Statement of Guidance

Subject Access Request Guide for Data Subjects

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is guidance from the Guernsey Office of the Data Protection Authority explaining, for individuals (data subjects), how to make a subject access request (SAR/DSAR) under the Data Protection (Bailiwick of Guernsey) Law, 2017, what organisations (controllers/processors) must provide in response, and what recourse is available if a request is mishandled. It is aimed primarily at individuals but sets out the corresponding obligations that controllers and processors must meet.

  • Making a request: An individual can request a copy of all personal data an organisation holds about them, in any form, made in writing, by phone or otherwise; the guidance recommends email or letter to the DPO or equivalent contact.
  • No fee generally: Organisations cannot charge a fee for responding to a DSAR unless they can prove the request is frivolous, vexatious, unnecessary or repetitive; the burden of proof is on the organisation.
  • Response timeframe: Organisations must respond within one month of the later of receipt of the request, receipt of identity verification information, or payment of any permitted fee; this can be extended by up to two further months for complex requests, provided the individual is notified within the original one month period with reasons.
  • Identity verification: Organisations may request reasonable identifying information but must not over-request where identity is already clear, and should scale verification to the risk of harm from wrongful disclosure.
  • Automated decision-making: Organisations must proactively disclose whether decisions about the individual are made by automated processing and, where so, provide meaningful information about the logic, significance and envisaged consequences.
  • Content of response (Schedule 3): Alongside a copy of the personal data, organisations must provide Schedule 3 information: whether data is special category, its source, legal basis, recipients, any transfers outside authorised jurisdictions, retention period, and any automated processing, all explained in intelligible terms.
  • Format of response: Written requests should be answered in printout, photocopy, letter or form format; electronic requests should be answered in a commonly used electronic format unless otherwise agreed.
  • Refusal or withholding: Organisations may refuse manifestly unfounded, frivolous, vexatious, unnecessary or repetitive requests, or withhold third party personal data absent consent or reasonable justification, but must generally state reasons and inform the individual of their right to complain to the ODPA or bring civil action.
  • Non compliance: If an organisation fails to respond in time or adequately, the individual should send a written reminder before escalating; the ODPA can assist and may investigate under Section 68 of the Law upon a formal complaint with supporting evidence.

The guide includes a template DSAR letter and reproduces Schedule 3 of the Law listing the specific information controllers must give data subjects. It does not itself change the Law but explains existing statutory obligations on Guernsey controllers and processors.

Key obligations

  • Organisations must not charge a fee for responding to a DSAR unless they can demonstrate the request is frivolous, vexatious, unnecessary or repetitive, with the burden of proof on the organisation.
  • Organisations must respond to a DSAR within one month of the later of receipt of the request, receipt of identity verification information, or payment of any permitted fee.
  • Where a request is complex, organisations may extend the response period by up to two further months but must notify the individual of the extension and reasons within the original one month period.
  • Organisations must request only reasonable and proportionate identity verification information, scaled to the risk of harm from wrongful disclosure.
  • Organisations must proactively inform individuals whether decisions about them are made by automated processing and provide meaningful information about the logic, significance and envisaged consequences.
  • Organisations must provide, alongside the personal data itself, the information listed in Schedule 3 of the Law (special category status, source, legal basis, recipients, cross border transfers, retention period, automated processing), explained in intelligible terms.
  • Responses to written requests must be provided as a computer printout, photocopy, letter or form (unless not possible or otherwise agreed); electronic requests must be answered in a commonly used electronic format unless otherwise agreed.
  • If refusing or withholding information (e.g. as manifestly unfounded, frivolous, vexatious, unnecessary, repetitive, or to protect a third party's data), the organisation must generally explain why and inform the individual of the right to complain to the ODPA and to bring a civil action.

Applies to

controllers, processors, data subjects (individuals)

Deadlines

  • within one month: Organisations must respond to a subject access request within one month of the later of receipt of the request, receipt of identity verification, or payment of any permitted fee.
  • a further two months: Where a request is complex, the response period may be extended by up to two further months, with notice given to the individual within the original one month period.

Topics

Version history

2026-07-30

source file (current)