Subject Access Request (SAR) Process Guide
Step-by-step guidance for handling patient and staff Subject Access Requests in a GP practice, including timelines, verification, and redaction obligations.
## Handling Subject Access Requests
### What is a SAR?
A Subject Access Request is a request from an individual to receive a copy of personal data held about them. Under UK GDPR, you must respond within **one calendar month** (extendable to 3 months for complex requests, with notification).
### Receiving a SAR
- Log the request immediately with date received
- Verify the requester's identity before releasing any data
- For patient records, use the GP Access Request Form
- Note: there is no fee for SARs (since GDPR replaced the DPA 1998)
### What to Include
- All personal data held about the individual
- The purposes of processing
- Who data is shared with
- Retention periods
### Third-Party Redaction
You must redact information about identifiable third parties before releasing records. This includes other patients' data and, in some cases, clinician names if they are not directly involved in the requester's care.
### Special Categories
Clinical records contain special category data. Take particular care with mental health records, HIV status, sexual health, and genetic data.
### Refusal Grounds
You may refuse a SAR if it is manifestly unfounded or excessive. Document your reasoning carefully.
### After Completion
File a copy of the response and log the SAR as closed in your data register.
Sign in to save this resource.
Added 9 July 2026 · 0 views