From https://ico.org.uk/for-organisations/guide-to-the-general-da... :
> The GDPR does not specify how to make a valid request. Therefore, an individual can make a subject access request to you verbally or in writing. It can also be made to any part of your organisation (including by social media) and does not have to be to a specific person or contact point.
> A request does not have to include the phrase 'subject access request' or Article 15 of the GDPR, as long as it is clear that the individual is asking for their own personal data.
> This presents a challenge as any of your employees could receive a valid request. However, you have a legal responsibility to identify that an individual has made a request to you and handle it accordingly.
In a normal world, I think only officers or registered agents can be addressed legal requests, how here any government though it was a good idea that "any of your employees could receive a valid request" and that it's a legal responsibility to handle it correctly. This is just mind blowing to me.