YOUR INFORMATION. YOUR ACCESS.
Data Subject Access Request Policy
How to request your personal data, what we will provide and how we protect your rights under UK and EU data protection law.
Effective and last reviewed: 11 September 2026
1. Controller and DPO
CyprusMove Limited is the Data Controller for CyprusMoveProperty.ai. Registered in England and Wales, company number 16541237.
Registered office:3rd Floor, 45 Albemarle Street
London W1S 4JL, United Kingdom
Controller email: info@cyprusmove.com
Telephone: +357 95 152 441
Data Protection Officer: Data Privacy Services
info@dataprivacyservices.co.uk
This policy addresses Articles 12 and 15 of the UK GDPR, the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, and the EU GDPR and applicable Cyprus legislation where relevant. The UK amendments do not amend the EU GDPR. We assess the rules applicable to your data and request; where both apply, we meet both sets of obligations.
2. Your right of access
A Data Subject Access Request (DSAR or SAR) lets you ask whether we process your personal data and obtain access to it. You can request all of your personal data or identify particular records. You do not need to explain why you want access.
Subject to applicable lawful restrictions, we provide a copy of your personal data and information about:
- The purposes of processing and categories of data concerned.
- The recipients to whom data has been or will be disclosed, or recipient categories where legally appropriate. Under EU law, actual recipients are identified where required.
- The retention period or the criteria used to determine it.
- The source of information not collected directly from you, where available.
- Your rights to correction, erasure, restriction and objection, and your right to complain.
- Relevant automated decision-making, including profiling, and meaningful information about the logic, significance and envisaged consequences where required.
- Applicable safeguards for transfers outside the relevant UK or EEA jurisdiction.
Access concerns your personal data, rather than an automatic entitlement to every complete business document. We provide sufficient context, including document extracts or copies where necessary, to make the information intelligible and allow you to exercise your rights.
3. Making a request
You can email the DPO or CyprusMove, write to our registered office or telephone using the details above. Requests made through other normal contact channels are also recognised and passed to the appropriate person. You do not have to use the term “DSAR”, cite legislation or direct your request to the DPO for it to be valid.
It helps to provide your name, a contact method, any previous names or email addresses used with us, and relevant property references or dates if known. These details assist our search; you may still ask for all of your personal data. Tell us your preferred response format and any accessibility needs. We will facilitate requests and make reasonable adjustments where needed.
Please do not send passports, passwords or bank details with an initial request. If further verification is necessary, we explain what is needed and an appropriate way to provide it.
4. Identity and representation
We take proportionate steps to ensure that information is supplied to the correct person. Where we have reasonable doubts about identity, we may promptly request additional information necessary to resolve them. We use information already available where sufficient and do not routinely require formal identification.
A representative may act with your authority. We verify that authority before disclosing your data to them. Requests involving a child are assessed with regard to the child’s understanding, interests and the representative’s entitlement to act; parental status alone does not automatically entitle someone to all of a child’s information.
We explain any effect of necessary verification on the response deadline under the applicable law and avoid unnecessary delay. Under the UK rules, the response period begins once reasonably required identity or authority information has been received. We do not use verification to obstruct access.
5. Response times and clarification
We respond without undue delay and normally within one calendar month. Where necessary because of the complexity or number of requests, the applicable law permits an extension of up to two further months. We notify you within the initial month and explain the reasons. Workload alone is not a blanket reason to extend every request.
UK requests: changes under the 2025 Act
Where clarification is reasonably required to respond to a UK subject access request, we may pause the response period while seeking that clarification. We explain what is unclear, why clarification is needed and the effect on the deadline. The pause starts when clarification is requested and the clock resumes after it is received, in accordance with the applicable UK rules. It does not give us a fresh full month.
We cannot force you to narrow your request. If you confirm that you want all of your data, we undertake the required search. A question about response format or routine administration is not, by itself, a reason to pause the clock. We record why any pause is justified and progress work that can reasonably continue.
EU requests
We may ask for useful clarification, particularly where a large amount of information is involved, but do not automatically pause the EU GDPR deadline using the UK Act’s provisions. We apply the EU rules on time limits, any necessary identity checks and permitted extensions separately. Where both regimes apply, a UK pause does not suspend an independently applicable EU deadline.
6. Searching and preparing your response
We identify relevant systems and records, including enquiries, correspondence, service records and data held by processors on our behalf. We coordinate searches with relevant staff and providers and record the approach taken. We do not delete or alter information to prevent its disclosure in response to a request.
The 2025 Act expressly recognises reasonable and proportionate searches for UK access requests. We assess and document what is reasonable in the circumstances, considering where information is likely to be held and its relevance. This is not permission to ignore a request because searching is inconvenient or to leave other readily accessible information unsearched.
For EU requests we apply the EU GDPR and relevant European guidance. We do not treat the UK search provision as a separate EU exemption or impose a blanket cost limit on access. If information cannot be located or is no longer held, we explain this rather than imply that it has been searched and withheld.
7. Fees and lawful restrictions
The first copy and normal handling of a request are free. Where the applicable law allows it, a reasonable administrative fee may be charged for further copies or a manifestly unfounded or excessive request; alternatively, such a request may be refused. We must justify this assessment. A large request or an ongoing dispute does not automatically make a request excessive.
We assess any relevant legal exemption individually. For example, disclosure may be limited to protect another person’s rights or legally privileged material where an applicable exemption permits this. We consider redaction or partial disclosure rather than refusing the whole response unnecessarily.
If we charge a fee, restrict access or refuse to act, we explain the basis, any fee calculation, and your rights to complain and seek a judicial remedy, within the applicable deadline and to the extent the law allows. UK exemptions are not automatically applied to EU processing.
8. Delivery and request records
We provide information clearly, with explanations of relevant codes or abbreviations. For an electronic request, we normally use a commonly used electronic format unless you request otherwise. We agree suitable secure delivery arrangements and consider accessibility needs. Access does not automatically delete or change your records; requests for other rights are considered separately.
We retain a proportionate record of the request, verification, searches, decisions and response to demonstrate compliance and handle any follow-up. Records and verification information are retained only as long as necessary for these purposes and applicable legal requirements. Our Privacy Policy explains our wider processing and retention criteria.
9. Your right to complain
If you believe our response is incomplete, late or otherwise incorrect, contact info@dataprivacyservices.co.uk. Explain the concern and any information you think is missing. We will address it under our Data Handling Complaints Process.
Complaints are acknowledged within 30 days and investigated and answered without undue delay. This complaints timetable does not replace or extend the deadline for your access request.
- UK: you may complain to the Information Commissioner’s Office (ICO), whose website explains its process.
- Cyprus: you may contact the Commissioner for Personal Data Protection.
- EEA: you may complain to the supervisory authority in particular where you habitually reside, work or where the alleged infringement occurred.
You do not need our permission to contact a regulator. Your EU complaint rights are not conditional on completing our internal review, and your rights to a judicial remedy remain unaffected.
Legal guidance
ICO: guide to subject access · European Data Protection Board: right of access guidelines · Data (Use and Access) Act 2025.
Ask for your information.
Our DPO can help you make a request and understand the next steps.
Make a subject access request ↗