A subject access request is a short email from someone who does not explain themselves and does not have to. What happens next is mostly clerical — unless one particular field was never recorded, in which case there is no amount of effort that produces the answer.
The clock and the price
| Obligation | The rule |
|---|---|
| Deadline | One month from receipt |
| Extension | Two further months where complex or numerous — but you must say so, with reasons, inside the first month |
| Cost to the requester | The first copy is free |
| Refusing or charging | Only where manifestly unfounded or excessive, and you must be able to show it |
None of that is onerous for a company that knows what it holds. The difficulty is never the deadline. It is one line in the list of things you have to disclose.
The line that does the damage
Where the data was not collected from the person, Article 15(1)(g) entitles them to any available information as to its source.
For a list bought from an aggregator, the honest answer is often that you do not know. The vendor supplied a row. The vendor may itself have bought it. “Public sources” is not a source; it is a category, and a person asking where you got their mobile number is not asking for a category.
Everything else in a subject access request can be assembled after the fact. The source cannot, because it was never written down.
Why “too expensive” is not the escape it looks like
There is an exemption for cases where informing people would involve disproportionate effort, and it is the clause every list-based business reaches for. Poland’s supervisory authority tested it in its first GDPR fine, and the reasoning is worth reading carefully.
A data company had assembled roughly 7.5 million records on individuals from public registers. It emailed the people whose addresses it had. For the rest it decided that direct contact was too costly, and published a privacy notice on its own website instead.
The authority fined it around €220,000. Two findings matter more than the number:
- A notice on your own website is too passive. Someone who does not know you hold their data has no reason to visit your site to find out.
- The cost of informing people is part of the cost of acquiring the data. Deciding not to pay it is a commercial choice, not an impossibility — and the exemption is written for impossibility.
The decision was later narrowed on appeal as to which individuals were covered, but the principle survived: choosing not to spend the money is not the same as being unable to.
What a cheap request looks like
A request is inexpensive when the answer already exists. Searching systems, assembling a copy, redacting other people — all mechanical, all solvable with an afternoon. The expensive version is the one where you have to go and ask a vendor where a row came from, and wait, and receive “public sources”, and then write that to a person who will not find it satisfying.
The two obligations that arrive together — access under Article 15 and objection to direct marketing under Article 21 — are also the two that a team running legitimate-interest outreach is most likely to see. Suppression has to be global for the same reason it has to be global for deliverability: one list, honoured everywhere.
Why we built it the other way round
Our evidence standard says every company is researched from public sources at the moment of the request, and every claim carries the page it came from and the date it was read. That reads like a quality argument. It is also, and less romantically, the reason a subject access request is a lookup rather than a project.
It is the same reason there is no contact database to sell and nothing gets resold: a stored row whose origin you cannot state is a row you cannot defend. We would rather return fewer companies — and fewer confident-looking flags — than hold data we would struggle to explain.