Respond to a subject access request (SAR)

Handling SARs correctly is essential for compliance and client trust. This guide explains what solicitors need to do to meet UK GDPR requirements and safeguard privileged information.

Anyone can ask for a copy of any personal data your practice holds on them. This is known as a subject access request (SAR).

You must respond to a SAR as soon as possible. The deadline to respond is within one month.

The one-month timeframe starts once you receive the SAR, or from when you receive any information you request to:

  • confirm the data subject’s identity
  • confirm that a third party is authorised to act on behalf of the data subject
  • collect a fee

Most of the time, you should respond to SARs for free. You can charge a reasonable fee for administrative costs if the request is manifestly unfounded or excessive, or if further copies of the same data are requested.

For more information, see the Information Commissioner's Office (ICO) SAR fees guidance.