Skip to main content
GDPR10 min read

Subject access request doctors: the one-month rule

Under GDPR, Irish doctors must respond to a patient's subject access request within one month, with a possible two-month extension for complex cases.

Ask Brigid Team
5 October 2026 · Updated 5 Oct 2026

Researched and written by Ask Brigid's AI pipeline and published automatically — not individually reviewed by a person. Useful as a starting point; check clinical, legal and regulatory details against a primary source before relying on them.

A stethoscope on a plain white surface

Built in Dublin · EU-hosted · Early access

Ask Brigid takes the admin so the clinic day stays clinical.

The challenge of managing urgent patient records requests

In a busy private urology practice, clinical administration often runs parallel to intensive theatre lists and outpatient clinics. A consultant operating across multiple sites—such as the Beacon Hospital, the Mater Private, or the Hermitage Clinic—frequently moves between different patient record environments. When a formal request for a patient's complete file arrives at your rooms, the administrative burden falls heavily on your medical secretary. Compiling a complete history is rarely a matter of printing a single document. For a urology patient, the file typically spans multi-year PSA tracking sheets, transperineal prostate biopsy pathology reports, flexible cystoscopy summaries, and letters to referring general practitioners. Gathering these records while maintaining strict confidentiality requires a methodical approach. When dealing with a formal request, understanding how GDPR patient communication rules in Ireland apply to your clinical records is essential to avoid administrative delays or compliance failures. Managing a subject access request doctors receive involves balancing patient rights with precise clinical and legal parameters. This article outlines the statutory timelines, the narrow circumstances under which records may be withheld, and how to structure your clinic's data retrieval processes to meet your obligations without disrupting clinical care.

What is the one-month timeline for doctors?

Under European and Irish data protection legislation, the timeline for responding to a patient's request for their clinical files is strict and begins immediately upon receipt of the request. The Data Protection Commission (DPC) states that data controllers must respond to an access request within one month of receiving it. This calendar-month deadline applies regardless of whether your practice is currently managing high clinical volumes, staff leave, or complex multi-site surgery schedules. For a private specialist, the clock does not wait for a convenient administrative day. If a patient submits a data access request medical records search on the 15th of October, your rooms must deliver the complete, redacted file on or before the 15th of November. To manage this timeline effectively, your practice must have a clear system for:
  • Date-stamping: Logging the exact date and time the request was received, whether via email, post, or hand delivery.
  • Identity verification: Confirming the requester is the patient or a legally authorised representative (such as a solicitor with signed consent) before compiling the file. The time taken to verify identity should be handled promptly, as it does not automatically pause the one-month clock unless additional clarification is genuinely required to locate the records.
  • Tracking progress: Monitoring the remaining days to ensure clinical review and redaction occur well before the deadline.

How to extend the response deadline under GDPR

Not every medical file is straightforward. A patient with a complex oncological history or chronic urological conditions may have years of correspondence, multi-disciplinary team (MDT) discussion sheets, and billing records involving various open-market insurers like Vhi Healthcare, Laya Healthcare, Irish Life Health, or Level Health. Where a request is exceptionally complex or voluminous, the law provides a mechanism to extend the response window. The Data Protection Commission (DPC) notes that this one-month timeframe can be extended by up to two further months where necessary, taking into account the complexity and number of the requests, in line with Article 12(3) of the GDPR. To execute this extension lawfully, your practice must follow specific steps:
  1. Assess complexity early: Evaluate the volume of the records within the first ten days of receiving the request. A standard vasectomy file is rarely complex; a multi-year prostate cancer pathway involving radical prostatectomy, radiotherapy, and ongoing active surveillance may qualify.
  2. Notify the patient in writing: You must inform the patient of the extension before the initial one-month deadline expires.
  3. Provide clear reasons: The notification must explain exactly why the extension is necessary (e.g., the need to retrieve archived paper records from off-site storage or coordinate files across multiple surgical facilities). You do not need prior permission from the DPC to apply this extension, but you must be prepared to justify the decision if the patient raises a complaint.
Compiling these files requires careful attention to detail, particularly when transcribing audio files. Ensuring that your clinical dictations are accurate from the outset reduces the time spent correcting records during an access request. For more on this, read our guide on medico-legal consultation dictation in Ireland.

Can a doctor refuse to release medical records?

A common clinical and legal question is: can a doctor refuse to release medical records? The short answer is no, a doctor cannot categorically refuse to release a patient's records simply because the request is inconvenient or because the relationship with the patient has broken down. However, the law provides specific, narrow exceptions designed to protect patient welfare. In Ireland, these exceptions are governed by statutory regulations. Under S.I. No. 121/2022 (Data Protection Act 2018 (Section 60(6)) (Official Control of Sharing of Health Data) Regulations 2022), which revoked the previous 1989 regulations, a data controller may withhold health data from a data subject under strict conditions. Specifically, you may withhold records where you have reasonable grounds for believing that granting access would be likely to cause serious harm to the physical or mental health of the data subject. When applying this exception, the following rules apply:
  • Proportionality: The restriction must apply only as far as, and for as long as, is necessary to prevent the anticipated harm. You cannot withhold the entire clinical history if only a single report carries this risk.
  • The Regulation 9 requirement: If you withhold health data under these grounds, Regulation 9 of S.I. No. 121/2022 stipulates that you must offer the patient the option to have the data released to an alternative health practitioner. This practitioner must have relevant experience and qualifications and be specified by the data subject.
  • Third-party data redaction: You must redact information that identifies third parties (other than healthcare professionals involved in the patient's care) unless those individuals have given explicit consent.

Rules on charging fees for patient access requests

Under older data protection regimes, clinics frequently charged an administrative fee to cover the cost of photocopying and mailing paper charts. Under current GDPR rules, this practice is largely prohibited. According to the Data Protection Commission (DPC), in most cases, individuals cannot be required to pay a fee to make a subject access request. The responsibility for the administrative cost of compiling, copying, and sending the records rests entirely on the practice. There are only two exceptions under Article 12(5) of the GDPR where a fee may be charged:
Scenario Fee Status Legal Condition
Standard Access Request Free of charge Default statutory requirement. Applies to all initial requests for clinical records.
Manifestly Unfounded or Excessive Requests Reasonable administrative fee allowed The clinic must prove the request is unfounded or excessive (e.g., repetitive requests for identical data). Alternatively, the clinic may refuse to act on the request.
Additional Copies Requested Reasonable administrative fee allowed The patient has already received their free copy and requests further physical or digital duplicates of the same records.
If your practice decides to charge a fee under these narrow exemptions, the fee must be based strictly on the administrative cost of the materials and labour required to produce the extra copy. It cannot be used as a penalty or a deterrent.

Streamlining your clinic's record export process

Compiling a complete record manually from paper charts and fragmented digital systems is a significant administrative drain. When a patient requests their files, your secretary often has to log into multiple hospital portals, retrieve local dictations, and locate scanned intake forms. Modern practice management software can simplify this process. Using Brigid, your clinic can maintain an organised electronic record where clinical notes, letters, and payment details are centralized. Rather than searching through disjointed files, your team can export the necessary structured data efficiently, helping you meet the strict one-month timeline. By utilizing the MyBrigid patient companion app, patients can access their clinical letters, booking details, and results directly on their phones. This patient-first approach gives individuals control over their own records and reduces the volume of formal administrative requests directed to your secretary. All clinical data processed through these platforms is hosted securely in AWS Dublin, ensuring alignment with data protection standards in Irish private practice. To ensure your rooms are prepared to handle a subject access request doctors receive, use this practical implementation checklist:
  • Establish a standard intake protocol: Train your medical secretary to identify an access request immediately, whether it arrives via a formal subject access request medical records template from a solicitor or an informal email from the patient.
  • Create a dedicated log: Track receipt dates, verification dates, and target deadlines in a centralized clinic diary.
  • Pre-define redaction workflows: Ensure you have PDF editing tools ready to redact third-party identifiers or sensitive non-clinical information before dispatch.
  • Implement secure delivery methods: Send completed files via secure, encrypted digital transfer or registered post, verifying the recipient's identity before releasing the password or package.

Ask Brigid is onboarding a small number of founding consultant practices. Request early access and we will reply with current availability and the next step.

Frequently asked questions

Ready to give Brigid the admin?

Request early access — founding practices are onboarding now. Or book a 30-minute walkthrough with our team to see Brigid run a workflow with your own data.

EU-hosted · Founding-partner access · Cancel any time