Blog Details
The latest news, updates and insights from our technology specialist lawyers at Law 365.
A Client Has Received a SAR: What Managed Service Providers (MSPs) Are Legally Required to Do
Contents
Sooner or later every Managed Service Provider (MSP) gets the call. A client has received a Subject Access Request (SAR), the clock is ticking, and they want you to "pull everything" from the IT systems you manage for them.
The good news is that the legal duty to respond to the data subject rests entirely with your client, not with you. The less good news is that you still hold statutory obligations as a data processor. Getting them wrong can put your client in breach of UK GDPR and expose your MSP to regulatory and contractual liability.
What is a Subject Access Request (SAR)?
A Subject Access Request is an individual’s right under Article 15 of the UK GDPR to see the personal data an organisation holds about them. Individuals are entitled to a copy of that data, plus the reasons it is processed, who it has been shared with, how long it will be kept and where it came from.
A SAR can be made verbally or in writing, to anyone in the organisation, and it does not need to mention the GDPR or use the words "subject access". The organisation normally has one month to respond, extendable by up to two further months if the request is complex. Searches are generally free of charge. Under the Data (Use and Access) Act, the required search must be "reasonable and proportionate" but determining proportionality is the controller’s legal judgement, not the MSP’s.
Controller vs Processor: Whose problem is it?
In almost every MSP relationship, your client is the data controller and you are the data processor. They decide why the data exists and what it is used for; you host it, back it up, patch the servers and keep the lights on. The UK GDPR places the duty to answer a SAR squarely on the controller.
That is why the individual’s one-month deadline is your client’s deadline, and why the Information Commissioner's Office (ICO) would look to your client first if it is missed. But processors are not spectators. Article 28 gives you a specific set of duties, and they are written into every compliant Data Processing Agreement (DPA) you have signed.
What an MSP Must Do When a Client Receives an SAR
Under Article 28, an MSP’s legal duties as a data processor centre on five core obligations:
- Assist the Controller - Article 28(3)(e) requires you to help the controller respond to data subject requests "by appropriate technical and organisational measures, insofar as this is possible". In practice that means locating and extracting the relevant personal data from the systems you run for the client (mailboxes, file shares, backups, ticketing systems, logs) and handing it over in a usable form, quickly enough for them to meet their deadline.
- Act solely on documented instructions - Under Articles 28(3)(a) and 29 you process personal data only as your client documents. Retrieving data for a SAR is fine because they have asked you to. Deciding what to disclose is not your call.
- Pass requests on immediately - If the individual sends the request to you rather than to your client, notify the client without delay and let them handle it. Do not sit on it, and do not reply to the individual yourself.
- Maintain strict data security - Extracting and transferring someone’s personal data is itself processing. Use secure channels, limit who sees it, and make sure any sub-processors you involve are ones the client has already approved.
- Enforce cost-recovery terms - SAR retrieval demands billable engineering hours. Ensure your client master services agreement (MSA) and DPA explicitly outline that technical assistance for compliance requests is chargeable outside standard retainer support.
Common MSP Mistakes: What you must NOT do
Most SAR compliance mistakes made by service providers stem from good intentions:
- Responding directly to the individual: An engineer attempts to help by emailing an archive file directly to the requester. This constitutes an unauthorised data disclosure.
- Filtering or redacting content: An account manager decides certain internal emails are irrelevant or confidential and omits them. Deciding whether statutory exemptions apply (such as legal privilege, third-party personal data, or commercial confidentiality) is strictly the controller’s duty.
- Withholding data over billing disputes: Refusing to release extracted SAR data because of an overdue invoice risks putting your client in breach of statutory ICO deadlines, violating your Article 28 duties and exposing both parties to regulatory scrutiny.
One more point: if you hold personal data for your own purposes (your own service desk records about the client’s staff, for example), you are the controller of that data, and a SAR for it lands on you directly.
How MSPs Can Prepare Ahead of Time
MSPs that handle SARs efficiently address potential bottlenecks in their standard contracts before an incident arises.
- Contractual Service Levels (SLAs): Ensure your DPA defines realistic turnaround targets (such as acknowledging a request within 48 hours and delivering retrieved data within 5 to 10 working days).
- Required Client Inputs: Stipulate that retrieval work begins only after the client supplies necessary parameters, including the data subject's identifiers, targeted systems, and agreed date ranges.
- Documented Search Playbooks: Maintain standard operating procedures for data extraction across core platforms (such as Microsoft Purview eDiscovery, backup restores, and PSA/RMM exports).
- Dedicated Inboxes & Logging: Assign a designated point of contact so incoming notices are never buried in a general support queue, and maintain an audit log of all retrieved data for your Article 30 records.
Summary
When a client receives a SAR, an MSP’s role is clear: locate the requested data rapidly, transfer it securely, and leave the disclosure decisions to the controller. Embedding this process into your contracts and ticketing workflows turns a high-risk fire drill into a standard technical request.
This article is general information about the UK position, not legal advice. Your contract terms and your actual role in the processing will determine what applies in a given case.
Recruitment insights
They say you can’t have a world-class business without world-class employees, and the competition in the marketplace...
How can Microsoft Partners use CPoR and DPoR to make money from rebates?
Microsoft pays out millions of dollars per annum in rebates to Microsoft Partners. How much are you getting? If you...
7 key considerations for subject access requests
Subject Access Requests (“SARs”), also referred to as data access requests or data subject access requests, grant...