How to Respond to a Subject Access Request

Under the GDPR every organisation must know how to respond to a subject access request.

At its simplest a subject access request is when a person, a data subject, asks for access to data held about them.

However, the GDPR sets certain standards that take this right further than simply giving people a copy of their information. In this article we will explore what people’s rights are, and how to respond to a subject access request.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

Contents

What is a Subject Access Request?

A subject access request is when people exercise a right under the GDPR as the right of access. This right is set out in Article 15 of the GDPR.

People are entitled to information about themselves, free of charge, within 30 calendar days of their request being received.

The right of access is one of eight rights people have under the GDPR. You can get an introduction to these rights here.

What does the GDPR Say?

  1. The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information:

    • the purposes of the processing;

    • the categories of personal data concerned;

    • the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;

    • where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;

    • the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;

    • the right to lodge a complaint with a supervisory authority;

    • where the personal data are not collected from the data subject, any available information as to their source;

    • the existence of automated decision-making, including profiling, and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.

  2. Where personal data are transferred to a third country or to an international organisation, the data subject shall have the right to be informed of the appropriate safeguards.. relating to the transfer.

  3. The controller shall provide a copy of the personal data undergoing processing…

What Does This Mean?

Firstly the right of access goes further than simply giving people a copy of their information. It points to a fundamental need to understand your data processing activities and all the personal data you hold. This is because, as well as providing a copy of the personal data about a person, you must be able to explain:

  • what you are processing data for

  • who you have shared the data with

  • where you got it from

  • how long you intend to keep the data

  • if you have sent the data abroad, and if so on what basis

  • if automated decision making or profiling has been done using the data

You also need to remind people of their rights to rectification and erasure, and their right to complain to the Information Commissioner if they feel their data has been handled wrongly.

What Are the Exceptions?

There are a number of exceptions to the right of access, but they operate in slightly different ways. In essence there are two types of exemption:

  1. where you do not have to disclose the data you have, but still need to comply with the bullet points above

  2. where you can withhold the data you have and do not have to comply with the bullet points above.

Withholding the Data

Sometimes you can refuse to share the information that you hold but you can still confirm that you have it, and are processing it.

Examples of this include things like:

  • employment references, both given and received

  • the marking or scoring of exams (although people are entitled to copies of their answers)

Withholding the Data and the Processing of Data

In other instances you can both withhold the information and the background information about it.

Two fairly straightforward examples where this can apply are:

Requests for information about other people.

Typically you can only ask for information about yourself but you can ask for information about third parties with permission. This is also true about information about children (see below).

Also, when you do get information about yourself in response to a subject access request the information about other people will usually be redacted, as will the reasons for processing it. The exceptions to this are:

  • if you have the consent of the other people

  • where it would be reasonable to share the information

It might be reasonable to share the information if it is a person’s email address and the requestor and the third party have communicated by email frequently in the past. Therefore you are not sharing anything new.

Remember personal data includes anything that could lead to a person being identified. Therefore if a person can be identified by context, such as the contents of an interview, the whole document should be withheld.

It should also be noted it is a criminal offence to require someone to make a subject access request. Any request is being made under compulsion or duress it must be refused.

Requests for Information Already Shared

If information has already been shared previously, perhaps because of a previous subject access request, there is no need to share it again. You also do not need to explain the background information to the processing again.

Manifestly Unfounded and Unreasonable Requests

Another key exemption to data subject access requests is when they are “manifestly unfounded and unreasonable”. This is a difficult one to get right, because when refusing a request for information you are denying someone’s legal rights.

However, there are circumstances when a request could be considered unfounded and excessive:

  • when someone makes repeated and frequent requests for information

  • when it is abundantly clear they are making a request in order to waste time or resources

  • when the requestor is targeting an individual as part of a wider campaign of harassment.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Recognising a Subject Access Request

Requests can be made verbally as well as in writing and people do not need to quote the act when doing so. You can ask people to fill in a particular form, or make their requests to a particular email address but you cannot make it a requirements.

Therefore it is important to understand what people are asking for when they request information about themselves.

In many instances people will only ask for a small amount of limited information or for details of processing of their personal data. These limited requests fall within the scope of a subject access request.

Remember: employees and staff can make data subject access requests too.

Proper Identification

Verification of the requester’s identity is a crucial step in the process. Organisations must have procedures to ensure that personal data is not inadvertently disclosed to unauthorised individuals. Inappropriate disclosure is a data breach.

Children and Subject Access Requests

GDPR rights apply from birth and the same is true of subject access requests. You must not assume parents can make requests on behalf of children, or that children have to be over a certain age to access information about themselves.

Instead you must make an assessment of the child’s competence to make a request for their information and whether or not, by making their request, they are acting in their own best interests.

How to Respond to a Subject Access Request

The clock starts ticking as soon as a request for information is received. The GDPR stipulates a one-month timeframe for responding, and without undue delay. Understanding this constraint is vital for organisations to ensure compliance and build trust with data subjects.

Extensions and Notifications

In certain situations, extensions to the one-month response window are permissible. However, organisations must communicate these extensions to the data subject.

A response can be extended by a further two months if it is a highly complex request. Examples of a complex request may include:

  • requests from people who are taking legal action or other action against the organisation – e.g. an employee in dispute with his employer, or;

  • where there are unusually high volumes of personal information held, especially if it is sensitive personal data.

Finding Personal Data

Establishing streamlined internal processes for handling subject access requests is indispensable. From the moment data is collected to its eventual destruction, organisations need a comprehensive strategy covering access, security, and sharing arrangements.

The biggest challenge to responding to requests is finding, analysing and collating the information. This is especially true, in our experience, with employees. This is because their personal data is processed internally quite widely if you consider:

  • meeting minutes

  • emails

  • HR files

etc. However, in a digital age it is likely that there a high volumes of personal data in electronic systems no matter what your relationship – employee, supplier or customer.

Digital solutions can collate that information reasonably quickly. However, your search parameters need to be wide because:

  • people are identifiable by more than name, like job title, order numbers of contact telephone number

  • personal data includes videos and images as well as text

  • paper records fall within the scope of subject access requests too.

Analysing the Data

Once the personal data has been collated it must be analysed. In order to respond withing the timescale set out in data protection laws you must be mindful of the time this will take. A large volume of data will need more time for review.

It is important to redact data that should not be shared, collate a register of data, and work out important elements of your response like:

  • data categories

  • the lawful bases for data processing (you can find out more about these here)

  • retention periods

etc. Once this is complete and the data are categorised appropriately you are in a position to respond.

Responding

When you have finished collating and analysing personal data the final step is to respond. When sharing information it is often appropriate to share it electronically.

Sometimes organisations can respond by giving data subjects access to their own records on organisational systems. This is not yet widespread but examples of when this happens include:

  • online access to medical records

  • workplace access to electronic staff record (ESR) systems

For high volume electronic data you can create a one-drive or other online account and pass the login details to the person making the request.

For paper based responses you should arrange for it to be collected or send it via recorded delivery or by courier. This will help ensure it is not lost or damaged in transit.

What Happens if People Aren’t Happy?

If people are not happy with your response to their request for information there is a two step process.

The first is to complain to you. You should consider any objections people have and decide whether you should release more information.

If people remain unhappy then they can complain to the Information Commissioner’s Office (ICO). The ICO, if they take the complaint forward, will usually require you to release the relevant information the data subject is complaining about.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial

Conclusion

Subject Access Requests are not merely a legal necessity; they are an opportunity for organisations to showcase their commitment to transparency and data protection. Care must be taken to respond without sharing information that should not be shared or breaching statutory timescales. Organisations must be mindful of both the volume of information they may have about people and the need to analyse it carefully when responding to requests for information.