Data Protection · 8 April 2026 · 6 min read
Handling Subject Access Requests Inside a Documentation File
A subject access request reaches into a documentation file from outside. Responding without breaching engagement confidentiality requires a defined procedure.

A subject access request under UK GDPR allows an individual to obtain a copy of their personal data held by a controller. When the request reaches a documentation file, the response procedure must reconcile transparency to the subject with confidentiality to the client.
The first step is identification of the requester. The procedure records the documents used to confirm identity, the date of verification, and the operator who performed it, so that the response is not sent to an impersonator or to a party without standing to receive the data.
Scope of the request is then defined. A broad request for all data is narrowed where lawful narrowing exists, and the narrowing is communicated to the requester with the basis stated. The dialogue is recorded so that the request and its scope are evidenced at every step.
Records inside the documentation file are searched against the defined scope. The search is reproducible: the search terms, the storage locations covered, and the categories of record examined are recorded so that the completeness of the search can be reviewed later.

Third-party personal data inside the records receives separate treatment. Where a record contains personal data of someone other than the requester, that data is redacted or withheld under the rules that protect third parties, and the redaction is logged with the reason given.
Confidential client information that is not personal data of the requester is also withheld. A trade secret, a counterparty's commercial terms, or a privileged communication is removed from the response under the basis recorded against the document at intake.
The response itself is delivered through a controlled channel with delivery confirmation retained. The cover note records what was provided, what was withheld, and the basis for any withholding, so that the requester can challenge the response against a documented record.
Our role is to act on the documented procedure. We do not negotiate subject access outcomes with regulators on the client's behalf, and we do not extend the response beyond the data the requester is entitled to receive under the law as it applies to the engagement.
More in Data Protection
- Lawful Bases for Processing Client Records in a Documentation Engagement
18 Jan 2026
- Retention, Erasure and the Limits of the Right to Be Forgotten
4 Mar 2026
- Cross-Border Transfer Mechanisms Inside an Engagement File
9 Jun 2026
- Subject Access Requests Inside an Active Documentation Engagement
22 May 2026
- Documentation Files That Touch Both Parent and Minor Records
9 Jul 2026
- Lawful Bases and Retention Periods Inside a Documentation Engagement
21 Oct 2026