These requests rarely arrive one at a time
When an investment or product runs into difficulty, the advisers who arranged it tend to receive a cluster of requests in a short period. Each client wants the same thing: everything you hold about them.
These are not routine privacy enquiries. They are broad, they are urgent, and the file being asked for is usually years of email rather than a tidy record in one system.
What a client file request actually covers
Broader than most firms expect. It is personal data about the client, not only documents addressed to them.
Email — including internal
Correspondence with the client, and internal email discussing them. Attachments count. So do the threads nobody has opened in six years.
Fact-finds and suitability
Fact-finds, risk profiles, suitability assessments and reasons-why letters — often the documents the request is really aimed at.
Notes and call records
Meeting notes, file notes, call logs and recordings. Informal notes are still personal data.
Provider correspondence
Correspondence with product providers, trustees and platforms that references the client — including where it also references other people.
The clock
You have one month from receipt. Where a request is genuinely complex, or you have received several from the same person, you may extend by up to two further months — but you must tell the client inside the first month and explain why.
In Ireland there is no facility to stop the clock while you seek clarification. The month runs from receipt. Being busy is not a ground for extension.
Responses must be free of charge unless the request is manifestly unfounded or excessive.
The part that catches firms out
You cannot simply forward the mailbox.
An advice file is full of other people's personal data — spouses and family members, colleagues, other clients, named staff at product providers, third parties mentioned in passing in a long email thread. The right to obtain a copy cannot adversely affect the rights and freedoms of others, so that data has to come out before anything is released.
Get it wrong and you have created a second data protection problem on top of the one you were already dealing with. This is the step that turns a request into days of work — and it is why manually redacting several hundred emails is rarely realistic inside a one-month deadline.
If the matter goes further
Where a request arises from a dispute, it is usually not the end of the matter. If it reaches the Financial Services and Pensions Ombudsman, or the courts, how you handled the request becomes part of the record — what you disclosed, what you withheld, on what basis, and when.
Being able to demonstrate that afterwards matters as much as meeting the deadline.
How SAR Portal helps
Take the file as it exists
Import .msg and .eml email with attachments and convert to PDF. No re-keying, no exporting mailboxes by hand.
Find third-party data
Detection across documents, email, spreadsheets, scans and images — including OCR of scanned correspondence and signed forms.
Redact properly
Content is removed from the file, not visually covered over. You review every proposed redaction before anything is released.
Track the deadline
One-month clock from receipt, with the extension rules built in, across every open request at once.
Handle them as a batch
Built for clusters, not one-offs. Process many documents across many requests without losing track of which client got what.
Keep a defensible record
A full audit trail of every action and every redaction, plus a secure packaged download for the client with per-file integrity hashes.
See it with a real request shape
Twenty minutes, walked through with an advice file rather than a canned demo. Built in Ireland, hosted in the EU.
General information on data protection obligations, not legal advice. Consider your own circumstances and take advice where needed.