Company Brochure

Subject Access Requests on the Isle of Man: How to Respond

A compliance officer reviewing personal data records at an Isle of Man office desk

Strengthen your compliance strategy

— with confidence. clarity. experts.

Book a
consultation

When someone asks to see the personal data your firm holds on them, that is a subject access request — and on the Isle of Man you must respond without undue delay and in any event within one calendar month. You generally cannot charge a fee, you cannot insist they use your form, and what you owe them is their personal data, not copies of your documents. The right sits in Article 15 of the Applied GDPR, and it is enforced locally by the Isle of Man Information Commissioner.

One point of terminology first: throughout this article, "SAR" means a subject access request — an individual (a data subject) asking for their own personal data — not a Suspicious Activity Report under the AML regime. To avoid that collision, we use "subject access request" or "DSAR" in what follows. This is a data-protection duty, not a financial-crime one, and it is governed by the Island's own Applied GDPR, not the UK ICO's rules or EU law.

What is a subject access request, and what must you actually hand over?

A subject access request is a person exercising their Article 15 right to obtain a copy of the personal data you are processing about them. Article 15(3) of the Applied GDPR requires the controller to provide a copy of that personal data; where the request is made electronically, you must provide it in a commonly used electronic form unless the requester asks otherwise. That is the core deliverable — but its scope is narrower than most firms assume.

Here is the point the Isle of Man Information Commissioner's guidance on complying with a subject access request states plainly: "This right does not entitle you to copies of documents – the right is only to the information that is about you (i.e. your personal data)." You are not obliged to photocopy every file, email thread and attachment that happens to mention the person. You can meet the request by extracting the relevant personal data into a new document. This "data, not documents" framing is one of the most practically useful things to understand, because it stops a request ballooning into a document-disclosure exercise it was never meant to be.

Alongside the data itself, you must give the requester a set of supplementary information: the purposes of the processing; the categories of personal data involved; the recipients or classes of recipient the data has been or will be disclosed to (including any in third countries); the retention period, or the criteria used to set it; the source of the data where you did not collect it from the individual; the safeguards applied to any third-country transfers under Article 46; the existence of their rights to rectification, erasure, restriction and objection; the right to complain to the Commissioner; and, where you use automated decision-making or profiling, meaningful information about the logic involved. The Commissioner is explicit that there is no exemption from providing these details.

We help Isle of Man firms build a repeatable subject-access process so the first request does not become a scramble.

A compliance officer extracting an individual's personal data into a new document at an Isle of Man office

How long do you have, and can you charge?

You have one calendar month from receipt of the request, and you should respond sooner where you can — the standard is "without undue delay". A calendar month matters: a request received on the 3rd is due by the 3rd of the following month, not thirty days later. If you hold no personal data on the requester at all, you must still tell them so within that calendar month (Article 12(4)) — silence is not an answer.

The month can be extended by up to two further calendar months, but only where the request is genuinely complex or where you are dealing with numerous requests (Article 12(3)). This is a narrow door, and the Commissioner closes part of it directly: "The volume of data does not make a request 'complex'." A large quantity of data to gather is not, by itself, complexity. And if you do extend, you must tell the requester about the extension and explain why within the first calendar month — you cannot reach day thirty, realise you are not ready, and quietly claim more time.

On fees, the default is simple: you cannot generally charge for responding to a subject access request. There are only two exceptions. You may charge a reasonable fee, based on administrative cost, for further copies of the same data the requester has already received. And where a request is manifestly unfounded or excessive — the Commissioner singles out a repeat request for the same information — you may either charge a reasonable fee or refuse to act on it (Article 12(5)). That is the honest answer to the natural question of whether you can turn away the persistent requester who asks for the same file every fortnight: yes, but only on the "manifestly unfounded or excessive" ground, and you should be able to justify that characterisation. General inconvenience does not clear the bar.

Can you ask for ID, and what about a refusal?

Identity verification is where Isle of Man practice is notably restrained, and where firms most often over-reach by importing habits from elsewhere. The Commissioner's position is that identification is not automatically necessary — particularly where the data subject is already known to you. You may seek further identifying information only where you have reasonable doubts about who the requester is, and then only the minimum necessary to resolve that doubt.

Routinely demanding photographic ID or a utility bill from everyone who asks "would be beyond the 'minimum necessary'", in the Commissioner's words — and if you insist on it, you may later have to justify to the Commissioner why that extra information was necessary in the particular case. So the workable rule is: if you already know the person, act on the request; if you have a real, articulable doubt, ask for the least that will settle it.

There are two proper grounds to refuse a request outright: where you genuinely cannot identify the requester, and where the request is manifestly unfounded or excessive. Neither is a general "this is inconvenient" escape hatch. Note too that a request can be made verbally or in writing, there is no obligatory form, and you cannot make your response conditional on the requester using your firm's own template. A parent, guardian or legal representative may make a request on someone's behalf, and where you have designated a Data Protection Officer under Article 37, individuals are entitled to contact that DPO directly (Article 38(4)).

If your firm has outsourced the DPO role, the person fielding these requests may sit outside the business — we set out how that works in our guide to the outsourced DPO on the Isle of Man.

We can review how your firm verifies identity and logs its decisions so an ID demand never looks like a delaying tactic.

An adviser reviewing identity-verification and redaction decisions against Isle of Man Applied GDPR guidance

Third-party data and the Island's exemptions

A single record about the requester often names other people. Where disclosing the personal data would identify another individual, you may withhold that other person's information — unless they consent, or it is reasonable to disclose without their consent, which means balancing the two individuals' rights. But withholding is not all-or-nothing: you must still disclose as much as possible by redacting the third party's identifying details. Redaction, not refusal, is the default response to a third-party complication.

The exemptions that let you restrict access are specific to the Isle of Man, and this is another place where reaching for UK or EU material will mislead you. The Commissioner is unambiguous: "The only restrictions on the right of access are those set out… in Schedule 9 to the GDPR and LED Implementing Regulations 2018." There are no blanket exemptions. Each item of personal data must be considered separately against Schedule 9, and where you do apply a restriction you must document the reasons. This is the same accountability discipline that runs through the whole regime — the ability to show your working, not merely to assert a conclusion. If a particular disclosure raises a high risk to the individuals involved, that is also the kind of processing that would prompt a data protection impact assessment in the first place.

Common mistakes we see

The most frequent error is treating a subject access request as a document-disclosure exercise — assembling every file that mentions the person and either drowning in the volume or handing over far more than the right requires. The right is to the individual's personal data; extracting it into a new document is a legitimate and often cleaner way to comply.

The second is over-verifying identity. Firms reflexively ask for photographic ID and proof of address from requesters they already know perfectly well. That is not neutral caution — on the Island it goes beyond the "minimum necessary", and it can look like an obstacle the Commissioner will expect you to justify.

The third is misreading the clock. The deadline is one calendar month, not thirty days, and the extension is not a routine buffer — "complex" does not mean "large", and if you extend you must have told the requester, with reasons, inside the first month. We also see firms forget the supplementary information entirely, treating the copy of the data as the whole job when the purposes, recipients, retention and rights information are equally owed. And some firms try to funnel every request through their own form or a fee — neither of which they are entitled to impose as a condition of responding.

We help firms turn these failure points into a documented, defensible workflow before a request arrives.

Personal data held securely and logged in an organised Isle of Man filing system

Frequently asked questions

How long do we have to respond to a subject access request on the Isle of Man?

One calendar month from receipt, and sooner where you reasonably can. You may extend by up to two further calendar months only where the request is genuinely complex or you face numerous requests under Article 12(3) — but you must tell the requester about the extension and explain it within the first month. The Isle of Man Information Commissioner is clear that a large volume of data does not, by itself, make a request complex.

Can we charge a fee or refuse a repeat request?

Generally no fee applies. You may charge a reasonable, cost-based fee only for further copies of data the requester already has. Where a request is manifestly unfounded or excessive — the Commissioner gives the example of a repeat request for the same information — you may charge a reasonable fee or refuse to act under Article 12(5). Ordinary inconvenience is not enough; you should be able to justify the "manifestly unfounded or excessive" label.

Do we have to provide copies of documents?

No. Under the Isle of Man Information Commissioner's guidance, the right is only to the personal data that is about the individual, not to copies of your documents. You can comply by extracting the relevant personal data into a new document, along with the required supplementary information about purposes, recipients, retention, sources and the individual's rights.

Can we ask the requester to prove their identity?

Only where you have reasonable doubts about who they are, and then only the minimum necessary to resolve that doubt. Identification is not automatically required, especially where the person is already known to you. Routinely demanding photographic ID or utility bills would go beyond the minimum necessary, and you may have to justify to the Commissioner why the extra information was needed.

The bottom line

A subject access request is not an audit of your filing cabinet — it is a person's right to see what you know about them, answered inside a calendar month, usually for free, and backed on the Island by penalties of up to £1,000,000 for getting it wrong. Handle it as their right, evidenced and on time, and it stops being a threat and becomes simply part of running a firm that respects the data it holds. For the wider framework these requests sit within, see our guide to GDPR compliance for Isle of Man firms.

Knight Consultancy Limited
(Company No: 136669C)
Design House, Hills Meadow, Douglas,
Isle of Man ,IM1 5EB

© Knight Consultancy Limited {{Y}}. All Rights Reserved. Privacy Policy

Website and marketing partner: Yellowstone Accounts

Knight