AMLEGALS — Strategic Lawyering
Rights Management

How to Handle Data Subject Access Requests

Establishing efficient procedures for responding to Data Principal information requests

Updated 17 January 2025

Executive Summary

The right of access enables Data Principals to understand what personal data organisations hold about them and how it is processed. Organisations must establish procedures to receive, verify, and respond to these requests within prescribed timelines. This guide provides a practical framework for access request management.

Key Takeaways

  • 1
    Establish clear intake channels for receiving access requests across all customer touchpoints
  • 2
    Implement identity verification proportionate to the sensitivity of data requested
  • 3
    Search all systems comprehensively, including backups and archived data
  • 4
    Provide responses in accessible formats within regulatory timelines
  • 5
    Document the handling process to demonstrate compliance

1Understanding the Right of Access

Section 11 grants Data Principals the right to obtain from the Data Fiduciary a summary of personal data being processed and the processing activities undertaken. This is not unlimited access to raw data but rather comprehensible information about what data exists and how it is used.

2Establishing Intake Procedures

Requests may arrive through multiple channels. Organisations need centralised procedures to capture and route them appropriately.

1

Define Intake Channels

Determine how requests will be received. Options include dedicated email addresses, web forms, in app request features, and physical mail. Publishing these channels in privacy notices guides requesters.

2

Centralise Receipt

Route all requests to a central team or system for consistent handling. Requests received by customer service, sales, or other teams should be forwarded promptly.

3

Acknowledge Receipt

Confirm receipt of the request to the requester, indicating expected timelines and any additional information needed.

4

Log and Track

Maintain a register of all requests including receipt date, requester identity, request scope, and status. This enables timeline compliance monitoring.

3Verifying Requester Identity

Before disclosing personal data, verify that the requester is indeed the Data Principal or their authorised representative. The level of verification should be proportionate to the sensitivity of data involved.

1

Authentication Methods

For existing customers, use established authentication such as account login. For others, request identifying information sufficient to match against records.

2

Authorised Representatives

Where someone requests on behalf of a Data Principal, require proof of authorisation such as a power of attorney or, for minors, evidence of guardianship.

3

Balancing Security and Accessibility

Verification should not be so onerous that it effectively denies the right. Requiring excessive documentation may itself constitute non-compliance.

Important Warnings

  • •Disclosing data to an impersonator constitutes a breach. Verification is essential.
  • •Demanding in-person appearance or notarised documents is generally disproportionate for routine requests.

4Searching for Responsive Data

A comprehensive search is essential. Organisations often hold personal data in more locations than initially apparent.

1

Identify Data Sources

Reference the data inventory to identify all systems containing personal data. Include databases, file shares, email systems, cloud services, and third party platforms.

2

Execute Searches

Search each identified source using appropriate identifiers. For unstructured data, this may require keyword searches or manual review.

3

Include Backups and Archives

Data in backup systems and archives remains subject to access rights. Determine whether retrieval is practicable and document the approach.

4

Check Third Party Holdings

Where processors hold data on behalf of the organisation, coordinate retrieval. Contractual arrangements should facilitate this.

5Preparing the Response

The response must be comprehensible to the requester, not merely a data dump that satisfies the letter but not the spirit of the right.

1

Organise Information Logically

Structure the response to help the requester understand what data exists and how it is processed. Group related information and use clear headings.

2

Provide Processing Context

Include information about processing purposes, categories of recipients, retention periods, and the source of data if not collected directly.

3

Use Accessible Formats

Provide the response in a format the requester can access. Common formats include PDF for documents and CSV or JSON for structured data.

4

Redact Third Party Data

Where responding would disclose another individual's personal data, redact that information unless the third party has consented to disclosure.

6Meeting Timeline Requirements

Responses must be provided within the timeframe specified in the Rules. Currently, this requires response without unreasonable delay. Organisations should establish internal targets to ensure compliance.

Practical Tips

  • •Set internal deadlines shorter than regulatory requirements to allow buffer for complex requests
  • •Establish escalation procedures for requests that cannot be completed within standard timelines

7Handling Complex Situations

Not all requests are straightforward. Establish procedures for common complexities.

1

Clarification Requests

If the request is unclear or overly broad, seek clarification before proceeding. This is not a delay tactic but a means to provide relevant responses.

2

Partial Responses

Where some information can be provided promptly while other searches continue, consider providing a partial response rather than delaying entirely.

3

Exemptions

Certain data may be exempt from disclosure, such as information subject to legal privilege or that would compromise security. Document the basis for any exemption claimed.

4

Denials

If the request must be denied, explain the reason clearly and inform the requester of their right to complain to the Data Protection Board.

Frequently Asked Questions

Need Implementation Support?

Our data protection team can help translate these guidelines into organisation-specific policies, procedures, and technical implementations.

Get Expert Guidance

Handle Data Subject Access Requests: questions and answers

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What must a DPDPA privacy notice contain?

Section 5 read with Rule 3 requires a notice, understandable independently of other information, that itemises the personal data and the specified purpose, and explains how the Data Principal may withdraw consent, exercise rights and complain to the Board. A Data Principal has the right to access the notice in English or any language specified in the Eighth Schedule to the Constitution. The design of translation operations is an implementation matter.

When must personal data be erased under DPDPA?

Section 8(7) requires erasure once the specified purpose is no longer served or consent is withdrawn, unless retention is required by law. Rule 8 and the Third Schedule prescribe time periods for specified classes of Data Fiduciaries, with prior intimation to the Data Principal before erasure.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Handle Data Subject Access Requests?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Handle Data Subject Access Requests under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Handle Data Subject Access Requests under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Handle Data Subject Access Requests?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Handle Data Subject Access Requests rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Handle Data Subject Access Requests?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Handle Data Subject Access Requests · DPDPA Exposure Assessment