‘A Practical Guide to Managing GDPR Data Subject Access Requests – Second Edition’ by Patrick O’Kane


Paperback: 978-1-914608-54-4
Published: November 2022
Read a FREE chapter online now

Purchase from ourselves by adding to cart below, or purchase with optional Prime delivery from Amazon, here.

SKU: B0267 SUBJECTACCESSREQUESTS 2 Categories: , Tags: , , , ,


Second Edition including updated case law and legal references.

How should your company or law firm respond to requests from people who want to access their personal data?

GDPR gives individuals the right to access and seek a copy of all of the personal data your company holds on them. This may include access to emails, call recordings, CCTV footage and any other record containing their personal data.

A study showed that companies spend up to £1.58 million per year dealing with GDPR Data Subject Access Requests (‘DSARs’/’Access Requests’). The Information Commissioner’s Office receives more complaints on Access Requests than any other issue.

Access Requests are a legal minefield. If Access Requests are mishandled, they can leave companies open to fines, litigation and reputational damage.

This concise practical guide explains how to comply with Access Requests under GDPR. The book explains how to:

  • Recognise Access Requests
  • Understand the UK data protection framework post-Brexit
  • Comply with the rules and time limits on Access Requests
  • Find the personal data
  • Redact the personal data
  • Understand the exceptions to Access Requests
  • Assess how legal professional privilege impacts Access Requests
  • Deal with Access Requests from your own employees
  • Draft a staff policy on Access Requests
  • Train Staff on Access Requests
  • Deal with other GDPR rights such as the ‘Right to Erasure’
  • Draft responses to employees and clients seeking access to their personal data

This book aims to put your company on the right side of GDPR Data Subject Access Requests.


Patrick O’Kane is an in-house barrister with a multinational organisation. Patrick is also the author of the books ‘GDPR: Fix it Fast – How to Apply GDPR to Your Company in Ten Steps’,  ‘A Practical Guide to GDPR in Financial Services’ and ‘A Practical Guide to Managing GDPR Data Subject Access Requests’ which received a 5-star review in The Law Society Gazette.


“I cannot fault this book. It does what it says it will do…Nietzsche once stated that he sought to say in 10 sentences what others say in a whole book. However, he never had to deal with a DSAR. This author clearly has, and given the potential complexities of the subject, has made a virtue of its relative brevity. I’ll be keeping a copy in my library.”
The Law Society Gazette


Chapter 1 – What is an Access Request?
Chapter 2 – Which Categories of Data Can a Person Access?
Chapter 3 – Access Requests: The Formalities
Chapter 4 – The Search
Chapter 5 – Third Party Data
Chapter 6 – Training Staff on Access Requests
Chapter 7 – Employee Access Requests
Chapter 8 – Further Rights Under GDPR
Chapter 9 – Exemptions
Chapter 10 – Frequently Asked Questions
Appendix 1 – Templates for Responding to Access Requests
Appendix 2 – Access Request Policies