Privacy & Data Protection

Subject Access Request Procedure

A subject access request procedure template defining how data subject access requests are received, verified, fulfilled within statutory deadlines and recorded, aligned to GDPR, ISO 27001, CCPA.

14-20 pages|Updated 2026-09-12|3 frameworks

What's Included

1. Purpose & Scope

Objective and the rights covered.

Policy ObjectiveRights in ScopeRoles and Responsibilities

2. Receipt & Logging

Recognising a request whatever form it arrives in.

Valid ChannelsRecognition TrainingLogging RequirementsAcknowledgement

3. Identity Verification

Preventing disclosure to the wrong person.

Verification StandardsProportionalityThird-Party RequestsRefusal on Verification Failure

4. Search & Retrieval

Finding the data.

Systems to SearchSearch RecordsThird-Party Processors

5. Review & Redaction

What must be withheld.

Third-Party DataExemptionsLegal PrivilegeRedaction Records

6. Response & Deadlines

Meeting the statutory clock.

Response DeadlineExtension ConditionsResponse FormatFee Conditions

7. Records & Review

Evidence and cadence.

Request RegisterDeadline PerformanceAnnual Policy Review

Frequently Asked Questions

What should a subject access request procedure include?

A comprehensive subject access request procedure should include purpose & scope, receipt & logging, identity verification, search & retrieval, and more. This template covers 7 key sections aligned to GDPR, ISO 27001, CCPA requirements.

Which frameworks require a privacy & data protection policy?

Major frameworks requiring privacy & data protection policies include GDPR, ISO 27001, CCPA. This template maps directly to their control requirements, making it easier to demonstrate compliance across multiple standards.

How often should a subject access request procedure be reviewed?

Best practice is to review your subject access request procedure at least annually, or whenever significant changes occur in your organisation, technology environment, or regulatory landscape. Most frameworks including ISO 27001 and NIST CSF require documented policy review cycles.

Build Your Compliance Programme

Pair this policy template with our compliance platform to map controls across 686+ frameworks, run self-assessments, and get AI-powered compliance advisory.

Get Started Free →

Free forever — no credit card required