{"id":178800,"date":"2022-11-28T13:41:59","date_gmt":"2022-11-28T13:41:59","guid":{"rendered":"https:\/\/legalvision.co.uk\/?p=178800"},"modified":"2026-04-24T05:49:06","modified_gmt":"2026-04-24T04:49:06","slug":"documents-sar","status":"publish","type":"post","link":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/","title":{"rendered":"What Documents Should My Business in the UK Disclose Following a Subject Access Request?"},"content":{"rendered":"\n<p>A Subject Access Request (SAR) gives individuals the legal right to obtain a copy of their personal data held by an organisation. Under the UK GDPR, businesses must handle these requests carefully or risk significant fines from the Information Commissioner&#8217;s Office (ICO). Many organisations find SARs administratively burdensome and the rules surrounding them complex. This article will explore the main types of documents your business should disclose following receipt of a SAR.<\/p>\n\n\n    <div class=\"my-7 lg:my-10 border-y-2 border-gray-100 py-7 lg:py-10 flex flex-col sm:flex-row items-start gap-10\">\n                    <img decoding=\"async\" class=\"w-52 mx-auto my-0! rounded\" src=\"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2024\/09\/30065809\/LV-UK-Personal-Data-Breach-Notification-Factsheet.png\" alt=\"Front page of publication\"\n                 loading=\"lazy\" width=\"208\" height=\"298\">\n                <section>\n            <div class=\"text-2xl font-bold\">Personal Data Breach Notification Factsheet<\/div>\n            <div class=\"body-text\">\n                <p>This factsheet outlines the steps for notifying the ICO and affected individuals about personal data breaches.<\/p>\n            <\/div>\n            \n\n<a href=\"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2024\/09\/30065528\/LegalVision_UK-Personal-Data-Breach-Notification-Factsheet.pdf\" class=\" block px-5 py-3.5 max-w-fit bg-orange button__hover transition rounded text-white font-bold text-lg no-underline uppercase leading-tight text-center\" target=\"\" rel=\"\">Download Now<\/a>        <\/section>\n    <\/div>\n\n\n\n\n<h2 class=\"wp-block-heading\">What is a Subject Access Request?<\/h2>\n\n\n\n<p>A SAR is a (usually written) request from an individual for a copy of all personal information relating to them. The <a href=\"https:\/\/legalvision.co.uk\/data-privacy-it\/subject-access-request-templates\/\">SAR<\/a> usually states whether the individual wishes for digital or printed copies of the data. Some individuals will label them as a Data Subject Access Request or DSAR.<\/p>\n\n\n\n<p>There are two main types of SAR:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>targeted SAR<\/strong>: one in which an individual asks for specific pieces of information (e.g. all emails between them and a specific manager within a <a href=\"https:\/\/legalvision.co.uk\/data-privacy-it\/complying-subject-access-request-timescales\/\">period of time<\/a>); and<\/li>\n\n\n\n<li><strong>general SAR<\/strong>: an individual simply asks for all personal data relating to them during their lifetime.<\/li>\n<\/ol>\n\n\n\n<p>The rules for dealing with both are the same, though you are likely to disclose fewer documents in response to a targeted SAR.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Rules Should My Company Comply With?<\/h2>\n\n\n\n<p>The core rules include the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>confirm receipt of the SAR (usually in writing);<\/li>\n\n\n\n<li>provide the individual with a digital or printed copy of the documents sought (verbally confirming the contents of a document down the phone is not sufficient);<\/li>\n\n\n\n<li>provide the information within one calendar month of receiving the SAR (with limited exceptions where the SAR is exceptionally complex or wide); and<\/li>\n\n\n\n<li>inform the individual whether any other third party has received the relevant documents you may have provided e.g. limited health records to an Occupational Health provider to assist a report.<\/li>\n<\/ul>\n\n\n\n<p>Now we know the nature of a SAR and the core rules, let us consider which documents your organisation should disclose in response to a SAR.<\/p>\n\n\n\n\n<a href=\"#content-next\"\n   class=\"block p-4 mt-10 text-xl font-bold text-center text-white no-underline bg-gray-800 rounded-t-xl\">\n    Continue reading this article below the form\n    <i class=\"text-xl fa-regular fa-arrow-down\"><\/i>\n<\/a>\n<div class=\"px-6 pt-10 pb-12 mb-10 text-center bg-gray-100 rounded-b-xl sm:px-12 test\">\n    <div class=\"mb-8 text-2xl font-bold text-orange\">\n        Need legal advice?\n        <br>\n        <span class=\"text-lg not-prose\">\n                            Call <a href=\"tel:+448081968584\" class=\"not-prose\">0808 196 8584<\/a> for urgent assistance.\n                <br>\n                Otherwise, complete this form, and we will contact you within one business day.\n                    <\/span>\n    <\/div>\n\n    \n\n<div class=\"not-prose flex justify-center text-left gform_input_bg_white    \">\n    <script>\nvar gform;gform||(document.addEventListener(\"gform_main_scripts_loaded\",function(){gform.scriptsLoaded=!0}),document.addEventListener(\"gform\/theme\/scripts_loaded\",function(){gform.themeScriptsLoaded=!0}),window.addEventListener(\"DOMContentLoaded\",function(){gform.domLoaded=!0}),gform={domLoaded:!1,scriptsLoaded:!1,themeScriptsLoaded:!1,isFormEditor:()=>\"function\"==typeof InitializeEditor,callIfLoaded:function(o){return!(!gform.domLoaded||!gform.scriptsLoaded||!gform.themeScriptsLoaded&&!gform.isFormEditor()||(gform.isFormEditor()&&console.warn(\"The use of gform.initializeOnLoaded() is deprecated in the form editor context and will be removed in Gravity Forms 3.1.\"),o(),0))},initializeOnLoaded:function(o){gform.callIfLoaded(o)||(document.addEventListener(\"gform_main_scripts_loaded\",()=>{gform.scriptsLoaded=!0,gform.callIfLoaded(o)}),document.addEventListener(\"gform\/theme\/scripts_loaded\",()=>{gform.themeScriptsLoaded=!0,gform.callIfLoaded(o)}),window.addEventListener(\"DOMContentLoaded\",()=>{gform.domLoaded=!0,gform.callIfLoaded(o)}))},hooks:{action:{},filter:{}},addAction:function(o,r,e,t){gform.addHook(\"action\",o,r,e,t)},addFilter:function(o,r,e,t){gform.addHook(\"filter\",o,r,e,t)},doAction:function(o){gform.doHook(\"action\",o,arguments)},applyFilters:function(o){return gform.doHook(\"filter\",o,arguments)},removeAction:function(o,r){gform.removeHook(\"action\",o,r)},removeFilter:function(o,r,e){gform.removeHook(\"filter\",o,r,e)},addHook:function(o,r,e,t,n){null==gform.hooks[o][r]&&(gform.hooks[o][r]=[]);var d=gform.hooks[o][r];null==n&&(n=r+\"_\"+d.length),gform.hooks[o][r].push({tag:n,callable:e,priority:t=null==t?10:t})},doHook:function(r,o,e){var t;if(e=Array.prototype.slice.call(e,1),null!=gform.hooks[r][o]&&((o=gform.hooks[r][o]).sort(function(o,r){return o.priority-r.priority}),o.forEach(function(o){\"function\"!=typeof(t=o.callable)&&(t=window[t]),\"action\"==r?t.apply(null,e):e[0]=t.apply(null,e)})),\"filter\"==r)return e[0]},removeHook:function(o,r,t,n){var e;null!=gform.hooks[o][r]&&(e=(e=gform.hooks[o][r]).filter(function(o,r,e){return!!(null!=n&&n!=o.tag||null!=t&&t!=o.priority)}),gform.hooks[o][r]=e)}});\n<\/script>\n\n                <div class='gf_browser_gecko gform_wrapper gravity-theme gform-theme--no-framework lawyer-form_wrapper gplaceholder_wrapper form-with-labels-no-asterisks_wrapper has-new-validation-error-styling_wrapper' data-form-theme='gravity-theme' data-form-index='0' id='gform_wrapper_2453' style='display:none'><div id='gf_2453' class='gform_anchor' tabindex='-1'><\/div><form method='post' enctype='multipart\/form-data' target='gform_ajax_frame_2453' id='gform_2453' class='lawyer-form gplaceholder form-with-labels-no-asterisks has-new-validation-error-styling' action='\/api\/wp\/v2\/posts\/178800#gf_2453' data-formid='2453' novalidate>\n                        <div class='gform-body gform_body'><div id='gform_fields_2453' class='gform_fields top_label form_sublabel_below description_below validation_below'><div id=\"field_2453_1000\" class=\"gfield gfield--type-honeypot gform_validation_container field_sublabel_below gfield--has-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_1000'>Name<\/label><div class='ginput_container'><input name='input_1000' id='input_2453_1000' type='text' value='' autocomplete='new-password'\/><\/div><div class='gfield_description' id='gfield_description_2453_1000'>This field is for validation purposes and should be left unchanged.<\/div><\/div><div id=\"field_2453_1\" class=\"gfield gfield--type-text gfield--input-type-text gf_left_half gfield--width-half gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_1'>First Name<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_text\">(Required)<\/span><\/span><\/label><div class='ginput_container ginput_container_text'><input name='input_1' id='input_2453_1' type='text' value='' class='medium'     aria-required=\"true\" aria-invalid=\"false\"   \/><\/div><\/div><div id=\"field_2453_12\" class=\"gfield gfield--type-text gfield--input-type-text gf_right_half gfield--width-half gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_12'>Last Name<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_text\">(Required)<\/span><\/span><\/label><div class='ginput_container ginput_container_text'><input name='input_12' id='input_2453_12' type='text' value='' class='medium'     aria-required=\"true\" aria-invalid=\"false\"   \/><\/div><\/div><div id=\"field_2453_2\" class=\"gfield gfield--type-email gfield--input-type-email gf_left_half gfield--width-half gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_2'>Email Address<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_text\">(Required)<\/span><\/span><\/label><div class='ginput_container ginput_container_email'>\n                            <input name='input_2' id='input_2453_2' type='email' value='' class='medium'    aria-required=\"true\" aria-invalid=\"false\"  \/>\n                        <\/div><\/div><div id=\"field_2453_3\" class=\"gfield gfield--type-phone gfield--input-type-phone gf_right_half gfield--width-half gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_3'>Phone<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_text\">(Required)<\/span><\/span><\/label><div class='ginput_container ginput_container_phone'><input name='input_3' id='input_2453_3' type='tel' value='' class='medium'   aria-required=\"true\" aria-invalid=\"false\"   \/><\/div><\/div><div id=\"field_2453_14\" class=\"gfield gfield--type-select gfield--input-type-select gfield--width-full custom-select gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_14'>Number of Employees in Your Business<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_text\">(Required)<\/span><\/span><\/label><div class='ginput_container ginput_container_select'><select name='input_14' id='input_2453_14' class='large gfield_select'    aria-required=\"true\" aria-invalid=\"false\" ><option value='' selected='selected'>Select ...<\/option><option value='0' >0<\/option><option value='1' >1-5<\/option><option value='6' >6-20<\/option><option value='21' >21-50<\/option><option value='51' >51-250<\/option><option value='250' >250+<\/option><\/select><\/div><\/div><div id=\"field_2453_4\" class=\"gfield gfield--type-textarea gfield--input-type-textarea gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_4'>Tell us about your enquiry<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_text\">(Required)<\/span><\/span><\/label><div class='ginput_container ginput_container_textarea'><textarea name='input_4' id='input_2453_4' class='textarea medium'     aria-required=\"true\" aria-invalid=\"false\"   rows='10' cols='50'><\/textarea><\/div><\/div><div id=\"field_2453_5\" class=\"gfield gfield--type-html gfield--input-type-html gfield_html gfield_html_formatted gfield_no_follows_desc field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  >By submitting this form, you agree to receive emails from LegalVision and can unsubscribe at any time. View our <a href=\"https:\/\/legalvision.co.uk\/privacy-notice\/\" target=\"_blank\">Privacy Policy<\/a>. <\/div><div id=\"field_2453_8\" class=\"gfield gfield--type-hidden gfield--input-type-hidden gform_hidden field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><div class='ginput_container ginput_container_text'><input name='input_8' id='input_2453_8' type='hidden' class='gform_hidden'  aria-invalid=\"false\" value='http:\/\/legalvision.co.uk\/api\/wp\/v2\/posts\/178800' \/><\/div><\/div><div id=\"field_2453_13\" class=\"gfield gfield--type-hidden gfield--input-type-hidden gform_hidden field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><div class='ginput_container ginput_container_text'><input name='input_13' id='input_2453_13' type='hidden' class='gform_hidden'  aria-invalid=\"false\" value='generic_form' \/><\/div><\/div><fieldset id=\"field_2453_999\" class=\"gfield gfield--type-checkbox gfield--type-choice gfield__uk-marketo-opt-in field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><legend class='gfield_label gform-field-label screen-reader-text' ><\/legend><div class='ginput_container ginput_container_checkbox'><div class='gfield_checkbox ' id='input_2453_999'><div class='gchoice gchoice_2453_999_1'>\n\t\t\t\t\t\t\t\t<input class='gfield-choice-input' name='input_999.1' type='checkbox'  value='1'  id='choice_2453_999_1'   \/>\n\t\t\t\t\t\t\t\t<label for='choice_2453_999_1' id='label_2453_999_1' class='gform-field-label gform-field-label--type-inline'>By submitting this form, you agree to receive content and event invitations from us to help you grow your business. If you do not want to receive such messages, tick here.<\/label>\n\t\t\t\t\t\t\t<\/div><\/div><\/div><\/fieldset><\/div><\/div>\n        <div class='gform-footer gform_footer top_label'> <button type=\"submit\" id=\"gform_submit_button_2453\" class=\"gform_button button\" onclick=\"gform.submission.handleButtonClick(this);\" data-submission-type=\"submit\"><span class=\"gform_submit_button__text\">Submit Now<\/span><\/button> <input type='hidden' name='gform_ajax' value='form_id=2453&amp;title=&amp;description=&amp;tabindex=0&amp;theme=gravity-theme&amp;hash=ec2463697d0d9cef7b71236ae60964c7' \/>\n            <input type='hidden' class='gform_hidden' name='gform_submission_method' data-js='gform_submission_method_2453' value='iframe' \/>\n            <input type='hidden' class='gform_hidden' name='gform_theme' data-js='gform_theme_2453' id='gform_theme_2453' value='gravity-theme' \/>\n            <input type='hidden' class='gform_hidden' name='gform_style_settings' data-js='gform_style_settings_2453' id='gform_style_settings_2453' value='' \/>\n            <input type='hidden' class='gform_hidden' name='is_submit_2453' value='1' \/>\n            <input type='hidden' class='gform_hidden' name='gform_submit' value='2453' \/>\n            \n            <input type='hidden' class='gform_hidden' name='gform_currency' data-currency='GBP' value='Uj3Pibg3tks\/13ivDpviKk7lcJYsx\/iCq3uA\/7t6tus\/PcXAcrHoCeoQ9BpJbfD85k0xfKq7GL1MhkFZYkMsGtL9EAJ8Tyk\/CnrHRiW7Sdtb\/0w=' \/>\n            <input type='hidden' class='gform_hidden' name='gform_unique_id' value='' \/>\n            <input type='hidden' class='gform_hidden' name='state_2453' value='WyJ7XCIxNFwiOltcIjIyODY0N2ViMWU3NTcxZjA4YTY4NGJmMDcwMTk3Y2I0XCIsXCJiMzk3YmQ1MDBmMmFjNjk1ODE4MzdmNTBhYTA2MzQ0OFwiLFwiNGYyNGZkZGEwMzlkNDUxMWFhZGE1NGYwZmQwZmNiZTdcIixcIjUyMmJkMDE2M2I2ZmEwOTI3NDZhZjU5YTg0ZmM1NDk5XCIsXCIzODRlNjk1YjQxMTAzMWFiYmQ2ODEyMGYyZWFhMDYyNlwiLFwiYjkzNDcwNTE2MjkxOGRjZWViMjQzNzRjNmE0NGVmNTlcIixcIjQxMTliODZhMzVjYzJiMWViNDZiMmQ4NjRlNGUzZmNjXCJdfSIsIjQ3MjNiMzA2ZDIyZGVkODA2N2YyMjYyOThkYzI1ODVmIl0=' \/>\n            <input type='hidden' autocomplete='off' class='gform_hidden' name='gform_target_page_number_2453' id='gform_target_page_number_2453' value='0' \/>\n            <input type='hidden' autocomplete='off' class='gform_hidden' name='gform_source_page_number_2453' id='gform_source_page_number_2453' value='1' \/>\n            <input type='hidden' name='gform_field_values' value='' \/>\n            \n        <\/div>\n                        <\/form>\n                        <\/div>\n\t\t                <iframe style='display:none;width:0px;height:0px;' src='about:blank' name='gform_ajax_frame_2453' id='gform_ajax_frame_2453' title='This iframe contains the logic required to handle Ajax powered Gravity Forms.'><\/iframe>\n\t\t                <script>\ngform.initializeOnLoaded( function() {gformInitSpinner( 2453, 'https:\/\/legalvision.co.uk\/wp-content\/themes\/legalv-v6\/img\/spinner.svg', true );jQuery('#gform_ajax_frame_2453').on('load',function(){var contents = jQuery(this).contents().find('*').html();var is_postback = contents.indexOf('GF_AJAX_POSTBACK') >= 0;if(!is_postback){return;}var form_content = jQuery(this).contents().find('#gform_wrapper_2453');var is_confirmation = jQuery(this).contents().find('#gform_confirmation_wrapper_2453').length > 0;var is_redirect = contents.indexOf('gformRedirect(){') >= 0;var is_form = form_content.length > 0 && ! is_redirect && ! is_confirmation;var mt = parseInt(jQuery('html').css('margin-top'), 10) + parseInt(jQuery('body').css('margin-top'), 10) + 100;if(is_form){form_content.find('form').css('opacity', 0);jQuery('#gform_wrapper_2453').html(form_content.html());if(form_content.hasClass('gform_validation_error')){jQuery('#gform_wrapper_2453').addClass('gform_validation_error');} else {jQuery('#gform_wrapper_2453').removeClass('gform_validation_error');}setTimeout( function() { \/* delay the scroll by 50 milliseconds to fix a bug in chrome *\/ jQuery(document).scrollTop(jQuery('#gform_wrapper_2453').offset().top - mt); }, 50 );if(window['gformInitDatepicker']) {gformInitDatepicker();}if(window['gformInitPriceFields']) {gformInitPriceFields();}var current_page = jQuery('#gform_source_page_number_2453').val();gformInitSpinner( 2453, 'https:\/\/legalvision.co.uk\/wp-content\/themes\/legalv-v6\/img\/spinner.svg', true );jQuery(document).trigger('gform_page_loaded', [2453, current_page]);window['gf_submitting_2453'] = false;}else if(!is_redirect){var confirmation_content = jQuery(this).contents().find('.GF_AJAX_POSTBACK').html();if(!confirmation_content){confirmation_content = contents;}jQuery('#gform_wrapper_2453').replaceWith(confirmation_content);jQuery(document).scrollTop(jQuery('#gf_2453').offset().top - mt);jQuery(document).trigger('gform_confirmation_loaded', [2453]);window['gf_submitting_2453'] = false;wp.a11y.speak(jQuery('#gform_confirmation_message_2453').text());}else{jQuery('#gform_2453').append(contents);if(window['gformRedirect']) {gformRedirect();}}jQuery(document).trigger(\"gform_pre_post_render\", [{ formId: \"2453\", currentPage: \"current_page\", abort: function() { this.preventDefault(); } }]);        if (event && event.defaultPrevented) {                return;        }        const gformWrapperDiv = document.getElementById( \"gform_wrapper_2453\" );        if ( gformWrapperDiv ) {            const visibilitySpan = document.createElement( \"span\" );            visibilitySpan.id = \"gform_visibility_test_2453\";            gformWrapperDiv.insertAdjacentElement( \"afterend\", visibilitySpan );        }        const visibilityTestDiv = document.getElementById( \"gform_visibility_test_2453\" );        let postRenderFired = false;        function triggerPostRender() {            if ( postRenderFired ) {                return;            }            postRenderFired = true;            gform.core.triggerPostRenderEvents( 2453, current_page );            if ( visibilityTestDiv ) {                visibilityTestDiv.parentNode.removeChild( visibilityTestDiv );            }        }        function debounce( func, wait, immediate ) {            var timeout;            return function() {                var context = this, args = arguments;                var later = function() {                    timeout = null;                    if ( !immediate ) func.apply( context, args );                };                var callNow = immediate && !timeout;                clearTimeout( timeout );                timeout = setTimeout( later, wait );                if ( callNow ) func.apply( context, args );            };        }        const debouncedTriggerPostRender = debounce( function() {            triggerPostRender();        }, 200 );        if ( visibilityTestDiv && visibilityTestDiv.offsetParent === null ) {            const observer = new MutationObserver( ( mutations ) => {                mutations.forEach( ( mutation ) => {                    if ( mutation.type === 'attributes' && visibilityTestDiv.offsetParent !== null ) {                        debouncedTriggerPostRender();                        observer.disconnect();                    }                });            });            observer.observe( document.body, {                attributes: true,                childList: false,                subtree: true,                attributeFilter: [ 'style', 'class' ],            });        } else {            triggerPostRender();        }    } );} );\n<\/script>\n<\/div>\n<\/div>\n<div id=\"content-next\"><!-- scroll anchor --><\/div>\n<h2 class=\"wp-block-heading\">1. Only Disclose the Documents Requested<\/h2>\n\n\n\n<p>This is where the difference between targeted and non-targeted SARs comes into play. For example, if an individual has only requested a copy of their sickness absence records, you should provide this document. Avoid the quicker option of sending their entire HR records.<\/p>\n\n\n\n<div  class=\"box box--icon box--info\">\n    <p>If your company is in doubt about which documents the individual is interested in, you should write to them and ask them to describe the records sought and the purpose behind the request. This can simplify matters considerably. For example, if an employee tells you they want documentation to help a pension appeal, you would know that payslips and pension emails are relevant personal data. However, disciplinary records are not.<\/p>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">2. Redact Confidential or Irrelevant Information<\/h2>\n\n\n\n<p>Step one aims to collate all relevant documents. The subsequent step involves a review of those documents and redacting any confidential or irrelevant information.<\/p>\n\n\n\n<p>Redaction is a method of covering up specific bits of information within documents, so the recipient cannot view them. The traditional way on printed copies was to strike parts of the text with a thick black marker. Nowadays, there are digital methods of striking out information, so recipients cannot view it. Furthermore, it can guard against someone simply trying to copy and paste it into another document to read it.<\/p>\n\n\n\n<p>It is essential to avoid misuse of redaction. Your business should refrain from using this method to cover up the information it does not want to disclose. Instead, use it to protect personal data relating to others.&nbsp;<\/p>\n\n\n\n<p>So, for example, if an email mentions the pension-related earnings of three different staff members, you would redact the parts of that email relating to the other two individuals. This is because disclosing that information to the <a href=\"https:\/\/legalvision.co.uk\/data-privacy-it\/safely-handle-sar\/\">SAR<\/a> author would breach the privacy of those other staff members.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">3. Avoid Disclosure of \u2018Closed\u2019 Documents<\/h2>\n\n\n\n<p>The first follow-up question here is obvious: what is a \u2018closed\u2019 document? The simple answer is that there are two main types of closed documents:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>any document recording legal advice between your company and its legal advisors (which is covered by \u2018legal advice privilege\u2019); and<\/li>\n\n\n\n<li>any correspondence marked \u2018without prejudice\u2019 and sent between your company and the relevant individual to negotiate a confidential deal.<\/li>\n<\/ul>\n\n\n\n<p>Legal advice privilege only applies to genuine legal advice between a company and a lawyer, so any emails between you and an HR manager are not covered. For this reason, many business owners disclose sensitive matters by phone or in a meeting room rather than by email (to avoid sensitive topics falling within a <a href=\"https:\/\/legalvision.co.uk\/data-privacy-it\/benefits-lawyer-handling-sar\/\">SAR<\/a>).<\/p>\n\n\n\n<p>Without prejudice correspondence covers materials that aim to explore a potential deal. Your business cannot simply mark documents \u2018without prejudice\u2019 and expect them to remain confidential. Rather, those documents must also evidence at least one party aiming to progress negotiations. If so, these documents can be protected from disclosure even if the parties fail to achieve a deal.<\/p>\n\n\n\n<div  class=\"box box--icon box--info\">\n    <p dir=\"auto\"><strong>Key Statistics<\/strong><\/p>\n<ol dir=\"auto\">\n<li><strong>60%:<\/strong> 60% of organisations reported an increase in DSAR volume, intensifying demands on document review, redaction and exemption handling.<\/li>\n<li><strong>Two thirds:<\/strong> Two thirds of data protection authorities rated right of access compliance as average to high, highlighting persistent document disclosure challenges.<\/li>\n<li><strong>15,300:<\/strong> The ICO received over 15,300 complaints about DSAR handling in 2023, raising scrutiny on what documents businesses must disclose.<\/li>\n<\/ol>\n<p dir=\"auto\"><strong>Sources<\/strong><\/p>\n<ol dir=\"auto\">\n<li>EY Law \u2013 Data subject access requests (DSARs): 2023 EY Law survey (April 2023)<\/li>\n<li>European Data Protection Board (EDPB) \u2013 Coordinated Enforcement Framework (CEF) 2024 report on right of access (January 2025)<\/li>\n<li>ICO (UK Regulator) \u2013 What exemptions are relevant for SARs? (updated December 2025)<\/li>\n<\/ol>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Key Takeaways<\/h2>\n\n\n\n<p>Dealing with SARs will always take time and effort. Unfortunately, this is unavoidable given the need to search, compile and deliver documents to the SAR author. However, another potential stress is failing to deal with the SAR correctly and risking a fine from the ICO. The good news is that the above steps can help your organisation handle SARs efficiently and in line with GDPR principles.<\/p>\n\n\n\n<p>If you need help complying with SARs, LegalVision provides ongoing legal support for businesses through our fixed-fee legal membership. Our experienced <strong><a href=\"https:\/\/legalvision.co.uk\/it-lawyers-lp\/\">data, privacy and IT lawyers<\/a><\/strong> help businesses manage contracts, employment law, disputes, intellectual property, and more, with unlimited access to specialist lawyers for a fixed monthly fee. To learn more about LegalVision\u2019s legal membership, call <a href=\"tel:+448081968584\" class=\"AVANSERnumber dynamic-number\">0808 196 8584<\/a> or <a href=\"https:\/\/legalvision.co.uk\/membership\/\" target=\"_blank\" rel=\"noreferrer noopener\">visit our membership page<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions<\/h2>\n\n\n\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-1669642685260\"><h3 class=\"schema-faq-question\">Does the ICO regularly deliver high fines to companies for SAR breaches?<\/h3> <p class=\"schema-faq-answer\">No, financial penalties in the millions are unusual.\u00a0 However, the ICO is not averse to handing out fines in the thousands or tens of thousands of pounds for GDPR breaches, so your business should handle SARs safely.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1669642697717\"><h3 class=\"schema-faq-question\">Can my business refuse to carry out a SAR if it believes the individual is considering an Employment Tribunal claim?<\/h3> <p class=\"schema-faq-answer\">No, the reason for the SAR is mostly irrelevant in the ICO\u2019s eyes. If a disgruntled employee lodges a genuine SAR, any failure to process it in the same way as for any other person will likely be viewed as unfair by the ICO or any Employment Tribunal.\u00a0<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1777006032363\"><h3 class=\"schema-faq-question\">What is the difference between a targeted and a general SAR?<\/h3> <p class=\"schema-faq-answer\">A targeted SAR requests specific pieces of information, such as emails between an individual and a particular manager within a set timeframe. A general SAR requests all personal data held about an individual. The same rules apply to both, though you will typically disclose fewer documents in response to a targeted SAR.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1777006041371\"><h3 class=\"schema-faq-question\">What documents can my business withhold when responding to a SAR?<\/h3> <p class=\"schema-faq-answer\">You can withhold documents covered by legal advice privilege, such as genuine legal advice between your company and its lawyers, and correspondence marked &#8216;without prejudice&#8217; that evidences active negotiations. You should also redact personal data relating to third parties to protect their privacy.<\/p> <\/div> <\/div>\n","protected":false},"excerpt":{"rendered":"<p>A Subject Access Request (SAR) gives individuals the legal right to obtain a copy of their personal data held by an organisation. Under the UK GDPR, businesses must handle these requests carefully or risk significant fines from the Information Commissioner&#8217;s Office (ICO). Many organisations find SARs administratively burdensome and the rules surrounding them complex. This<a href=\"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/\">Continue reading <span class=\"sr-only\">&#8220;What Documents Should My Business in the UK Disclose Following a Subject Access Request?&#8221;<\/span><\/a><\/p>\n","protected":false},"author":13461,"featured_media":3216,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"173443,1836,177098,175390,3620,177424","_relevanssi_noindex_reason":"","editor_notices":[],"footnotes":""},"categories":[27],"tags":[20,21,365,642],"class_list":["post-178800","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-privacy-it","tag-small-business","tag-medium-business","tag-gdpr","tag-gdpr-complicance"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Documents to Disclose in a SAR | LegalVision UK<\/title>\n<meta name=\"description\" content=\"This article will explore the documents your business should disclose if you receive a Subject Access Request (SAR).\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Documents to Disclose in a SAR | LegalVision UK\" \/>\n<meta property=\"og:description\" content=\"This article will explore the documents your business should disclose if you receive a Subject Access Request (SAR).\" \/>\n<meta property=\"og:url\" content=\"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/\" \/>\n<meta property=\"og:site_name\" content=\"LegalVision UK\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/LegalVision\" \/>\n<meta property=\"article:published_time\" content=\"2022-11-28T13:41:59+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-24T04:49:06+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24122105\/business-image-0522157.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"897\" \/>\n\t<meta property=\"og:image:height\" content=\"599\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Kieran Ram\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@LegalVision_law\" \/>\n<meta name=\"twitter:site\" content=\"@LegalVision_law\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kieran Ram\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/\"},\"author\":{\"name\":\"Kieran Ram\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/#\\\/schema\\\/person\\\/5a59ade89273f68f939c7cb8cc66e6f1\"},\"headline\":\"What Documents Should My Business in the UK Disclose Following a Subject Access Request?\",\"datePublished\":\"2022-11-28T13:41:59+00:00\",\"dateModified\":\"2026-04-24T04:49:06+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/\"},\"wordCount\":1130,\"image\":{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/img.legalvision.com.au\\\/wp-content\\\/uploads\\\/sites\\\/4\\\/2022\\\/05\\\/24122105\\\/business-image-0522157.jpg\",\"keywords\":[\"small business\",\"medium business\",\"gdpr\",\"gdpr complicance\"],\"articleSection\":[\"Data, Privacy and IT Articles\"],\"inLanguage\":\"en-GB\"},{\"@type\":[\"WebPage\",\"FAQPage\"],\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/\",\"url\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/\",\"name\":\"Documents to Disclose in a SAR | LegalVision UK\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/img.legalvision.com.au\\\/wp-content\\\/uploads\\\/sites\\\/4\\\/2022\\\/05\\\/24122105\\\/business-image-0522157.jpg\",\"datePublished\":\"2022-11-28T13:41:59+00:00\",\"dateModified\":\"2026-04-24T04:49:06+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/#\\\/schema\\\/person\\\/5a59ade89273f68f939c7cb8cc66e6f1\"},\"description\":\"This article will explore the documents your business should disclose if you receive a Subject Access Request (SAR).\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/#breadcrumb\"},\"mainEntity\":[{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/#faq-question-1669642685260\"},{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/#faq-question-1669642697717\"},{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/#faq-question-1777006032363\"},{\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/#faq-question-1777006041371\"}],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/#primaryimage\",\"url\":\"https:\\\/\\\/img.legalvision.com.au\\\/wp-content\\\/uploads\\\/sites\\\/4\\\/2022\\\/05\\\/24122105\\\/business-image-0522157.jpg\",\"contentUrl\":\"https:\\\/\\\/img.legalvision.com.au\\\/wp-content\\\/uploads\\\/sites\\\/4\\\/2022\\\/05\\\/24122105\\\/business-image-0522157.jpg\",\"width\":897,\"height\":599,\"caption\":\"Common Legal Disputes for Non-Profits | LegalVision UK\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/legalvision.co.uk\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data, Privacy and IT Articles\",\"item\":\"https:\\\/\\\/legalvision.co.uk\\\/category\\\/data-privacy-it\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"What Documents Should My Business in the UK Disclose Following a Subject Access Request?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/#website\",\"url\":\"https:\\\/\\\/legalvision.co.uk\\\/\",\"name\":\"LegalVision UK\",\"description\":\"LegalVision is a commercial law firm in the UK with a commitment to innovation\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/legalvision.co.uk\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/#\\\/schema\\\/person\\\/5a59ade89273f68f939c7cb8cc66e6f1\",\"name\":\"Kieran Ram\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/wp-content\\\/uploads\\\/sites\\\/4\\\/2024\\\/04\\\/Kieran-2349-scaled-e1714435159620-96x96.jpg\",\"url\":\"https:\\\/\\\/legalvision.co.uk\\\/wp-content\\\/uploads\\\/sites\\\/4\\\/2024\\\/04\\\/Kieran-2349-scaled-e1714435159620-96x96.jpg\",\"contentUrl\":\"https:\\\/\\\/legalvision.co.uk\\\/wp-content\\\/uploads\\\/sites\\\/4\\\/2024\\\/04\\\/Kieran-2349-scaled-e1714435159620-96x96.jpg\",\"caption\":\"Kieran Ram\"},\"description\":\"Kieran is a Trainee Solicitor in LegalVision\u2019s Corporate and Commercial team. He has completed a Law Degree, the Legal Practice Course and a Masters in Sports Law, specialising in Football Law.\",\"url\":\"https:\\\/\\\/legalvision.co.uk\\\/author\\\/kieranram\\\/\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/#faq-question-1669642685260\",\"name\":\"Does the ICO regularly deliver high fines to companies for SAR breaches?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No, financial penalties in the millions are unusual.\u00a0 However, the ICO is not averse to handing out fines in the thousands or tens of thousands of pounds for GDPR breaches, so your business should handle SARs safely.\",\"inLanguage\":\"en-GB\"},\"inLanguage\":\"en-GB\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/#faq-question-1669642697717\",\"name\":\"Can my business refuse to carry out a SAR if it believes the individual is considering an Employment Tribunal claim?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No, the reason for the SAR is mostly irrelevant in the ICO\u2019s eyes. If a disgruntled employee lodges a genuine SAR, any failure to process it in the same way as for any other person will likely be viewed as unfair by the ICO or any Employment Tribunal.\u00a0\",\"inLanguage\":\"en-GB\"},\"inLanguage\":\"en-GB\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/#faq-question-1777006032363\",\"name\":\"What is the difference between a targeted and a general SAR?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"A targeted SAR requests specific pieces of information, such as emails between an individual and a particular manager within a set timeframe. A general SAR requests all personal data held about an individual. The same rules apply to both, though you will typically disclose fewer documents in response to a targeted SAR.\",\"inLanguage\":\"en-GB\"},\"inLanguage\":\"en-GB\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/legalvision.co.uk\\\/data-privacy-it\\\/documents-sar\\\/#faq-question-1777006041371\",\"name\":\"What documents can my business withhold when responding to a SAR?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"You can withhold documents covered by legal advice privilege, such as genuine legal advice between your company and its lawyers, and correspondence marked 'without prejudice' that evidences active negotiations. You should also redact personal data relating to third parties to protect their privacy.\",\"inLanguage\":\"en-GB\"},\"inLanguage\":\"en-GB\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Documents to Disclose in a SAR | LegalVision UK","description":"This article will explore the documents your business should disclose if you receive a Subject Access Request (SAR).","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/","og_locale":"en_GB","og_type":"article","og_title":"Documents to Disclose in a SAR | LegalVision UK","og_description":"This article will explore the documents your business should disclose if you receive a Subject Access Request (SAR).","og_url":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/","og_site_name":"LegalVision UK","article_publisher":"https:\/\/www.facebook.com\/LegalVision","article_published_time":"2022-11-28T13:41:59+00:00","article_modified_time":"2026-04-24T04:49:06+00:00","og_image":[{"width":897,"height":599,"url":"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24122105\/business-image-0522157.jpg","type":"image\/jpeg"}],"author":"Kieran Ram","twitter_card":"summary_large_image","twitter_creator":"@LegalVision_law","twitter_site":"@LegalVision_law","twitter_misc":{"Written by":"Kieran Ram","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/#article","isPartOf":{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/"},"author":{"name":"Kieran Ram","@id":"https:\/\/legalvision.co.uk\/#\/schema\/person\/5a59ade89273f68f939c7cb8cc66e6f1"},"headline":"What Documents Should My Business in the UK Disclose Following a Subject Access Request?","datePublished":"2022-11-28T13:41:59+00:00","dateModified":"2026-04-24T04:49:06+00:00","mainEntityOfPage":{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/"},"wordCount":1130,"image":{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/#primaryimage"},"thumbnailUrl":"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24122105\/business-image-0522157.jpg","keywords":["small business","medium business","gdpr","gdpr complicance"],"articleSection":["Data, Privacy and IT Articles"],"inLanguage":"en-GB"},{"@type":["WebPage","FAQPage"],"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/","url":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/","name":"Documents to Disclose in a SAR | LegalVision UK","isPartOf":{"@id":"https:\/\/legalvision.co.uk\/#website"},"primaryImageOfPage":{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/#primaryimage"},"image":{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/#primaryimage"},"thumbnailUrl":"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24122105\/business-image-0522157.jpg","datePublished":"2022-11-28T13:41:59+00:00","dateModified":"2026-04-24T04:49:06+00:00","author":{"@id":"https:\/\/legalvision.co.uk\/#\/schema\/person\/5a59ade89273f68f939c7cb8cc66e6f1"},"description":"This article will explore the documents your business should disclose if you receive a Subject Access Request (SAR).","breadcrumb":{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/#breadcrumb"},"mainEntity":[{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/#faq-question-1669642685260"},{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/#faq-question-1669642697717"},{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/#faq-question-1777006032363"},{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/#faq-question-1777006041371"}],"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/#primaryimage","url":"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24122105\/business-image-0522157.jpg","contentUrl":"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24122105\/business-image-0522157.jpg","width":897,"height":599,"caption":"Common Legal Disputes for Non-Profits | LegalVision UK"},{"@type":"BreadcrumbList","@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/legalvision.co.uk\/"},{"@type":"ListItem","position":2,"name":"Data, Privacy and IT Articles","item":"https:\/\/legalvision.co.uk\/category\/data-privacy-it\/"},{"@type":"ListItem","position":3,"name":"What Documents Should My Business in the UK Disclose Following a Subject Access Request?"}]},{"@type":"WebSite","@id":"https:\/\/legalvision.co.uk\/#website","url":"https:\/\/legalvision.co.uk\/","name":"LegalVision UK","description":"LegalVision is a commercial law firm in the UK with a commitment to innovation","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/legalvision.co.uk\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/legalvision.co.uk\/#\/schema\/person\/5a59ade89273f68f939c7cb8cc66e6f1","name":"Kieran Ram","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/legalvision.co.uk\/wp-content\/uploads\/sites\/4\/2024\/04\/Kieran-2349-scaled-e1714435159620-96x96.jpg","url":"https:\/\/legalvision.co.uk\/wp-content\/uploads\/sites\/4\/2024\/04\/Kieran-2349-scaled-e1714435159620-96x96.jpg","contentUrl":"https:\/\/legalvision.co.uk\/wp-content\/uploads\/sites\/4\/2024\/04\/Kieran-2349-scaled-e1714435159620-96x96.jpg","caption":"Kieran Ram"},"description":"Kieran is a Trainee Solicitor in LegalVision\u2019s Corporate and Commercial team. He has completed a Law Degree, the Legal Practice Course and a Masters in Sports Law, specialising in Football Law.","url":"https:\/\/legalvision.co.uk\/author\/kieranram\/"},{"@type":"Question","@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/#faq-question-1669642685260","name":"Does the ICO regularly deliver high fines to companies for SAR breaches?","acceptedAnswer":{"@type":"Answer","text":"No, financial penalties in the millions are unusual.\u00a0 However, the ICO is not averse to handing out fines in the thousands or tens of thousands of pounds for GDPR breaches, so your business should handle SARs safely.","inLanguage":"en-GB"},"inLanguage":"en-GB"},{"@type":"Question","@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/#faq-question-1669642697717","name":"Can my business refuse to carry out a SAR if it believes the individual is considering an Employment Tribunal claim?","acceptedAnswer":{"@type":"Answer","text":"No, the reason for the SAR is mostly irrelevant in the ICO\u2019s eyes. If a disgruntled employee lodges a genuine SAR, any failure to process it in the same way as for any other person will likely be viewed as unfair by the ICO or any Employment Tribunal.\u00a0","inLanguage":"en-GB"},"inLanguage":"en-GB"},{"@type":"Question","@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/#faq-question-1777006032363","name":"What is the difference between a targeted and a general SAR?","acceptedAnswer":{"@type":"Answer","text":"A targeted SAR requests specific pieces of information, such as emails between an individual and a particular manager within a set timeframe. A general SAR requests all personal data held about an individual. The same rules apply to both, though you will typically disclose fewer documents in response to a targeted SAR.","inLanguage":"en-GB"},"inLanguage":"en-GB"},{"@type":"Question","@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/documents-sar\/#faq-question-1777006041371","name":"What documents can my business withhold when responding to a SAR?","acceptedAnswer":{"@type":"Answer","text":"You can withhold documents covered by legal advice privilege, such as genuine legal advice between your company and its lawyers, and correspondence marked 'without prejudice' that evidences active negotiations. You should also redact personal data relating to third parties to protect their privacy.","inLanguage":"en-GB"},"inLanguage":"en-GB"}]}},"_links":{"self":[{"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/posts\/178800","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/users\/13461"}],"replies":[{"embeddable":true,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/comments?post=178800"}],"version-history":[{"count":6,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/posts\/178800\/revisions"}],"predecessor-version":[{"id":197234,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/posts\/178800\/revisions\/197234"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/media\/3216"}],"wp:attachment":[{"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/media?parent=178800"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/categories?post=178800"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/tags?post=178800"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}