Handling Data Subject Access Requests

data subject requests

Data Subject Access Requests (DSARs) are on the rise and it can be overwhelming for a business or organisation to know what to do and how to respond.  

Under UK GDPR (our data protection law), organisations have a legal obligation to respond to a request by a data subject for the personal information that you hold about them, within a certain time frame (generally a calendar month). By following the guidance set out below you can make responding to a DSAR easier to handle and more straightforward. 

DSAR recognition

DSARs can be made in a variety of ways, not just by email or letter, they can also be made verbally, or on social media.  All staff should be able to recognise a DSAR when they see or hear one.  Regular training and awareness campaigns work well to ensure that DSARs are picked up and dealt with effectively.  

Narrow down the scope of the Data Subject Access Request

Adopt a strategy of asking the individual to clarify whether there is specific information about that person that they are interested in.  It’s not easy if the Data Subject wants “all their data”, although this type of request is usually submitted as a nuisance and isn’t really about the individual wanting a copy of their information. By narrowing the scope of the request, the response can be handled quickly and more efficiently which will reduce the likelihood of a mishandling complaint.

How much information do you need to provide in response to a DSAR?

One common request made under the banner of a Data Subject Access Request is when the individual asks where their personal data has been shared. In the case of Harrison v Cameron, the data subject requested the names of all the third parties with whom the company had shared his personal data. 

Many organisations would respond to an enquiry like this with a generalised list of categories of recipients, referring requesters to their privacy notice which, in accordance with UK GDPR, should say that a data subject should be given information on ‘the recipients or categories of recipient’ to whom their personal data have been or will be disclosed. 

In the case of Harrison v Cameron, the High Court ruled that the data subject, not the controller, was entitled to decide whether they want information about specific recipients or just categories of recipients.

This means that if someone asks for the names of the specific parties who have received their personal data, you must provide that information, unless it would be impossible or manifestly excessive to do so.

Understand the Data Subject’s motivation

It’s not always easy to analyse with a great deal of certainty but as a general rule, individuals usually only request copies of their personal information when they are disgruntled or unhappy.  Keep a simple log of each DSAR you receive, noting the type of data subject, the date of the request and the location of the personal information.  You will soon build up a picture that may point towards the need to revisit your processes and procedures. 

If providing the information is genuinely impossible or manifestly excessive, you may have grounds to limit your response. However, be prepared to justify your decision.

Data Subject Requests – Keep records

Keep a record of the requests received and how they are dealt with (including any justifications for decisions about how they are responded to).  This will help evidence compliance and ensure that deadlines are not missed. Having a robust workflow and keeping logs also helps with understanding the root cause of the DSAR.  Personal information in straightforward DSARs must be supplied within 1 calendar month and for more complicated DSARs you have an additional 2 months but you must keep the individual informed of your progress. 

It’s also good to keep records of how and where data is shared, including the names of individuals to whom it is provided. This will help you comply with any detailed DSARs you might receive.

Act promptly when dealing with DSARs

DSARs must be dealt with within one month, which can be extended by a further two months for complex and extensive DSARs. Incorporating deadlines into your workflow will ease the burden and assist with compliance. 

Technology can help you manage your data protection obligations

Organisations receiving a lot of DSARs might want to consider a technology platform that can capture all the necessary compliance obligations as well as gather and redact the personal information. 

The best response to DSARs? Let us know if we can help

Please contact us for a no-obligation chat.  We can help you understand your data protection obligations, in more detail, so that you can comply with the law and put procedures in place to reduce the risk of breach or non-compliance, which will lead to building trust and boosting your reputation as a responsible business.