Data Subject Access Request Form GDPR Template for England and Wales

Create a bespoke document in minutes,  or upload and review your own.

4.6 / 5
4.8 / 5

Let's create your Data Subject Access Request Form GDPR

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Get your first 2 documents free

Your data doesn't train Genie's AI

You keep IP ownership of your information

Key Requirements PROMPT example:

Data Subject Access Request Form GDPR

"I need a Data Subject Access Request Form GDPR for our healthcare company that operates across multiple hospitals in England, with specific sections for medical record requests and the ability for authorized family members to make requests on behalf of patients."

Document background
The Data Subject Access Request Form GDPR is a crucial tool for implementing data protection rights under UK law. Created in response to GDPR requirements and maintained under the UK GDPR and Data Protection Act 2018, this form enables individuals in England and Wales to exercise their fundamental right to access personal data. Organizations must respond to these requests within one month, making this standardized form essential for efficient processing and compliance with data protection obligations.
Suggested Sections

1. Personal Details: Section for collecting data subject's identification information including full name, contact details, and any reference numbers

2. Request Details: Section specifying the scope of the request, including specific information being requested and relevant time period

3. Identity Verification: Section outlining the requirements for proving the requestor's identity and what documents are acceptable

4. Declaration: Statement confirming the accuracy of information provided and understanding of the process

Optional Sections

1. Third Party Authorization: Section to be completed when the request is being made by someone other than the data subject

2. Specific Data Categories: Detailed checklist of specific types of personal data being requested to help narrow down the scope

3. Preferred Response Format: Section allowing the requestor to specify their preferred format for receiving the information

Suggested Schedules

1. Schedule 1 - Identity Verification Documents: List of acceptable identification documents and requirements for verification

2. Schedule 2 - Third Party Authorization Form: Template form for authorizing third-party representatives to make the request

3. Schedule 3 - Privacy Notice: Information about how the personal data provided in the DSAR form will be processed

Authors

Alex Denne

Head of Growth (Open Source Law) @ Genie AI | 3 x UCL-Certified in Contract Law & Drafting | 4+ Years Managing 1M+ Legal Documents | Serial Founder & Legal AI Author

Industries

UK GDPR: The United Kingdom General Data Protection Regulation - primary legislation governing data protection in the UK post-Brexit, particularly Article 15 (Right of access) and Article 12 (Transparent information and communication)

DPA 2018: Data Protection Act 2018 - the UK's implementation of data protection laws, particularly Section 45 regarding right of access by data subjects and Schedule 2 exemptions

ICO Guidance: Information Commissioner's Office regulatory guidance on handling Data Subject Access Requests, including practical implementation and best practices

EDPB Guidelines: European Data Protection Board guidelines - while not binding post-Brexit, these remain influential for UK data protection practices

Time Limits: Legal requirement to respond to DSARs within one month, with possible extension under specific circumstances

Identification Requirements: Legal obligation to verify the identity of the person making the DSAR to ensure data security and prevent unauthorized access

Fee Regulations: Rules regarding DSAR processing fees - generally free of charge, except for manifestly unfounded or excessive requests

Verification Methods: Legitimate means of verifying the identity of the data subject making the request

Response Format: Requirements for the format in which personal data should be provided to the data subject

DPA Exemptions: Exemptions under Schedule 2 of Data Protection Act 2018 where certain data may be withheld from DSAR responses

Plain Language Requirement: Legal obligation to provide information in clear and plain language, in a concise, transparent, intelligible and easily accessible form

Submission Methods: Acceptable methods for submitting DSARs, including verbal, written, electronic, and third-party requests

Teams

Employer, Employee, Start Date, Job Title, Department, Location, Probationary Period, Notice Period, Salary, Overtime, Vacation Pay, Statutory Holidays, Benefits, Bonus, Expenses, Working Hours, Rest Breaks,  Leaves of Absence, Confidentiality, Intellectual Property, Non-Solicitation, Non-Competition, Code of Conduct, Termination,  Severance Pay, Governing Law, Entire Agreemen

Find the exact document you need

Data Subject Rights Request Form

find out more

Data Subject Access Request Form GDPR

find out more

Data Protection Request Form

find out more

Subject Access Request Form

A standardized form under English and Welsh law enabling individuals to request access to their personal data held by organizations.

find out more

Dsar Form

A standardized form under English and Welsh law for individuals to request access to their personal data held by organizations, as per UK GDPR requirements.

find out more

Data Subject Access Request Form

A standardized form under English and Welsh law enabling individuals to request access to their personal data held by organizations.

find out more

Download our whitepaper on the future of AI in Legal

By providing your email address you are consenting to our Privacy Notice.
Thank you for downloading our whitepaper. This should arrive in your inbox shortly. In the meantime, why not jump straight to a section that interests you here: https://www.genieai.co/our-research
Oops! Something went wrong while submitting the form.

Genie’s Security Promise

Genie is the safest place to draft. Here’s how we prioritise your privacy and security.

Your documents are private:

We do not train on your data; Genie’s AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

Our bank-grade security infrastructure undergoes regular external audits

We are ISO27001 certified, so your data is secure

Organizational security

You retain IP ownership of your documents

You have full control over your data and who gets to see it

Innovation in privacy:

Genie partnered with the Computational Privacy Department at Imperial College London

Together, we ran a £1 million research project on privacy and anonymity in legal contracts

Want to know more?

Visit our Trust Centre for more details and real-time security updates.