A subject access request can expose weaknesses in customer information management very quickly. A small business may think the relevant data is ‘in the CRM’, then discover that personal information also appears in activity notes, attachments, linked inboxes, support records and connected systems. The CRM can help organise the response, but it should not be mistaken for the complete legal process or the complete data estate.
Recognise a request even when it is informal
The Information Commissioner's Office explains that people can make subject access requests verbally or in writing, including through social media. A customer does not have to use a particular form or technical phrase for the request to count.
Frontline staff therefore need a simple route for escalating requests to whoever is responsible for handling them. The CRM can record receipt and ownership, but staff should not delay recognition merely because the customer did not submit a preferred template.
Record the request without spreading it unnecessarily
Create a controlled record of when the request arrived, who is handling it and what information appears to be requested. Avoid copying sensitive details into broad notes or tasks visible to people who do not need them.
The ICO's current guidance says organisations must respond without undue delay and within one month in most circumstances, with possible extension in certain complex situations. Businesses should check the current ICO subject access guidance for the rules that apply to the particular request.
Use CRM search as one part of a wider search plan
Search the CRM using the identifiers reasonably associated with the person, taking account of previous names, contact details, account references or duplicate records where relevant. Document the approach so the business can explain how information was located.
Do not stop at the CRM if personal information is also processed elsewhere. The ICO describes the requirement as a reasonable and proportionate search for the requested information. Connected email, service or operational systems may therefore need consideration depending on the scope of the request.
Separate the requester's information from other people's information
Customer records can contain notes about employees, family members, contacts at another organisation or other third parties. Exporting an entire CRM record without review can disclose information the requester is not simply entitled to receive as their own.
This is an area where exemptions, third-party information and other legal considerations can become fact-specific. The person handling the request should use current ICO guidance and seek appropriate specialist advice where the position is uncertain rather than relying on an automated CRM export as a legal decision.
Review notes and attachments carefully
Free-text notes deserve particular attention because staff may have recorded personal information in inconsistent ways. Attachments can also contain much more than their filename suggests.
Good CRM discipline before any request makes this work easier. Staff should record factual, necessary customer information in appropriate places and avoid casual commentary that has no legitimate operational purpose. A subject access process should not depend on guessing what colleagues may have written.
Prepare information for secure delivery
The response process needs to establish that information belongs to the correct requester and provide it through an appropriate secure method. The ICO advises organisations to take reasonable steps to ensure information is supplied securely.
The CRM may provide export tools, but file creation is only one step. Review what the export contains, whether information from other people requires treatment, whether supplementary information must also be supplied and how the final material will reach the requester.
Keep an audit trail of the handling process
Record key actions such as receipt, clarification where appropriate, searches performed, review decisions and completion. The record should be useful for governance without duplicating the requested personal information unnecessarily across more systems.
If the organisation relies on an exemption, restriction, extension or refusal ground, that decision should not be improvised by a CRM user. Current guidance and appropriate responsibility are essential because the legal position depends on the circumstances.
Use each request to improve information governance
A difficult search often reveals a wider data-management issue: duplicate customer records, unclear retention, uncontrolled notes or integrations nobody has mapped. Fixing those weaknesses can make future customer service and rights handling more dependable.
The CRM is valuable because it can support ownership, search and evidence. It does not decide what the law requires. Small businesses should use it as part of a documented rights-handling process grounded in current ICO guidance and their actual information flows.