Under the GDPR every organisation must know how to respond to a subject access request.
At its simplest a subject access request is when a person, a data subject, asks for access to data held about them.
However, the GDPR sets certain standards that take this right further than simply giving people a copy of their information. In this article we will explore what people’s rights are, and how to respond to a subject access request.
Contents
What is a Subject Access Request?
A subject access request is when people exercise a right under the GDPR as the right of access. This right is set out in Article 15 of the GDPR.
People are entitled to information about themselves, free of charge, within 30 calendar days of their request being received.
The right of access is one of eight rights people have under the GDPR. You can get an introduction to these rights here.
What does the GDPR Say?
-
The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information:
-
the purposes of the processing;
-
the categories of personal data concerned;
-
the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
-
where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
-
the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;
-
the right to lodge a complaint with a supervisory authority;
-
where the personal data are not collected from the data subject, any available information as to their source;
-
the existence of automated decision-making, including profiling, and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
-
-
Where personal data are transferred to a third country or to an international organisation, the data subject shall have the right to be informed of the appropriate safeguards.. relating to the transfer.
-
The controller shall provide a copy of the personal data undergoing processing…
What Does This Mean?
Firstly the right of access goes further than simply giving people a copy of their information. It points to a fundamental need to understand your data processing activities and all the personal data you hold. This is because, as well as providing a copy of the personal data about a person, you must be able to explain:
-
what you are processing data for
-
who you have shared the data with
-
where you got it from
-
how long you intend to keep the data
-
if you have sent the data abroad, and if so on what basis
-
if automated decision making or profiling has been done using the data
You also need to remind people of their rights to rectification and erasure, and their right to complain to the Information Commissioner if they feel their data has been handled wrongly.
What Are the Exceptions?
There are a number of exceptions to the right of access, but they operate in slightly different ways. In essence there are two types of exemption:
-
where you do not have to disclose the data you have, but still need to comply with the bullet points above
-
where you can withhold the data you have and do not have to comply with the bullet points above.
Withholding the Data
Sometimes you can refuse to share the information that you hold but you can still confirm that you have it, and are processing it.
Examples of this include things like:
-
employment references, both given and received
-
the marking or scoring of exams (although people are entitled to copies of their answers)
Withholding the Data and the Processing of Data
In other instances you can both withhold the information and the background information about it.
Two fairly straightforward examples where this can apply are:
Requests for information about other people.
Typically you can only ask for information about yourself but you can ask for information about third parties with permission. This is also true about information about children (see below).
Also, when you do get information about yourself in response to a subject access request the information about other people will usually be redacted, as will the reasons for processing it. The exceptions to this are:
-
if you have the consent of the other people
-
where it would be reasonable to share the information
It might be reasonable to share the information if it is a person’s email address and the requestor and the third party have communicated by email frequently in the past. Therefore you are not sharing anything new.
Remember personal data includes anything that could lead to a person being identified. Therefore if a person can be identified by context, such as the contents of an interview, the whole document should be withheld.
It should also be noted it is a criminal offence to require someone to make a subject access request. Any request is being made under compulsion or duress it must be refused.
Requests for Information Already Shared
If information has already been shared previously, perhaps because of a previous subject access request, there is no need to share it again. You also do not need to explain the background information to the processing again.
Manifestly Unfounded and Unreasonable Requests
Another key exemption to data subject access requests is when they are “manifestly unfounded and unreasonable”. This is a difficult one to get right, because when refusing a request for information you are denying someone’s legal rights.
However, there are circumstances when a request could be considered unfounded and excessive:
-
when someone makes repeated and frequent requests for information
-
when it is abundantly clear they are making a request in order to waste time or resources
-
when the requestor is targeting an individual as part of a wider campaign of harassment.
Sign Up Here:
Requests can be made verbally as well as in writing and people do not need to quote the act when doing so. You can ask people to fill in a particular form, or make their requests to a particular email address but you cannot make it a requirements. Therefore it is important to understand what people are asking for when they request information about themselves. In many instances people will only ask for a small amount of limited information or for details of processing of their personal data. These limited requests fall within the scope of a subject access request. Remember: employees and staff can make data subject access requests too. Verification of the requester’s identity is a crucial step in the process. Organisations must have procedures to ensure that personal data is not inadvertently disclosed to unauthorised individuals. Inappropriate disclosure is a data breach. GDPR rights apply from birth and the same is true of subject access requests. You must not assume parents can make requests on behalf of children, or that children have to be over a certain age to access information about themselves. Instead you must make an assessment of the child’s competence to make a request for their information and whether or not, by making their request, they are acting in their own best interests. The clock starts ticking as soon as a request for information is received. The GDPR stipulates a one-month timeframe for responding, and without undue delay. Understanding this constraint is vital for organisations to ensure compliance and build trust with data subjects. In certain situations, extensions to the one-month response window are permissible. However, organisations must communicate these extensions to the data subject. A response can be extended by a further two months if it is a highly complex request. Examples of a complex request may include: requests from people who are taking legal action or other action against the organisation – e.g. an employee in dispute with his employer, or; where there are unusually high volumes of personal information held, especially if it is sensitive personal data. Establishing streamlined internal processes for handling subject access requests is indispensable. From the moment data is collected to its eventual destruction, organisations need a comprehensive strategy covering access, security, and sharing arrangements. The biggest challenge to responding to requests is finding, analysing and collating the information. This is especially true, in our experience, with employees. This is because their personal data is processed internally quite widely if you consider: meeting minutes emails HR files etc. However, in a digital age it is likely that there a high volumes of personal data in electronic systems no matter what your relationship – employee, supplier or customer. Digital solutions can collate that information reasonably quickly. However, your search parameters need to be wide because: people are identifiable by more than name, like job title, order numbers of contact telephone number personal data includes videos and images as well as text paper records fall within the scope of subject access requests too. Once the personal data has been collated it must be analysed. In order to respond withing the timescale set out in data protection laws you must be mindful of the time this will take. A large volume of data will need more time for review. It is important to redact data that should not be shared, collate a register of data, and work out important elements of your response like: data categories the lawful bases for data processing (you can find out more about these here) retention periods etc. Once this is complete and the data are categorised appropriately you are in a position to respond. When you have finished collating and analysing personal data the final step is to respond. When sharing information it is often appropriate to share it electronically. Sometimes organisations can respond by giving data subjects access to their own records on organisational systems. This is not yet widespread but examples of when this happens include: online access to medical records workplace access to electronic staff record (ESR) systems For high volume electronic data you can create a one-drive or other online account and pass the login details to the person making the request. For paper based responses you should arrange for it to be collected or send it via recorded delivery or by courier. This will help ensure it is not lost or damaged in transit. If people are not happy with your response to their request for information there is a two step process. The first is to complain to you. You should consider any objections people have and decide whether you should release more information. If people remain unhappy then they can complain to the Information Commissioner’s Office (ICO). The ICO, if they take the complaint forward, will usually require you to release the relevant information the data subject is complaining about. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.
Subject Access Requests are not merely a legal necessity; they are an opportunity for organisations to showcase their commitment to transparency and data protection. Care must be taken to respond without sharing information that should not be shared or breaching statutory timescales. Organisations must be mindful of both the volume of information they may have about people and the need to analyse it carefully when responding to requests for information.Recognising a Subject Access Request
Proper Identification
Children and Subject Access Requests
How to Respond to a Subject Access Request
Extensions and Notifications
Finding Personal Data
Analysing the Data
Responding
What Happens if People Aren’t Happy?
Conclusion
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: