Acknowledge it, confirm who is asking, search every location you hold information, and provide what you have in a readable form within the period that applies to you.

What usually prompts one

Rarely idle curiosity.

Most requests arrive attached to something else: a dispute about work, a complaint, an insurance matter, an unwanted marketing email, or somebody who has decided to leave and wants to know what you kept.

Knowing that is useful, because the underlying issue is frequently the thing to address, and handling the request well is often what defuses it.

What follows is a general description rather than legal advice, and the applicable timeframes, exceptions, and requirements depend on where you operate.

Recognise it as a request

The first failure, and it happens more than the process failing.

These rarely arrive labelled. Somebody writes asking what information you have about them, or what you did with their details, in an ordinary email to whoever they normally deal with.

That email then sits in an inbox while somebody wonders whether to reply, and the clock is already running.

Tell whoever monitors your inboxes that a message asking what information you hold should be passed to one named person immediately, whatever it looks like.

That instruction takes two minutes and prevents the most common problem, which is a request discovered three weeks later.

The sequence

The fourth is where the work is and the fifth is where the judgement is.

Confirming who is asking

A necessary step and one that is easy to overdo.

You need reasonable confidence the person is who they say, because sending somebody's records to the wrong person is a worse outcome than a delayed response.

Reasonable usually means the request coming from the email address you already hold for them, or a detail only they would know, such as a recent invoice number.

What is not proportionate is demanding photographic identification from a customer you have dealt with for six years, which reads as obstruction and is frequently more information than you held in the first place.

Match the check to the sensitivity of what you are about to send.

Searching properly

This is why the inventory matters, and it is the step people underestimate.

Search every location: the customer system, accounting, email including archives and sent items, any messaging threads, paper files, the website form archive, third-party services, and photographs.

Search on more than one term, since somebody may appear under a maiden name, a company name, a nickname, an old address, or a misspelling.

Staff phones are the awkward one, particularly where job photographs or message threads live there, and it is worth asking rather than assuming there is nothing.

Keep a note of where you looked, which turns a vague assurance into a defensible answer if the person says you must have more.

A worked example

A firm received an email from a former customer, in the middle of a dispute about a job, asking for everything they held about him.

The initial reaction was that this was an escalation to be resisted.

They treated it as an ordinary request instead. Two people spent an afternoon searching seven locations and found correspondence, invoices, job notes, eleven photographs, and a mailing list entry.

They removed a colleague's personal mobile number from one email chain and redacted a second customer's address from a scheduling note, and sent the rest as a labelled folder with a covering letter explaining what each part was.

The customer replied thanking them and the dispute settled shortly afterwards.

The owner's view was that responding openly had cost an afternoon and had done more to resolve the argument than anything else they tried.

Other people's information

The one genuinely difficult part, and it needs care rather than speed.

Records about one person frequently contain information about others: a colleague's notes, another customer on the same schedule, a supplier's pricing, an employee's opinion.

You are not obliged to disclose other people's personal information in the course of answering somebody's request, and the usual approach is to redact those parts rather than withhold the whole document.

Internal opinions about the person are more nuanced and are frequently disclosable, which is a good reason for internal notes to be written as though the subject might read them.

Where a document is genuinely difficult to separate, that is the point to take advice rather than to guess.

How to send it

The practical half, which affects how the response is received.

Send it in a form the person can actually read: labelled files or a document, not a database export or a screenshot of a system.

Include a short covering note explaining what each part is and where it came from, since a bundle without context invites follow-up questions.

Send it securely where it is sensitive, which usually means a password-protected file or a link rather than a large open attachment.

And say what you have deleted or do not hold, if that is relevant, rather than leaving a silence somebody will interpret.

The counter-case

Not every request needs the full process.

Somebody asking casually whether they are still on your mailing list is asking a question, and the proportionate answer is to check and tell them rather than to open a formal exercise.

Reading every enquiry as a formal request produces a defensive tone with people who simply wanted to know something.

Equally, a small number of requests are made to be difficult, and the answer there is the same as for any other: respond properly, within time, and keep a record. Treating a hostile request differently is how businesses create the problem they feared.

Answer the question that was asked, at the level it was asked, and escalate to the full process when the scope or the context warrants it.

Being ready

  1. Tell your team to pass these to one named person.
  2. Keep the inventory current so you know where to look.
  3. Acknowledge within a day or two.
  4. Check identity proportionately.
  5. Search on several name variants, including phones.
  6. Redact other people rather than withholding documents.
  7. Send it readable, with a covering explanation.

Step one is the cheapest preparation available and prevents the failure that actually happens.

The records behind the answer are covered in consent you can actually evidence.


Frequently asked questions

What usually prompts an access request?

Something else: a dispute, a complaint, an insurance matter, or unwanted marketing. The underlying issue is often the thing to address, and handling the request well frequently defuses it.

What is the most common failure?

Not recognising it. These rarely arrive labelled, so a request sits in an inbox while somebody wonders whether to reply. Tell your team to pass any such message to one named person.

How should I confirm identity?

Proportionately. The request coming from an address you already hold, or a detail only they would know. Demanding photo identification from a long-standing customer reads as obstruction.

Where do I need to search?

Everywhere you hold information: customer systems, accounting, email including archives and sent items, messaging threads, paper, form archives, third-party services, and phones.

What about information about other people?

Redact those parts rather than withholding whole documents. Internal opinions about the requester are frequently disclosable, which is a reason to write notes as if they might be read.

Does every enquiry need the full process?

No. Somebody asking whether they are still on your mailing list is asking a question. Answer at the level asked, and escalate when the scope or context warrants it.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Nobody knows who would handle one?

Name a person and tell whoever reads your inboxes to forward anything asking what information you hold. Two minutes.

Start a Conversation