GDPR Subject Access Requests (DSAR) in Ireland — How to Respond
Any employee, customer, or job applicant whose personal data you hold can send you a Subject Access Request (SAR or DSAR) under Article 15 GDPR at any time, by any means — an email is enough, no special form is required. Irish businesses have a hard one-month deadline to respond, and getting it wrong is one of the most common triggers for a complaint to the Data Protection Commission (DPC). This guide covers what a DSAR requires, what you can withhold, and how to avoid the mistakes that turn a routine request into an enforcement matter.
What counts as a DSAR?
A DSAR is simply a request from an individual (a "data subject") asking whether you process their personal data and, if so, for a copy of it. It does not need to mention "GDPR", "Article 15", or "Subject Access Request" by name — a plain email asking "can you send me everything you hold on me" is a valid DSAR and starts the clock. Requests can come from current or former employees, customers, website users, or job applicants, and no reason needs to be given.
No fee can normally be charged for a first request. You may only charge a reasonable administrative fee, or refuse to act, where a request is manifestly unfounded or excessive — most commonly where it is repetitive.
The one-month deadline
You must respond within one calendar month of receiving the request (not one month of "processing" it — the clock starts on receipt). Where a request is complex or you have received a number of requests from the same individual, this can be extended by a further two months, but you must tell the individual about the extension — and explain why — within the first month. You cannot apply the extension retroactively after the first month has already passed.
What you must provide
- Confirmation as to whether or not you are processing their personal data
- A copy of the personal data itself, in an accessible format
- The purposes of the processing
- The categories of personal data concerned
- The recipients or categories of recipients the data has been or will be disclosed to
- How long you intend to keep the data, or the criteria used to decide that
- Where the data was not collected directly from the individual, its source
- Whether any automated decision-making or profiling is involved, and the logic behind it
What you can withhold or redact
- Other people's personal data — redact or omit third-party personal data unless that person consents or it is reasonable to disclose it without consent
- Material subject to legal professional privilege
- Confidential job references you gave about the individual to someone else
- Data that would prejudice a negotiation with the individual (e.g. an active dispute or settlement discussion) — limited and narrowly interpreted
- Requests that are manifestly unfounded or excessive, most often because they are repetitive with no new purpose
Verifying identity
You are entitled to take reasonable steps to confirm the requester is who they say they are before releasing data — for example, matching the request against records you already hold (an employee number, account email, or date of birth on file). Do not demand disproportionate identification (like a passport copy) where a lighter check would do; this itself can be treated as an unreasonable barrier to exercising the right.
Common mistakes that lead to a DPC complaint
- Missing the one-month deadline, or extending it without telling the individual in writing within that first month
- Only searching the obvious system (e.g. the CRM) and missing personal data held in email, shared drives, HR files, CCTV footage, or messaging tools like Slack or Teams
- Providing a partial response and treating the matter as closed, rather than confirming the search covered all reasonable locations
- Failing to redact third-party personal data properly, exposing another person's data in the process
- Refusing a request outright as "excessive" without being able to justify that assessment if challenged
What happens if you get it wrong
The DPC can investigate a complaint, issue a formal decision, and require corrective action. For serious or repeated non-compliance, GDPR allows administrative fines of up to €20 million or 4% of annual global turnover, whichever is higher — though in practice, most DSAR-related enforcement in Ireland results in corrective orders and reputational damage rather than maximum fines. Either way, a mishandled DSAR is avoidable with a clear, documented process.
Related guides
Need to generate this document now?
ComplianceDesk generates Irish-compliant documents in minutes — no accountant required.
Generate a DSAR response letter →