Secure transmission. Personal data sent in response to a SAR must be sent securely. Unencrypted email with a full SAR disclosure is a data breach risk.
ICO enforcement context
The ICO's annual report for 2022-23 recorded over 16,000 SAR complaints — the largest single category of data protection complaints. The majority were resolved by compliance rather than formal enforcement, but:
- ICO reprimands for SAR handling failures are publicly listed
- SAR non-compliance during employment disputes escalates tribunal costs
- Persistent failures can lead to enforcement notices and fines
The higher UK GDPR penalty tier is £17.5 million or 4% of annual worldwide turnover. SMEs are unlikely to face top-tier fines for SAR handling failures, but ICO reprimands are reputationally significant and increase scrutiny for subsequent complaints.
Data protection policies and SAR readiness
The ICO's guidance on accountability (UK GDPR Article 5(2)) expects organisations to be able to demonstrate compliance — not just comply. For SARs, that means having:
- A written SAR policy covering who handles requests and how
- A documented search scope per SAR
- A record of exemptions applied and why
- Proof of dispatch and response date
If you do not have a policy, see How to Write a Subject Access Request Policy for UK Employers.
For response letter templates — acknowledgement, extension notices, and cover letters — see the DSAR template guide for UK employers.
Sources
- UK GDPR — Article 15 (right of access)
- UK GDPR — Article 4 (definitions)
- UK GDPR — Article 12 (transparency and time limits)
- Data Protection Act 2018 — Schedule 2, Part 4 (exemptions)
- Data (Use and Access) Act 2025 — Section 76 (stop the clock)
- Data (Use and Access) Act 2025 — Section 78 (reasonable and proportionate search)
- ICO — Right of access (subject access) guidance
This guide provides general information about UK data protection law as it applies to subject access requests. It is not a substitute for legal advice.
Handle your next SAR step by step
dsartracker guides UK employers through every stage of a subject access request — deadlines, exemptions, redaction, and the audit trail the ICO expects.
Related guides
CCTV Subject Access Request: What UK Employers Must Disclose
What UK employers must do when a SAR covers CCTV footage — which footage to disclose, how to redact third parties, retention obligations, and common ICO complaint triggers.
DSAR Template for UK Employers: Examples and How to Use Them
Free DSAR template examples for UK employers — acknowledgement, extension notice, and response cover letter — with guidance on adapting each for your SAR.
GDPR and Subject Access Requests: An Employer's Legal Duties
What UK GDPR requires of employers when a subject access request arrives — the right of access, your obligations, the 2025 law changes, and where SMEs go wrong.