Statement of Guidance

Data Subject Access Request Guide for Controllers

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is guidance from the Guernsey Office of the Data Protection Authority (ODPA) explaining how organisations acting as data controllers should handle data subject access requests (DSARs) under the Data Protection (Bailiwick of Guernsey) Law, 2017. It provides a step by step process form and accompanying explanatory notes covering the full lifecycle of a DSAR, from recognising and logging a request through to final disclosure.

  • Recognise and log requests: Staff must be able to identify a DSAR (which can be made verbally, in writing, or via social media, and need not reference the Law), log it in an internal DSAR register, and acknowledge receipt.
  • Assess validity and identity: Controllers must check the request is valid, verify the requestor's identity where in doubt, confirm any third party's authority to act on the individual's behalf, and apply additional care where the request concerns a child.
  • Screen for unfounded or excessive requests: Controllers may refuse (or in limited circumstances charge a reasonable fee for) requests that are manifestly unfounded, frivolous, vexatious, unnecessarily repetitive, or otherwise excessive, but bear the burden of proving this and must document their reasoning.
  • Search, safeguard and review data: Controllers must enact safeguards so only routine changes are made to data while a request is processed, and carry out a comprehensive search including any processors engaged.
  • Respond within the statutory timeframe: Controllers must respond within one month of a valid request, extendable where the request is complex, with the requestor notified of and given reasons for any extension.
  • Handle third party data: Where a response would include another person's personal data, controllers must redact it where possible or perform a balancing test between the requestor's right of access and the other person's rights.
  • Apply and record exemptions: Any exemptions relied upon must be documented internally and generally explained to the requestor, along with reasons for withholding information.
  • Provide Schedule 3 information: The response must include the information required by Schedule 3 of the Law (e.g. identity of controller, purposes and legal basis of processing, recipients, retention periods, data subject rights, right to complain to the Authority, and details of any automated decision making).
  • Ensure understandability: If the material sent would not be understandable to the requestor, controllers must prepare and provide additional explanatory guidance alongside the data.

The guide also includes worked examples distinguishing business as usual requests from valid DSARs, a glossary of key terms, and the full text of Schedule 3 of the Law as an appendix.

Key obligations

  • Controllers must log each DSAR in an internal register and acknowledge receipt.
  • Controllers must verify the identity of a requestor where there is doubt, and confirm a third party's authority to act on an individual's behalf.
  • Controllers must respond to a valid DSAR within one month, and may only extend this period where the request is complex, notifying the requestor of the extension and the reason for it.
  • Controllers must not charge a fee for supplying the information except in limited excessive, repetitive, or manifestly unfounded circumstances, where they bear the burden of proving this and must document their reasoning.
  • Controllers must carry out a comprehensive search for the requested information, including contacting any processors engaged, and must safeguard against non-routine changes to the data during processing.
  • Where a response includes another person's personal data, controllers must redact it where possible or otherwise conduct a balancing test between the two individuals' rights.
  • Controllers must document the reasons for applying any exemptions and generally explain to the requestor which exemptions were applied and why.
  • Controllers must provide, alongside the personal data disclosed, all information required by Schedule 3 of the Law.
  • If the disclosed information would not be understandable to the requestor, controllers must provide additional explanatory guidance with it.

Applies to

data controllers, processors (referenced in relation to controller obligations)

Deadlines

  • one month: Standard statutory period within which a controller must respond to a valid data subject access request.
  • extension where request is complex: The one month response period may be extended for complex requests, provided the requestor is notified of the extension and the reason for it.

Topics

Version history

2026-07-30

source file (current)