Skip to content
DutyHub

Templates

Subject access request log

Two dates decide whether a response is late, and one of them is not the date somebody started work on it.

Download the CSV

No email address required. It is a file.

What it records

Date received and how that date was established are separate columns because the second is what settles a dispute about lateness. Extension and reason are separate from the deadline for the same reason: an extension is a declared decision with conditions attached, not a later date somebody adopted.

The columns

ColumnWhat goes in it
Reference Your reference.
Date received When it arrived anywhere in the organisation.
How received Email, letter, verbally, in a complaint.
How date established Postmark, email header, note of the conversation.
Requester Who is asking.
Identity verified Whether verification was needed, and how it was done.
Deadline One calendar month from receipt.
Extension applied Yes or no.
Extension reason Why, and the date the requester was told.
Exemptions applied Which, and the reasoning.
Date responded When it was sent.
How sent And to what address.

This is a starting point, not a compliance document. What your organisation actually needs to record follows from your own risk assessment and from the arrangements you have in place; a template cannot know either. Nothing here is legal advice.

Or stop keeping it in a spreadsheet

A spreadsheet records what you type into it. It does not chase you when a week is missed, turn a duty amber when a check falls due, or raise an action from a failed reading — and it is not much use as evidence, because it can be edited afterwards without trace.

How DutyHub handles dsars Recurring checks See pricing