Does it Matter if you Breach Timescales for SARs?

Subject Access Requests, or SARs, are the most commonly used GDOR right that people have. They can place a material burden on organisations and therefore it is not uncommon for deadlines or information to be missed. However, even missing the deadline is itself a breach of GDPR, regardless of whether data is eventually provided.

 

Subject access request timeline

 

The Background to Subject Access Requests

People have been able to make subject access requests since the data protection Act 1998. The GDPR incorporated an expanded this right, renaming it the Right of Access.

Under the GDPR when someone exercises this right they are entitled to:

  • Confirmation their data are being processed
  • Background information including the legal basis for that data processing
  • A copy of the information they have requested

Organisations generally must provide this information within one calendar month of the request, free of charge. Exceptionally you may extend by up to two further months for complex or numerous requests, but must inform the requester within the first month.

Sometimes, such as verifying a requestor’s identity, you can pause the clock. This must be justified and proportionate—you cannot routinely delay requests by asking for unnecessary identification. Rarely, you can refuse to comply with a request but the bar for this is quite high e.g. the request is “manifestly unfounded or excessive”

Why Do People Makes SARs?

In our experience people rarely make requests out of idle curiosity. People tend to ask for information about themselves if they have a complaint, grievance or suspicion of wrongdoing.

Examples include:

  • Dismissed employees seeking information to make a claim for unfair dismissal
  • Customers who feel their data has been misused in some way
  • Citizens checking what public bodies hold about them due to a lack of trust or an ongoing dispute

It is important to note that people do not need to give a reason for their request.

How Organisations Get SARs Wrong

There are a number of ways organisations get SARs wrong. Some of these are more technical, others more material.

For example organisations often fail to provide the supplementary information outlined above. While people might generally just want the information not the background, Article 15 of the GDPR requires supplementary information. A failure to provide it is a breach, even if the requester doesn’t explicitly complain.

Sometimes organisations fail to provide everything they hold about the requestor, perhaps because they have not done a thorough enough search or considered all of the identifiers a person may be known or classified by (date of birth, order number, employee number, initials etc.)

Most seriously organisations will deliberately fail to disclose information, even going so far as to delete data rather than share it. Deliberately concealing or destroying data to avoid disclosure can expose organisations to serious regulatory action and, in some circumstances, criminal liability under the Data Protection Act 2018.

The most common way organisations get this wrong is to take longer than allowed to respond.

Why Do Organisations Miss Deadlines?

There are three main reasons organisations miss statutory deadlines:

  • They do not have the resources to manage requests. A lot of organisations, especially public bodies like NHS bodies, police forces or local authorities, get hundreds of requests a year
  • They have too much information. Some organisations hold huge volumes of data about people. This is especially true about public sector bodies, but employers are often surprised about how much they hold about current or past workers.
  • It takes a long time to review, redact and collate information for disclosure.

External Consequences: What Could Happen if We Do Not Comply?

Like all risks there are three main ways a failure to comply with people’s GDPR rights might impact you:

  • Reputational: your organisation’s reputation can suffer if you do not comply with SARs, especially if you are subject to regulatory action.
  • Financial: people can complain to the Information Commissioner or even take civil action if you do not comply with SARs. The Information Commissioner cannot offer compensation but he can issue financial penalties for breaching the GDPR. Civil action has its own costs whether it succeeds or fails.
  • Operational: people, quite rightly, don’t just sit quietly if you do not respond in good time. Delays or gaps in responses cause complaints and ongoing communication that take time and resources to deal with. Enforcement action could lead to directions to change your systems and processes, which will also have an operational impact.

Internal Consequences: Why Does it Matter?

A failure to comply with SARs or respond in good time means you are denying people a legal right. Legally and ethically that is serious. However, the real world consequences as outlined above can be significant.

One issue that not responding properly to requests might be a symptom of is a lack of control over your personal data and the flows of personal data in your organisation. This also is potentially serious as you might find it difficult to show:

  • You have a proper lawful basis for processing people’s personal data
  • You might be in breach of privacy principles around data retention or security
  • Core rights like the right to be informed may also not be being complied with

Therefore there are wider reputational, operational and financial risks you might be exposed to without knowing. Key things to explore if there are systematic or long standing failures to comply with SARs include:

  • Whether your data mapping is adequate and complete
  • Your data retention and deletion policies and practices
  • system integration
  • whether data protection and information governance has sufficient oversight

Periodic Table of the GDPR

How Can You Get SARs Right?

The main ways you can employ to ensure you can comply with subject access requests include:

  • Ensure that you recognise when people are exercising this right. They do not need to quote the GDPR or even put their request in writing. You can avoid delays by acting speedily as soon as a request is received
  • Minimise the data you hold. The GDPR requires organisations to hold the minimum necessary data about individuals. You will be more operationally efficient and save costs if you delete data you don’t need. It will also make it easier to find and share data about people if a request is made
  • Have appropriate compliance systems. You can use free resources like our SAR request checklist and response template to help track process and ensure you respond fully and in a timely manner.
  • If things go wrong ensure you understand why, and implement reasonable steps to avoid a recurrent.

Key elements to put in place to fulfil your statutory duties when people make subject access requests include:

  • SAR workflow tracking
  • central request logging
  • search protocols
  • redaction standards
  • templates like those you can find on our GDPR resource page.