Subject Access Requests Under GDPR: A Care Home's Practical Guide

Learnsignal Education Team
Updated

A subject access request (SAR) gives someone the legal right to ask a care home what personal data it holds about them and to receive a copy of it. For a care home, that most often means a resident, a family member acting on a resident's behalf, or occasionally a current or former member of staff. Most general GDPR training touches on SARs briefly as one right among several; in practice, handling one properly involves a specific process with real deadlines and genuine pitfalls, which makes it worth understanding on its own terms.

Who Can Make a Request, and About Whom

A SAR can be made by the person the data is about, or by someone authorised to act on their behalf — a solicitor, an attorney under a registered power of attorney, or a deputy appointed by the Court of Protection. A family member who isn't formally authorised to act for the resident does not automatically have the right to request the resident's personal data, even if their intentions are good; care homes need a clear, consistent way of checking authority before releasing anything; where a resident lacks capacity to make the request themselves and no one holds formal authority to act for them, the request should be handled carefully and usually with input from the resident's care team about what's genuinely in their best interests to disclose.

The One-Month Clock

A care home has one calendar month from receiving a valid request to respond, starting from the day the request is received (or from when identity is verified, if that took additional time). This can be extended by a further two months for requests that are particularly complex or numerous, but the requester must be told about the extension, and the reason for it, within the original month — silence past the deadline is not an acceptable way of buying more time.

What Actually Has to Be Provided

A SAR response should include a copy of the personal data held about the individual, along with supplementary information: why the data is processed, who it's shared with, how long it's kept, and the person's other rights under data protection law. This includes care notes, incident reports, safeguarding records and correspondence that mention the individual — a SAR reaches considerably further than most people expect, and care homes should be prepared for that scope rather than assuming a request only covers an obvious document like a care plan.

The Part Everyone Gets Wrong: Third-Party Data

Care records routinely contain information about other people — another resident, a family member, a member of staff — mixed in with the requester's own data. This third-party information generally shouldn't be disclosed without that person's consent, or unless it's reasonable to disclose it without consent given the circumstances. In practice, this means every SAR response needs a careful read-through to redact or remove references to other individuals before anything is sent out, which is often the single most time-consuming part of the process and the step most likely to be rushed under deadline pressure.

Common Mistakes to Avoid

The most frequent errors are treating an informal request ("can you tell me what's in Mum's file?") as something other than a SAR just because the word "GDPR" wasn't used — a request doesn't need to name the legislation to count; missing the one-month deadline because the request sat unactioned in someone's inbox; and releasing third-party information because a redaction pass was skipped under time pressure. A clear internal process — a named point of contact, a logging system for incoming requests, and a checklist for identity verification and redaction — prevents all three.

Connecting SARs to Wider Data Protection Practice

Handling SARs well depends on the same underlying data protection discipline covered in our guide to data breach and cyber incident response — knowing what personal data you hold, where it's stored, and who has access to it. A care home that struggles to quickly locate everything held about a particular resident will find SAR deadlines far harder to meet than one with well-organised, centralised records.

Frequently Asked Questions

Can we charge a fee for a subject access request? Generally no — requests are usually free of charge, except where a request is manifestly unfounded or excessive, or where someone asks for further copies of data already provided, in which case a reasonable administrative fee may apply.

What if we can't meet the one-month deadline? Extend by up to two further months if the request is genuinely complex, but tell the requester about the extension and the reason within the original month — don't simply let the deadline pass without communication.

Do we have to hand over everything, including staff's personal notes about a resident? Generally yes, if it's personal data about the requester, though professional opinions and internal notes may still be disclosable — this is an area where seeking advice from your data protection officer or legal adviser is worthwhile if there's any doubt.

A well-handled SAR reassures residents and families that a care home takes their information seriously; a mishandled one can cause real reputational and regulatory harm. Learnsignal's CPD courses for care staff include data protection modules to help teams build this competence.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Healthcare Compliance & CPD Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View plans