Subject Access Requests SAR & FOI Management
Expert management of Subject Access Requests under UK GDPR and Freedom of Information requests under FOIA 2000. We handle the entire process — logging, searching, exemptions, redaction and compliant response within statutory timescales.
SAR & FOI Services
Complete request management from receipt to response.
SAR Management
End-to-end Subject Access Request handling — logging, identity verification, scope clarification, system searches, exemption assessment, redaction and compliant response within one month.
FOI Management
Freedom of Information request handling for public authorities — logging, search, exemption assessment (qualified and absolute), public interest test and response within 20 working days.
Redaction Services
Expert redaction of third-party personal data, legally privileged material, safeguarding information and other exempt content from SAR and FOI disclosures.
Exemption Assessment
Assessment of applicable exemptions — third-party data, legal privilege, safeguarding, crime prevention, management forecasting, negotiations, exam scripts and regulatory functions.
Excessive Request Assessment
Assessment of whether requests are manifestly unfounded or excessive, justifying refusal or fee charging. Documentation of the reasoning for ICO if challenged.
Rights Training
Staff training on recognising and handling individual rights requests — SARs, erasure, rectification, portability, objection and restriction. GDPR training →
Risk Assessments for Your Sector
Every industry has different hazards. We tailor every assessment to your specific sector and operations.
Factories & Warehousing
Machinery, forklift, racking, noiseTransport & Logistics
Depot safety, loading bays, vehiclesConstruction
CDM, excavations, heights, demolitionSchools & Education
Classrooms, labs, playgrounds, tripsCare & Healthcare
Patient handling, clinical, infectionChemical
Process safety, COSHH, DSEARHospitality
Kitchens, fire, slips, public safetySMEs & Offices
DSE, fire, general workplaceCharities
Events, lone working, volunteersHow We Carry Out a Risk Assessment
Receipt & Logging
We log the request, verify the requester's identity and clarify scope where needed — within the statutory timescale.
Search & Retrieval
We search all relevant systems — databases, email, paper records, cloud storage, CCTV, backups — for personal data matching the request.
Exemptions & Redaction
We assess applicable exemptions, redact third-party data and legally exempt material, and compile the disclosure bundle.
Quality Review
Every response is quality-checked for completeness, accuracy, appropriate redaction and compliance with Article 15 supplementary information requirements.
Response & Recording
Compliant response issued within the statutory timescale. Full documentation retained in your SAR/FOI register for accountability.
Subject Access Requests FAQ
Can we charge for a SAR?
Generally no. SARs are free under UK GDPR. You may charge a reasonable fee or refuse only if the request is manifestly unfounded or excessive. The bar for this is very high. RADCaT advises on whether refusal or charging is justified in specific cases.
What is the deadline for responding?
SARs: one calendar month from receipt (can be extended by two months for complex requests with notification to the requester). FOIs: 20 working days. Missing these deadlines is a compliance failure that can trigger ICO investigation.
What if the SAR involves other people's data?
Third-party personal data must be redacted unless the third party consents or it is reasonable to disclose without consent. This requires careful assessment — particularly in school settings where pupil data, parent data and staff data often overlap in the same documents.
Do you handle SARs during employment disputes?
Yes. Employment-related SARs are often tactical — submitted during grievances, disciplinaries or pre-tribunal. They require careful handling to ensure compliance while protecting legally privileged material and management information. RADCaT has extensive experience with employment SARs.
What exemptions can we use?
Depends on the request type. SAR exemptions include third-party data, legal privilege, crime prevention, regulatory functions, management forecasting, negotiations and exam scripts. FOI exemptions include personal data, commercial interests, law enforcement and policy formulation. Each exemption has specific conditions.
Is SAR handling included in DPO services?
Yes. For RADCaT DPO clients, SAR and FOI management is included in the annual retainer. For non-DPO clients, we provide SAR handling as a standalone service.
How much does SAR management cost?
For DPO clients: included. Standalone: priced per request based on complexity. Volume packages for organisations receiving regular requests. Contact us for pricing.
Need SAR or FOI Support?
Get in touch for immediate support with a pending request or to discuss ongoing management.