Subject access request log
Two dates decide whether a response is late, and one of them is not the date somebody started work on it.
No email address required. It is a file.
What it records
Date received and how that date was established are separate columns because the second is what settles a dispute about lateness. Extension and reason are separate from the deadline for the same reason: an extension is a declared decision with conditions attached, not a later date somebody adopted.
The columns
| Column | What goes in it |
|---|---|
| Reference | Your reference. |
| Date received | When it arrived anywhere in the organisation. |
| How received | Email, letter, verbally, in a complaint. |
| How date established | Postmark, email header, note of the conversation. |
| Requester | Who is asking. |
| Identity verified | Whether verification was needed, and how it was done. |
| Deadline | One calendar month from receipt. |
| Extension applied | Yes or no. |
| Extension reason | Why, and the date the requester was told. |
| Exemptions applied | Which, and the reasoning. |
| Date responded | When it was sent. |
| How sent | And to what address. |
This is a starting point, not a compliance document. What your organisation actually needs to record follows from your own risk assessment and from the arrangements you have in place; a template cannot know either. Nothing here is legal advice.
Or stop keeping it in a spreadsheet
A spreadsheet records what you type into it. It does not chase you when a week is missed, turn a duty amber when a check falls due, or raise an action from a failed reading — and it is not much use as evidence, because it can be edited afterwards without trace.