Exceptions and other rights
Clarification, extensions, refusal, and specialist advice
Recognise when a subject access request cannot simply follow the standard journey, and handle the exception safely.
What this page covers
Most requests run straight through the access-request lifecycle. A few do not: you may genuinely need the requester to clarify what they want, the request may qualify for an extension, or it may raise a question — a fee, a refusal, an exemption, information about someone else — that is a legal judgement rather than a product step.
This page is a signpost, not a legal analysis. It shows you what DSAR Respond can record, what the ICO says at a high level, and where the line is between something you can decide at your desk and something to put in front of your organisation's data protection officer or legal adviser. Where a decision is fact-specific, this guidance deliberately does not tell you the answer.
Ask for clarification
Clarification is not a routine step and it is not a way to make a broad request smaller. Ask only when you process a large amount of information about the person and you genuinely cannot tell what they want without asking.
DSAR Respond has no built-in way to send a clarification request: the Correspondence tab on a case is read-only, and there is no clarification template or status. Contact the person through the channel you already use, then record the exchange yourself:
- Ask a specific, answerable question, and offer to help the person frame their request — do not simply invite them to narrow it.
- On the case's Timeline & Actions tab, use Add Note to record what you asked, when, and how.
- Add a second note when the reply arrives, or when it becomes clear none is coming.
While you wait, you can change the case status to On Hold with a Hold Reason of Awaiting Information, as described in Assess the request, scope, and response period.
On Hold is a product state, not a legal pause
Placing a case On Hold pauses only DSAR Respond's own countdown. It has no effect on the statutory response period, and the product does not track whether a clarification request qualifies. Only a qualifying clarification pauses the legal clock, and it is you — not the product — who determines whether this one does. Record the start of the pause, the reason, and the date the answer arrived, and keep the real deadline in view throughout.
UK GDPR context
You may ask for clarification only where you process a large amount of information about the individual and you genuinely require clarification to respond. Where that applies, the response period is paused until you receive the clarification. Anything else — an internal query, a question about delivery format, a general hold on work — does not pause it. If the person repeats the request without narrowing it, or does not reply, you still have to respond on the basis of a reasonable and proportionate search for everything they asked for. Check current ICO guidance before relying on a pause.
This is operational guidance for UK organisations, not legal advice.
Extend the response deadline
An Admin can extend a case's deadline from the case, using Extend Deadline to open the Extend Response Deadline dialog. Choose a Reason, set the New Deadline, add Notes, and leave Send extension notice to data subject ticked unless you have a recorded reason to notify the person another way. The steps are covered in Assess the request, scope, and response period.
UK GDPR context
An extension of up to two further months is available only where the request is complex, or where the person has made a number of requests. Volume alone does not make a request complex, and neither does needing help from a processor or a busy team. Where an extension applies you must tell the requester within the first month, and tell them why. Whether a particular request qualifies is a judgement on the facts — if you are not confident, escalate before extending rather than after.
This is operational guidance for UK organisations, not legal advice.
Setting a new date in the product does not create a lawful extension by itself. It records a decision you have already made, and sends the notice that goes with it.
Decisions that need specialist advice
The questions below share a shape: the law provides a test, and applying that test to your facts is a judgement your organisation has to make and be able to defend. DSAR Respond has no feature that decides any of them for you, and this documentation will not prescribe an outcome. Escalate to your data protection officer or legal adviser, and record the outcome on the case.
Fees and refusal
A subject access request is normally free, and refusing to act on one is exceptional. The tests for treating a request as manifestly unfounded or excessive — and for the alternatives of charging a reasonable fee or refusing to act — are set out in the ICO's guidance on manifestly unfounded or excessive requests. Each request has to be assessed on its own facts; a person having made requests before does not settle it.
Escalate before anyone acts on such a decision. If your organisation does decide to charge a fee or to refuse, there are things it must tell the requester and a time limit for telling them — check the ICO guidance above for what that notice has to contain, rather than drafting from memory.
DSAR Respond has no fee feature and no way to mark a request as refused. A refused request is still a case, and moving its status to Closed records no reason at all. Before you change the status, use Add Note to record the decision, who made it, what it relied on, what the requester was told, and when.
Exemptions
Exemptions can remove some or all of the information from what you must disclose. They are specific, narrow, and applied to particular material rather than to a request as a whole — see the ICO's guidance on relevant exemptions and Schedule 2 to the Data Protection Act 2018.
Applying one is a legal judgement. Do not withhold material on the assumption that an exemption "probably" covers it, and do not treat a redaction made during review as an exemption decision. Where you rely on an exemption, record which material it applies to and why.
Information about other people
Responses routinely contain other people's personal data — the sender of an email, a colleague named in a note. Deciding what to do with it involves balancing the requester's right of access against the other person's rights, and the ICO's guidance on information about other people explains the balance you are expected to strike.
Day-to-day redaction of third-party details happens during review and redaction. Escalate when the balance is genuinely difficult: when the third party objects, when withholding their information would make the response meaningless, or when the other person is identifiable even after redaction.
Requests that need specialist input
Some contexts carry their own rules and are outside the scope of this guidance. Get specialist advice for requests involving children or people who may lack capacity, health, education, or social work records, legally privileged material, criminal offence data or law enforcement processing, and requests to public authorities that also engage freedom of information duties.
Record every exception decision
Whatever is decided, the case is where the reasoning has to live — an account reconstructed months later is worth much less. The Activity Timeline records status changes, holds, and deadline extensions by itself, but it captures no reasoning, so Add Note is where the thinking has to go. Record what the exception was, who decided it, what they relied on, what the requester was told, and when. Keep the wording factual and assume someone outside your team will read it. See Complete the case and retain an audit record.
For a product problem rather than a judgement call, see Troubleshoot the core workflow or Contact product support. Support cannot advise on any of the decisions on this page.
Official sources
- ICO: Responding to a request, timing, identity, clarification, and extensions
- ICO: Manifestly unfounded or excessive requests
- ICO: Relevant exemptions
- ICO: Information about other people
- Data Protection Act 2018, Schedule 2
- Data (Use and Access) Act 2025, section 76
What happens next
What happens next
Continue to Other data rights in DSAR Respond — erasure, rectification, restriction, portability, and objection are separate rights with their own rules.
Last reviewed . UK regulatory context.