The right of access is a fundamental right of individuals under data protection law. Organisations can face challenges in dealing effectively with the exercise of the right (a subject access request or ‘SAR’), including in identifying requests, searching for personal data, and applying exemptions.
This course looks at the requirements for SARs set out in the UK GDPR and Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025), taking into account associated ICO guidance and case law, which assist with practical interpretation of the rules. It gives delegates the information they need to set up an effective SAR-handling process in their organisation, and looks at how to avoid common pitfalls that arise. It includes:
- what is the right of access, and who is responsible for responding to SARs
- identifying requests from individuals and determining when a request is a SAR
- initial steps to take on receipt of a SAR, including confirming identity, seeking clarification, and determining whether a fee can be charged
- timescales for responding
- clarification over what is an individual’s “personal data”
- practical approaches to searching for data
- deciding what data to provide and in what format
- dealing with third-party information (information about another individual which is mixed in with the requestor’s data)
- assessing whether a request is manifestly unfounded or excessive
- applying other common exemptions
- preparing for SARs and managing the SAR process
Delegates will work through practical scenarios and will leave the session knowing how to respond to access requests and how to set up an effective SAR-handling process in their organisation.
Attendance on the Classroom and Virtual(Teams) formats of this course can be used as credit towards gaining the Practitioner Certificate in Data Protection.
“Extensive, interesting, well-delivered and engaging.”