Create a bespoke document in minutes,聽or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership聽of your information
Subject Access Request
"I need a subject access request template to request all personal data held by the company within the last 2 years, including processing purposes and third-party disclosures, to be fulfilled within 30 days."
What is a Subject Access Request?
A Subject Access Request is your legal right to see what personal information organizations have about you. Under Philippine data privacy laws, you can ask any company, government agency, or organization to show you all the data they've collected and stored about you - from basic details like your name and address to more complex records like CCTV footage or employee evaluations.
Once you submit this request, the organization must respond within 21 days, as required by the Data Privacy Act of 2012. They should provide copies of your data, explain how they use it, and tell you who else might have access to it. It's a powerful tool that helps you protect your privacy rights and ensure organizations handle your information properly.
When should you use a Subject Access Request?
Submit a Subject Access Request when you need to understand exactly what personal information an organization holds about you in the Philippines. Common situations include applying for jobs and wanting to see your previous employment records, checking what financial institutions know about your credit history, or verifying medical records held by healthcare providers.
This tool becomes especially valuable if you suspect outdated or incorrect information is affecting your opportunities, or if you're preparing for legal proceedings and need documentation. Many Filipinos also use these requests to check how government agencies are using their data, particularly when applying for licenses, permits, or benefits.
What are the different types of Subject Access Request?
- Written Requests: The standard format sent via email or letter, detailing specific personal data you want to review from an organization's records
- Verbal Requests: Made in person or by phone, though organizations may ask you to follow up in writing for verification
- Online Portal Submissions: Many Philippine companies now offer dedicated web forms for filing Subject Access Requests
- Representative Requests: Filed by authorized persons on behalf of minors, elderly relatives, or those with special needs
- Emergency Requests: Expedited versions for urgent situations like medical emergencies or legal proceedings
Who should typically use a Subject Access Request?
- Data Subjects: Any Filipino citizen or resident who wants to know what personal information organizations hold about them
- Data Protection Officers: Company representatives legally required to handle Subject Access Requests and ensure compliance with privacy laws
- Legal Departments: Review and process requests, ensuring organizations meet their obligations under the Data Privacy Act
- HR Professionals: Often handle employee-related Subject Access Requests and maintain personnel records
- Privacy Commission Officials: Oversee compliance and handle complaints about mishandled requests
How do you write a Subject Access Request?
- Personal Details: Gather your full name, contact information, and any reference numbers related to your relationship with the organization
- Identity Verification: Prepare a valid government ID or two other forms of identification accepted in the Philippines
- Data Specifics: List exactly what information you're seeking and the time period it covers
- Organization Details: Note the correct legal name and contact information of the entity holding your data
- Request Format: Our platform generates properly structured Subject Access Requests that meet Philippine legal requirements, ensuring clarity and compliance
What should be included in a Subject Access Request?
- Personal Information: Clear statement of your full legal name, current address, and contact details as required by the Data Privacy Act
- Request Scope: Precise description of the personal data you're requesting access to, including relevant time periods
- Identity Verification: Declaration confirming your identity, with reference to attached proof documents
- Legal Authority: Citation of your rights under Republic Act 10173 (Data Privacy Act)
- Response Timeline: Statement requesting response within the mandatory 21-day period
- Format Preference: Specification of how you want to receive the information (digital or physical copies)
What's the difference between a Subject Access Request and an Access Control Policy?
A Subject Access Request fundamentally differs from an Access Control Policy in both purpose and scope. While both deal with information access, they serve distinct functions in Philippine data privacy compliance.
- Purpose and Direction: Subject Access Requests are individual-initiated tools to view personal data, while Access Control Policies are organization-created frameworks defining who can access what information
- Legal Authority: Subject Access Requests are backed by the Data Privacy Act giving individuals direct rights to their data, whereas Access Control Policies are internal governance documents
- Time Frame: Subject Access Requests require responses within 21 days, but Access Control Policies remain active indefinitely until revised
- Content Focus: Subject Access Requests target specific personal information about one individual, while Access Control Policies cover broad categories of data and multiple user types
Download our whitepaper on the future of AI in Legal
骋别苍颈别鈥檚 Security Promise
Genie is the safest place to draft. Here鈥檚 how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; 骋别苍颈别鈥檚 AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a 拢1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our for more details and real-time security updates.
Read our Privacy Policy.