When someone asks what personal data you hold, says it is wrong, or asks you to delete it, log the request, identify the law and deadline that apply, verify identity proportionately, and assess each requested right separately. Under UK GDPR guidance from the Information Commissioner’s Office (ICO), a request can be verbal or written and does not need to use legal terminology. The UK and California examples below are not universal rules: confirm the applicable jurisdiction, exemptions, and deadline calculations with your privacy lead or local counsel.
Start by recognising and logging the request
Do not wait for a person to submit a form, use a particular mailbox, or write “subject access request.” The ICO says a person need not use that phrase or cite Article 15 to make an access request. A request to correct or erase data likewise need not cite the relevant article under ICO guidance.
At intake, record when and where the request arrived, what the person appears to want, the account or relationship involved, and who owns the next action. If one message asks for access, correction, and deletion, log all three rights separately so one is not lost inside a general support ticket. Route it promptly to the team responsible for privacy requests.
Identify the applicable law and response clock
Before promising a response date, determine which law applies to your organisation, the person, the processing, and the request. The figures below are examples for UK GDPR and California CCPA requests, not interchangeable deadlines. Do not combine one jurisdiction’s start-date rules or extension conditions with another’s.
#1 Best Overall
| Issue | UK GDPR example (ICO guidance) | California CCPA example (CPPA materials) |
|---|---|---|
| Rights covered by these sources | Access, rectification, and erasure | Know/access, correction, and deletion |
| Ordinary response period | Generally within one month | Within 45 calendar days for covered requests |
| Possible extension | Up to two further months for a qualifying complex request or multiple requests; give notice and reasons within the initial month | Up to one additional 45-day period when necessary; give notice and an explanation |
| Receipt confirmation | The cited ICO guidance does not establish a separate California-style confirmation deadline | Confirm receipt of covered know, correct, and delete requests within 10 business days |
| Separate deletion mechanism | Apply UK rules and exemptions to the particular organisation and request | DROP is a separate data-broker mechanism. California data brokers must access it at least every 45 days starting August 1, 2026, subject to the statute and exceptions. |
The ICO’s access guidance was updated December 8, 2025; its brief subject-access guide reflects the UK Data (Use and Access) Act 2025 and was updated July 16, 2026. The California CPPA FAQ was accessed October 5, 2026, and the CCPA text referenced there is effective January 1, 2026. Because these rules and dates can change, check the current regulator guidance before calculating a live deadline.
Verify identity and authority only as far as needed
First consider whether the person is already identifiable through a trusted account or an ongoing relationship. If there is genuine doubt, ask only for information reasonably necessary to verify identity. If someone is acting for another person, check their authority where needed before disclosing data or acting on the request.
Rank #2
The ICO advises organisations to be reasonable and proportionate: formal identity documents should be requested only when necessary. Do not make a full identity document a routine prerequisite when identity is already clear. Verification itself creates personal information, so keep any material collected secure and use it for the relevant check in line with applicable law.
Clarify scope without letting the request disappear
If a request is unusually broad or unclear, ask a focused question that helps identify the information the person means. Explain why the clarification is needed and keep a record of the contact. Do not assume that asking a question automatically pauses all work: the ICO notes that it may often be possible to provide some information while clarification is pending. Whether, and how, clarification affects a deadline depends on the governing law and circumstances.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallRank #3
Handle an access request as a search and disclosure decision
Access is about providing a copy of the person’s personal data together with required supplementary information; it is not simply a copy of one account screen or a dump of every record in the organisation. Make a reasonable and proportionate search of systems and records likely to contain the requested information, including relevant communications and repositories. A proportionate search is not a reason to skip likely locations.
For a UK GDPR access response, the ICO identifies supplementary information that can include the purposes of processing, categories of personal data, recipients, retention information, the source when data was not collected from the person, and relevant automated-decision information. Review records for other people’s information and applicable legal restrictions or exemptions before disclosure. Then deliver the response clearly, accessibly, and securely, and record the searches and disclosure decision.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Assess correction against accuracy and purpose
Pin down which information the person says is inaccurate or incomplete, and why it matters for the purpose for which it is processed. Consider evidence they provide and the reasonable steps already taken to assure accuracy. Where appropriate, correct inaccurate data or complete incomplete data. A correction request is not automatically a direction to replace a fact merely because the person disputes it; assess the information and context.
If you refuse all or part of the request, explain the reason and identify the applicable complaint or review route. Keep a record of the information considered, the decision, and any change made.
Free tools Windows power users keep installed
One-click scans. No signup required.
Assess erasure grounds, exceptions, and implementation
An erasure request does not mean data must always be deleted. Determine whether a recognised ground for erasure applies and whether an exception or continuing legal obligation allows or requires retention. The applicable grounds and exceptions depend on the law and facts; do not promise deletion before completing that assessment.
If erasure is granted, identify the relevant live systems and recipients or processors that need action. Distinguish operational deletion from limited backup or archival treatment and from retention required by law or another valid basis. Plan so that erased data does not simply reappear in normal use. If refusing all or part, tell the person what was decided, why, and what challenge rights apply.
Close the request with a clear outcome and audit trail
Send the outcome securely in plain language. State what you did, or why you refused action, and include any required complaint or regulator information. Keep a record of the dates, identity and authority checks, searches, any extension notice, decision, implementation evidence, and delivery. That record lets the organisation explain how it handled the request and whether its actions matched the decision.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




