Skip to content
← All articles

14 September 2026 · 7 min read

A client asks for their file: what a subject access request actually requires

A client emails: "Can I have a copy of everything you hold on me?" No mention of GDPR, no form, maybe just that one line. It still counts, and the clock on your response started the moment you read it.

That's a subject access request (SAR), and it's a different right from the one in our piece on the new complaints procedure: a complaint is someone unhappy with how you've handled their data, a SAR is someone asking to see it. Both land on you as the data controller, and both are worth knowing cold before either arrives, because working it out from scratch while a client is waiting is the wrong moment to be reading the rules for the first time.

This is general information about a legal requirement, not legal advice. It doesn't account for your specific records or situation, and where a request turns out to be genuinely complicated, that's a conversation for a solicitor or your professional body, not this article.

What counts as a request, and what doesn't

There's no required form or wording. "Can I see my file", "send me my records" and "what information do you have about me" are all valid subject access requests, however they arrive: email, a message through your booking system, even something said in a session and then confirmed in writing. You don't get to insist it comes through a particular channel, though you can ask the person to confirm their identity if you're not already certain who you're dealing with.

What it covers is the personal data you hold about that person: session notes, contact details, invoices, correspondence, anything that identifies them. It is not a general right to ask you to explain your clinical reasoning or justify decisions you made in the room; it's access to the data, not an audit of the therapy.

The one-month clock, and when it can move

You have one calendar month from the day you receive the request to respond, and the ICO's guidance is clear that this can be extended by up to two further months if the request is complex or you're dealing with a number of requests from the same person, provided you tell them within the first month that you're doing so and explain why. For most solo practices with one client's file to pull together, the extension is the exception, not something to reach for by default.

There's normally no fee for a standard request. You can only charge a reasonable administrative fee, or refuse outright, where a request is genuinely manifestly unfounded or excessive, and the bar for that is higher than it sounds: wanting a lot of information isn't excessive on its own, and "it was a lot of work" isn't a defence if the ICO asks you to justify a refusal. Reserve this for requests that are plainly repetitive or clearly intended to harass rather than to see data.

What you actually send

A full copy of the personal data itself, in a clear and accessible form, along with an explanation of what you hold and why, if that isn't already obvious from your privacy notice. It doesn't have to be photocopies of your literal notes if a clean, readable extract or export covers the same ground, but it does have to be complete: picking out the flattering parts and leaving out the rest isn't compliant, whatever the temptation.

The exemption most private practices will actually use: other people's data

Session notes rarely mention only the client. A partner, a parent, a colleague they've described might appear by name. Where disclosing that would identify or reveal information about someone else, you can withhold that specific detail, but the exemption applies to that piece of information, not to the file as a whole. The practical approach is redaction: go through the record and take out what would identify the third party, then send everything else. Refusing the whole request because a few lines mention someone else is not what the exemption is for, and if a request has a lot of third-party material tangled through it, that's a case worth getting advice on before you respond rather than guessing.

The exemption specific to health records

This is the one that catches therapists particularly, because it doesn't apply to most other small businesses handling a SAR. Under the Data Protection Act 2018, information doesn't have to be disclosed where doing so would be likely to cause serious harm to the physical or mental health of the client or of someone else. It isn't a general discretion to withhold anything uncomfortable, and it isn't something you get to decide alone by re-reading your own notes: the assessment has to come from the health professional who was, or is, responsible for the person's care, and that person has to be able to clearly set out the reasoning for withholding a specific part of the record, not just assert that it might be upsetting.

For most sessions, most of the time, this exemption won't apply, because most notes don't meet that bar. Where you genuinely think it might, that's a decision to take carefully, document, and where there's any doubt, discuss with a supervisor or your professional body before you act on it, rather than a box to tick as a matter of routine.

Building the five-minute version now, before you need it

You don't need a formal SAR policy published anywhere, but having a short routine ready means the first real request doesn't turn into a scramble:

  1. Know where a request could arrive. Email, your booking system's messaging, social media. If you spot one, the clock has already started whether or not you've formally "logged" it yet.
  2. Confirm identity if there's any doubt, especially for a request that doesn't come from the address or account you already know the client by.
  3. Pull together what you hold: session notes, contact and billing records, any correspondence. Faresay keeps your session and client records in one place and lets you export them, which covers most of what a request actually needs; anything you hold outside it (email threads, a separate invoicing tool) you'll still need to gather yourself.
  4. Read through for anyone else's data before you send anything, and redact rather than refuse.
  5. Reply within the month, or write to the client within that month explaining a specific, justified extension if the request is genuinely complex.

Where this sits against the ICO fee and the complaints procedure

The £52 annual fee is about being a registered data controller at all. The new complaints right is about what happens when someone is unhappy with how you've handled their data. A subject access request is neither: it's someone exercising their right to see what you hold, and it can arrive from a happy client just as easily as an unhappy one. Worth keeping the three straight in your own head, because they carry different clocks and different obligations.

The ICO has been working through an update to its subject access guidance for small organisations this year, aimed at making the practical mechanics clearer for exactly this kind of business. Worth a look at the current version on ico.org.uk before you rely on anything here, since guidance gets refined and this piece won't be updated to track every change.


This article describes UK data protection law as it stood in September 2026, and is general information, not legal advice. It doesn't cover every circumstance, particularly around third-party data and the health-records exemption, where the right answer depends on the specific record in front of you. Check current ICO guidance and take advice from a solicitor or your professional body where a request is genuinely difficult.

Faresay acts as a data processor for the therapists who use it, and keeps client records exportable so pulling together what you hold is straightforward. Read how we handle data.

If you need help right now, please see urgent support. Faresay is not a crisis service.

Ready to talk to someone? Get matched with a verified therapist in minutes.

Find your therapist