¶¶Òõ¶ÌÊÓÆµ

Data Subject Access Request Form Template for England and Wales

Create a bespoke document in minutes,  or upload and review your own.

4.6 / 5
4.8 / 5

Let's create your Data Subject Access Request Form

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Get your first 2 documents free

Your data doesn't train Genie's AI

You keep IP ownership of your information

Key Requirements PROMPT example:

Data Subject Access Request Form

"I need a Data Subject Access Request Form for our UK-based healthcare company that handles sensitive medical data, with specific sections for patient consent and medical record identification, ensuring compliance with both GDPR and healthcare regulations."

Document background
The Data Subject Access Request Form is a crucial document required under UK data protection legislation. It enables individuals to exercise their fundamental right to access personal data held about them by organizations. The form helps organizations process requests efficiently while ensuring compliance with the UK GDPR and Data Protection Act 2018. It should be used whenever an individual wishes to obtain information about what personal data an organization holds about them, how it's being used, and who it's being shared with.
Suggested Sections

1. Personal Information: Data subject's full name, address, contact details, and any reference numbers or identifiers

2. Identity Verification: Details of required proof of identity and address documentation

3. Request Details: Specific information being requested, including relevant time periods and departments

4. Preferred Response Format: How the data subject would like to receive their information (e.g., electronic, hard copy)

5. Declaration: Statement confirming the request is legitimate and information provided is accurate

Optional Sections

1. Third Party Authorization: Section to be completed when someone is making a request on behalf of another person

2. Specific Department Details: Optional section for specifying particular departments or services the request relates to

3. Previous Correspondence: Optional section for referencing any previous communication about this matter

4. Urgency Request: Section for indicating if the request requires expedited processing and reasons why

Suggested Schedules

1. Schedule 1: Acceptable ID Documents: List of acceptable forms of identification and address verification

2. Schedule 2: Third Party Authorization Form: Template form for authorizing another person to make the request

3. Schedule 3: Privacy Notice: Information about how the personal data provided in this form will be processed

4. Schedule 4: Guide to DSARs: Information about response times, fees, and what to expect after submission

Authors

Alex Denne

Head of Growth (Open Source Law) @ ¶¶Òõ¶ÌÊÓÆµ | 3 x UCL-Certified in Contract Law & Drafting | 4+ Years Managing 1M+ Legal Documents | Serial Founder & Legal AI Author

Relevant legal definitions

























Clauses




















Relevant Industries
Relevant Teams
Relevant Roles
Industries

UK GDPR: The UK General Data Protection Regulation - primary legislation governing data protection rights and obligations in the UK post-Brexit, including the fundamental right of data subject access under Article 15

DPA 2018: Data Protection Act 2018 - the UK's implementation of data protection laws, including specific exemptions under Schedule 2 that may affect data subject access requests

ICO Guidance: Regulatory guidance from the Information Commissioner's Office specifically addressing how organizations should handle Data Subject Access Requests

EDPB Guidelines: European Data Protection Board guidelines which, while not binding post-Brexit, remain influential in UK data protection practices

Time Limit Requirements: Statutory requirement to respond to DSARs within one month, with possible extensions for complex requests

Identification Requirements: Legal obligation to verify the identity of the person making the DSAR before disclosing personal data

Fee Regulations: Rules regarding DSAR fees - typically free of charge, but reasonable fees may be charged for excessive or repetitive requests

Format Requirements: Obligations regarding the format in which personal data should be provided to the data subject

Human Rights Act 1998: Legislation protecting fundamental rights including the right to privacy, which intersects with data protection rights

Freedom of Information Act 2000: Legislation relevant when the organization receiving the DSAR is a public body, potentially affecting how requests are handled

PECR: Privacy and Electronic Communications Regulations - additional rules that may be relevant when handling electronic personal data

Teams

Employer, Employee, Start Date, Job Title, Department, Location, Probationary Period, Notice Period, Salary, Overtime, Vacation Pay, Statutory Holidays, Benefits, Bonus, Expenses, Working Hours, Rest Breaks,  Leaves of Absence, Confidentiality, Intellectual Property, Non-Solicitation, Non-Competition, Code of Conduct, Termination,  Severance Pay, Governing Law, Entire Agreemen

Find the exact document you need

Data Subject Rights Request Form

find out more

Data Subject Access Request Form GDPR

find out more

Data Protection Request Form

find out more

Subject Access Request Form

A standardized form under English and Welsh law enabling individuals to request access to their personal data held by organizations.

find out more

Dsar Form

A standardized form under English and Welsh law for individuals to request access to their personal data held by organizations, as per UK GDPR requirements.

find out more

Data Subject Access Request Form

A standardized form under English and Welsh law enabling individuals to request access to their personal data held by organizations.

find out more

Download our whitepaper on the future of AI in Legal

By providing your email address you are consenting to our Privacy Notice.
Thank you for downloading our whitepaper. This should arrive in your inbox shortly. In the meantime, why not jump straight to a section that interests you here: /our-research
Oops! Something went wrong while submitting the form.

³Ò±ð²Ô¾±±ð’s Security Promise

Genie is the safest place to draft. Here’s how we prioritise your privacy and security.

Your documents are private:

We do not train on your data; ³Ò±ð²Ô¾±±ð’s AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

Our bank-grade security infrastructure undergoes regular external audits

We are ISO27001 certified, so your data is secure

Organizational security

You retain IP ownership of your documents

You have full control over your data and who gets to see it

Innovation in privacy:

Genie partnered with the Computational Privacy Department at Imperial College London

Together, we ran a £1 million research project on privacy and anonymity in legal contracts

Want to know more?

Visit our for more details and real-time security updates.