Subject Access Request Support

IOLIS provides complete subject access request support, from a single piece of advice on how to handle a request through to search, retrieval, review, redaction, and the production of the final disclosure. We work with organisations that have no in-house capability at all, and with established teams that have simply been overwhelmed by the volume or the sensitivity of what has landed on them. Processing and redaction are carried out on our own platform, Redaktr, which means material does not have to be passed through a chain of unfamiliar third-party tools before it comes back to you.

What does subject access request support involve?

A subject access request under Article 15 of UK GDPR is deceptively simple as a matter of law and frequently difficult as a matter of practice. The right itself is broad, the time limits are short, and the exemptions that matter most sit not in the Regulation but in the schedules to the Data Protection Act 2018, where they have to be applied item by item rather than in a single sweep. Most of the difficulty an organisation encounters is not in deciding whether to respond, but in working out what is actually caught, where it lives, and what has to come out before anything is sent.

Our support spans the whole of that, and you can take any part of it in isolation:

  • Advice on the request itself – whether it is valid, what it properly covers, whether it can be clarified, what the response deadline actually is, and whether it can be extended
  • Search and retrieval advice – how to run a defensible search across the systems you already have, and how to record what you did
  • Processing of the retrieved material – de-duplication, threading, sifting out what is not personal data, and reducing an unmanageable export to a reviewable set
  • Review and application of exemptions – third party data, legal professional privilege, and the other schedule provisions that bear on the material in front of us
  • Redaction – applied properly, so that what is removed is genuinely removed rather than merely hidden behind a black box
  • Provision of the final output – a disclosure set you can send, with the covering material and the audit trail that sits behind it

Searching and retrieving the data

The search is where most subject access requests are quietly lost. A search that is too narrow produces a disclosure that will not survive a complaint; a search that is too broad produces an export nobody can review inside the time available, which amounts to the same failure by a slower route. Section 78 of the Data (Use and Access) Act 2025 has now put the point on a statutory footing, requiring only a reasonable and proportionate search – but proportionality has to be reasoned and recorded, not simply asserted after the fact.

We advise on running and documenting that search in the tools organisations most commonly hold:

  • Microsoft Purview – eDiscovery searches across Exchange, SharePoint, OneDrive and Teams, including how to scope custodians and locations sensibly and how to handle the export
  • Google Vault – matters and holds across Gmail, Drive and Chat, and the practical limits of what Vault will and will not reach
  • Mimecast – archive searching where mail has been journalled or where former employees’ correspondence is no longer live in the tenancy

This is deliberately framed as advice rather than access. In most engagements your own IT team runs the search, because they hold the credentials and the knowledge of your estate; our part is to specify what should be searched, on what terms, and to make sure the reasoning is written down while it is still fresh.

Processing, review and redaction on Redaktr

Once the material has been retrieved, it comes into Redaktr, our own disclosure and redaction platform. Everything from that point – de-duplication, review, the application of exemptions, redaction, and the production of the final set – happens in one place, which keeps the audit trail intact and avoids the familiar mess of spreadsheets, tracked changes, and email attachments circulating between people who are each holding a slightly different version of the truth.

Redaction is done at the level of the underlying document rather than as an overlay, which matters more than it sounds. A black rectangle drawn over text in a PDF viewer removes nothing at all, and material has been recovered from supposedly redacted disclosures often enough for the point to be well past arguing about.

The exemptions applied during review are the ones that do the real work in contested requests – third party data under paragraph 16 of Schedule 2 to the Data Protection Act 2018, legal professional privilege under paragraph 19, and, where the context calls for it, the provisions bearing on regulatory functions and the protection of the public. None of these is a blanket. Each has to be reasoned against the particular item, and the reasoning is what you will be asked for if the request is later escalated.

Who this is for

Three situations come up again and again.

Small organisations with no in-house function. A single request can absorb a disproportionate amount of a small team’s time, usually at the worst possible moment. Here we tend to do most of the work, and the engagement is scoped to the request in front of you rather than to a standing arrangement.

Established teams that have become overwhelmed. Larger organisations rarely lack the competence; they lack the hours. A request spanning several years and tens of thousands of items will swamp a team that is also expected to keep everything else running. We take the volume, and your team keeps the judgement calls that ought to stay in-house.

Contentious or complex requests. Requests arriving alongside an employment tribunal claim, a disciplinary process, or a safeguarding investigation are a different animal entirely. They are frequently made for tactical reasons, they are almost always facially valid, and the material caught by them is exactly the material an organisation would least like to hand over without thinking carefully first. That is not a reason to refuse – the grounds for refusal are much narrower than most people assume, and prejudice to an ongoing investigation is not among them – but it is a reason to have the analysis done properly, item by item, by someone who has done it before.

As much or as little as you need

There is no standing commitment and no minimum engagement. Some clients take a half hour of advice on a request they then handle perfectly well themselves. Others hand over an export of forty thousand items and take back a finished disclosure set. Most sit somewhere in between, and the shape of the work is agreed at the start, when we have seen what the request actually says and roughly what it is likely to catch.

Where a request has already gone wrong – a deadline missed, a disclosure sent that should not have been, or a complaint made under section 164A of the Data Protection Act 2018 – we can pick it up from there too. It is a less comfortable position to start from, but it is a common one, and it is recoverable more often than people fear.

Talk to us

If you have a request in front of you – or you can see one coming – we would be glad to look at it and tell you plainly what is involved. Find the best way to contact us here.

You may also find our guide on how to respond to a subject access request without over- or under-disclosing useful, and this service sits alongside our wider Data Protection support, including outsourced DPO cover and DPIAs.