Personal data requests (subject access): recognising and routing
For front-line, office, HR, customer service and team-lead staff who might receive a request for someone's own personal data: by email, phone, in person, by letter or on social media. Complete 'Personal data at work: recognize, protect and report' first. This course goes further with an inbox of realistic requests, the details to log, how the one-month clock works under the UK GDPR (including extensions and 'stopping the clock'), requests from solicitors, portals, parents and children, and what not to do once a request has arrived. It includes a short US note on the HIPAA right of access for health records. UK guidance comes from the Information Commissioner's Office (ICO), updated for the Data (Use and Access) Act 2025; the US note uses 45 CFR 164.524. Your privacy team or data protection officer decides how to answer; your job is to recognise and route. This course is not legal advice, and rules differ in other countries and sectors.
- Level
- Beginner
- Length
- About 66 minutes
- Contents
- 5 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Recognise a subject access request however it arrives, including verbal, social media and FOI-labelled requests
- Record and route a subject access request the same day without changing or deleting the data it covers
- Calculate a subject access response deadline, including extensions and stopping the clock
- Route requests made on someone else's behalf or about a child without disclosing anything yourself
- Distinguish a UK GDPR subject access request from a US HIPAA right-of-access request for health records
Course outline
- 1.Recognising a subject access request however it arrivesLesson · 15 min
- 2.Recording and routing a subject access request the same dayLesson · 13 min
- 3.Calculating a subject access response deadline, including extensions and stopping the clockLesson · 14 min
- 4.Routing requests made on someone else's behalf or about a childLesson · 13 min
- 5.Distinguishing a UK GDPR subject access request from a US HIPAA right-of-access requestLesson · 7 min
- 6.Personal data requests (subject access): recognising and routing: knowledge checkKnowledge check · 14 questions
- 7.Personal data requests (subject access): recognising and routing: practical exerciseKnowledge check · 1 question
- 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- ICO: A guide to subject access (in brief; updated 16 July 2026 for the Data (Use and Access) Act 2025)
- ICO Right of access (detailed guidance): How do we recognise a subject access request (SAR)? (updated 7 April 2026)
- ICO Right of access (detailed guidance): What should we consider when responding to a request? (time limits, extensions, clarification, ID)
- ICO Right of access (detailed guidance): How do we find and retrieve the relevant information? (amending or deleting after a request)
- 45 CFR 164.524 Access of individuals to protected health information (US HIPAA Privacy Rule), via Cornell LII
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.