Skip to main content
SwiftCase
PlatformSwitchboardFeaturesSolutionsCase StudiesFree ToolsPricingAbout
Book a Demo
SwiftCase

Workflow automation for UK service businesses. Created in the UK.

A Livepoint Solution

Platform

  • Platform Overview
  • Workflow Engine
  • Case Management
  • CRM
  • Document Generation
  • Data Model
  • Integrations
  • Analytics

Switchboard

  • Switchboard Overview
  • Voice AI
  • Chat
  • Email
  • SMS
  • WhatsApp

Features

  • All Features
  • High-Volume Operations
  • Multi-Party Collaboration
  • Contract Renewals
  • Compliance & Audit
  • Pricing
  • Case Studies
  • Customers
  • Why SwiftCase

Company

  • About
  • Our Team
  • Adam Sykes
  • Nik Ellis
  • Implementation
  • 30-Day Pilot
  • Operations Pressure Map
  • For Your Role
  • Peer Clusters
  • Engineering
  • Careers
  • Partners
  • Press
  • Research
  • Tech Radar
  • Blog
  • Contact

Resources

  • Use Cases
  • Software
  • ROI Calculator
  • Pressure Diagnostic
  • Pilot Scope Estimator
  • Board Case Builder
  • Free Tools
  • Guides & Templates
  • FAQ
  • Compare
  • Glossary
  • Best Practices
  • Changelog
  • Help Centre

Legal

  • Privacy
  • Terms
  • Cookies
  • Accessibility

Stay in the loop

Cyber Essentials CertifiedGDPR CompliantUK Data CentresISO 27001 Standards

© 2026 SwiftCase. All rights reserved.

  1. Home
  2. Guides
  3. Data Protection
  4. Processing Data Subject Access Requests in Insurance Within 30 Days
Data ProtectionDSARs

Processing Data Subject Access Requests in Insurance Within 30 Days

A practical guide to handling DSARs efficiently and compliantly, addressing the unique challenges insurance firms face with complex multi-system data estates.

9 min readLast updated 2025-01-28Last verified 2026-02-18

The DSAR Challenge for Insurance Firms

30 days
Statutory deadline for responding to a valid DSAR
UK GDPR Article 12(3)

Data Subject Access Requests are one of the most operationally demanding aspects of UK GDPR compliance for insurance firms. Policyholders, claimants, and former customers have the right to obtain confirmation of whether their personal data is being processed, a copy of that data, and supplementary information about how it is used — all within one calendar month.

Insurance firms face particular complexity because policyholder data is typically spread across multiple systems: policy administration platforms, claims management systems, document management repositories, email archives, and third-party processor systems. A single DSAR may require searching dozens of data sources and coordinating responses from brokers, loss adjusters, and outsourced service providers.

The ICO reported a significant increase in complaints about DSAR handling in the financial services sector during 2024, with late responses and incomplete disclosures among the most common failings. Firms that rely on manual search-and-collation processes frequently exceed the one-month deadline, exposing themselves to ICO enforcement action and reputational damage.

A Streamlined DSAR Response Framework

Effective DSAR handling requires a combination of clear procedures, efficient search capabilities, and well-defined roles. Insurance firms need to establish a centralised DSAR management process that can identify, retrieve, review, and disclose personal data from across their entire data estate within the statutory timeframe.

Key to meeting the deadline is reducing the time spent on each phase of the process. Automated identity verification, pre-configured system searches, templated response letters, and workflow-driven review processes can compress what would otherwise be weeks of manual work into days.

Equally important is understanding the exemptions available to insurance firms. The DPA 2018 provides specific exemptions relevant to insurance, including for legal professional privilege, management forecasting, and — critically — for data processed for the purposes of prevention or detection of crime, which may apply to fraud investigation files.

Consistent one-month response compliance with automated deadline tracking
Reduced manual effort through pre-configured data source searches
Proper application of insurance-relevant DSAR exemptions
Audit trail of every DSAR from receipt to response for ICO accountability
Coordinated third-party data retrieval from brokers and service providers

Handling DSARs Step by Step

Follow this structured process to handle every DSAR consistently and within the statutory deadline.

1

Receive and Log the Request

A DSAR can be made verbally or in writing, in any format, and does not need to reference the UK GDPR or use the term "subject access request." Train all customer-facing staff to recognise DSARs. Log every request immediately in your central DSAR register with the date received — this is when the one-month clock starts. Assign a unique reference number and designated handler.

Create a simple checklist for frontline staff: if a customer asks "what data do you hold about me?" or "can I have a copy of my file?" — that is a DSAR and must be logged immediately.
2

Verify the Requester Identity

Before disclosing any personal data, verify that the requester is who they claim to be. For existing policyholders, you may be able to verify identity through their account details or security questions. For former customers or third-party requesters, you may need to request identity documentation. Do not use identity verification as a delay tactic — the ICO expects proportionate measures.

If you receive a DSAR from a solicitor acting on behalf of a data subject, you can request written authority from the individual before disclosing. The one-month clock pauses until you receive the authority.
3

Clarify and Scope the Request

If the request is broad or unclear, you may contact the requester to clarify what information they are seeking. This is particularly useful for insurance DSARs where the individual may have multiple policies, claims, or interactions over many years. However, you cannot refuse to act simply because the request is broad — if the requester does not narrow it down, you must process it as received.

4

Search All Relevant Data Sources

Conduct a thorough search across all systems that may contain the requester personal data. For insurance firms, this typically includes: policy administration systems, claims management systems, CRM platforms, email and correspondence archives, document management systems, telephony recordings, and any third-party systems operated by brokers or outsourced processors.

Maintain a pre-prepared DSAR search checklist listing every data source in your organisation. This ensures no system is overlooked and speeds up the search process significantly.
5

Review and Apply Exemptions

Review the retrieved data carefully to identify any information that is exempt from disclosure. Key exemptions for insurance firms include: legal professional privilege (Schedule 2, Part 5, Paragraph 19 DPA 2018), data relating to management forecasting or planning (Schedule 2, Part 5, Paragraph 22), crime prevention and detection (Schedule 2, Part 1, Paragraph 2), and third-party personal data that cannot be disclosed without the third party consent or where it would be unreasonable to do so.

6

Redact Third-Party Personal Data

Insurance files frequently contain personal data of third parties — other policyholders, claimants, witnesses, or employees. You must redact this information unless the third party has consented to disclosure or it is reasonable in all the circumstances to disclose without consent. Apply consistent redaction and maintain a record of what was redacted and why.

7

Compile and Send the Response

Prepare the response package including: confirmation that you process the individual personal data, a copy of the personal data in an intelligible format, the supplementary information required by Article 15 (purposes, categories, recipients, retention periods, rights, source of data, automated decision-making). Send the response securely, using encrypted email or a secure portal where possible.

8

Close and Record the DSAR

Log the response date, method of delivery, and a summary of what was disclosed and what was exempted or redacted. Retain a copy of the response and your decision log for at least two years in case of ICO complaint or investigation. Update your DSAR metrics for management reporting.

Track DSAR volumes, response times, and exemption usage in quarterly MI reports — this data helps identify trends and resource requirements for future planning.

Best Practices

Centralise DSAR Management

Route all DSARs through a single point of management, whether that is your DPO, a dedicated privacy team, or a compliance function. Decentralised handling leads to inconsistent responses, missed deadlines, and incomplete searches.

Automate Deadline Tracking

Use automated calendar alerts to track the one-month deadline for every DSAR, with escalation triggers at 14 days and 7 days remaining. Factor in the possibility of a one-month extension for complex requests, but only use this where genuinely justified.

Build Relationships with Third-Party Processors

Agree DSAR cooperation procedures with your key processors in advance, not when a request arrives. Include DSAR response timelines in your data processing agreements, requiring processors to return data within a specified number of working days.

Document Your Exemption Decisions

When withholding data under an exemption, record the specific exemption relied upon, the data withheld, and your reasoning. The ICO may require you to justify your exemption decisions, and contemporaneous records are far more persuasive than retrospective explanations.

Provide Data in Accessible Formats

Respond in a commonly used electronic format such as PDF, and structure the data logically by source system or data type. Avoid sending raw database exports that the individual cannot interpret. The ICO expects responses to be intelligible to a lay person.

Learn from Recurring Requests

If you receive repeat DSARs from the same individuals or about the same types of data, investigate whether there is an underlying transparency issue that could be resolved by improving your privacy notices or data access self-service options.

Implementation Checklist

DSAR recognition training delivered to all customer-facing staff

All staff who interact with customers can identify and escalate a DSAR appropriately.

Central DSAR register and workflow established

Single point of management for all DSARs with automated logging and deadline tracking.

Complete data source search checklist documented

Pre-prepared list of every system and data repository to search for each DSAR.

Identity verification procedures proportionate and documented

Clear process for verifying requester identity without using verification as a delay mechanism.

Exemption assessment guidance available to DSAR handlers

Documented guidance on insurance-relevant exemptions with practical examples.

Third-party processor DSAR cooperation agreements in place

Data processing agreements include specific timelines for processors to return DSAR data.

Response templates prepared for standard DSAR scenarios

Pre-drafted templates covering common insurance DSAR types, customisable for each case.

DSAR metrics reported to management quarterly

Free tools for data protection

Try these related tools — no sign-up required.

GDPR Data Retention Calculator

Check retention periods and deletion dates for 30+ data types.

FCA Compliance Checker

Assess your data protection obligations under FCA rules.

Frequently Asked Questions

Related Guides

data protection

UK GDPR Data Handling Obligations for Insurance Firms

A comprehensive guide to meeting your data handling responsibilities under the UK GDPR, tailored specifically for insurers, brokers, and MGAs.

data protection

Data Retention Policy for Insurance Firms

What to keep, when to delete, and how to balance UK GDPR storage limitation with FCA record-keeping and long-tail claims obligations.

fca compliance

FCA Record-Keeping Requirements: What Insurance Firms Must Retain and For How Long

A definitive guide to meeting FCA record-keeping obligations under SYSC 9, COBS, ICOBS, and DISP — with practical retention schedules and storage recommendations.

Further Reading

Platform SecurityCompliance FeaturesFCA Compliance CheckerInsurance Solutions

Streamline DSAR Processing for Your Insurance Firm

SwiftCase automates DSAR workflows with centralised logging, deadline tracking, multi-system search coordination, and audit-ready response records — helping you hit the 30-day deadline every time.

Book a Discovery CallSee Security Features