Can your team spot an access request?

A request for personal information may arrive through an ordinary inbox, not a special form.

By GDPRFix · Published · 2 min read
AI-assisted reporting and commentary · Official sources linked below.
Practical explainer

Practical explainer; use the current detailed guidance for deadlines, extensions and exceptions.

What happened

The ICO’s right-of-access guidance explains how organisations should recognise and respond to requests for personal information. Identity checks, response timing, searches and exemptions require consideration in context. The current guidance should be used when deciding how a particular request must be handled.

Source: ICO — original source ↗

What it means for your website

Imagine a customer writes, “Please send me the information you hold about me.” If your contact form categorises that as a general sales enquiry, someone still needs to recognise it and route it correctly. Give front-line staff a short escalation guide. Map the systems that may contain relevant information, including support mailboxes and account records. Avoid demanding excessive identity information by default, and do not disclose another person’s information without the appropriate review. A website contact address is useful, but finding it during a scan does not prove your organisation can fulfil a request.

Three useful next steps

  1. Train staff to recognise requests in ordinary language.
  2. Maintain a map of relevant systems and responsible staff.
  3. Use a tracked workflow for assessment and response.

Sources & context

Official sources consulted on 1 October 2026. A regulator’s announcement records its findings at that time; it is not proof of payment or the outcome of every later appeal.

ICO — original source

Our practical suggestions are GDPRFix commentary. A public website scan cannot establish your full legal position. For advice on a specific obligation or enforcement matter, use a suitably qualified adviser.

Keep reading