Skip to content

Personal data requests (subject access): recognising and routing

For front-line, office, HR, customer service and team-lead staff who might receive a request for someone's own personal data: by email, phone, in person, by letter or on social media. Complete 'Personal data at work: recognize, protect and report' first. This course goes further with an inbox of realistic requests, the details to log, how the one-month clock works under the UK GDPR (including extensions and 'stopping the clock'), requests from solicitors, portals, parents and children, and what not to do once a request has arrived. It includes a short US note on the HIPAA right of access for health records. UK guidance comes from the Information Commissioner's Office (ICO), updated for the Data (Use and Access) Act 2025; the US note uses 45 CFR 164.524. Your privacy team or data protection officer decides how to answer; your job is to recognise and route. This course is not legal advice, and rules differ in other countries and sectors.

Level
Beginner
Length
About 66 minutes
Contents
5 lessons · final exam
Status
Published · updated 10 Oct 2026

Skills you'll practise

  • Recognise a subject access request however it arrives, including verbal, social media and FOI-labelled requests
  • Record and route a subject access request the same day without changing or deleting the data it covers
  • Calculate a subject access response deadline, including extensions and stopping the clock
  • Route requests made on someone else's behalf or about a child without disclosing anything yourself
  • Distinguish a UK GDPR subject access request from a US HIPAA right-of-access request for health records

Course outline

  1. 1.Recognising a subject access request however it arrivesLesson · 15 min
  2. 2.Recording and routing a subject access request the same dayLesson · 13 min
  3. 3.Calculating a subject access response deadline, including extensions and stopping the clockLesson · 14 min
  4. 4.Routing requests made on someone else's behalf or about a childLesson · 13 min
  5. 5.Distinguishing a UK GDPR subject access request from a US HIPAA right-of-access requestLesson · 7 min
  6. 6.Personal data requests (subject access): recognising and routing: knowledge checkKnowledge check · 14 questions
  7. 7.Personal data requests (subject access): recognising and routing: practical exerciseKnowledge check · 1 question
  8. 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.