Firms should be aware that a key part of the Data Protection Act 2018 is that it grants
individuals significant rights over their personal data. One of the most prominent of these
rights is the right to access their personal data, commonly known as a Data Subject Access
Request (DSAR).
This blog post will provide a practical guide to help organizations navigate the DSAR
process effectively and comply with the DPA 2108.
1. What is a DSAR?
A DSAR is a formal request from an individual to an organization to:
Confirm whether or not the organization is processing their personal data.
Access their personal data.
Obtain information about how their personal data is being processed.
2. Key Considerations for Handling DSARs:
Timeliness: Organizations must respond to valid DSARs within one month.
o In complex cases, this period can be extended by a further two months, but
the organization must inform the individual within one month of the request
and explain the reasons for the delay.
Free of Charge: In most cases, organizations must provide access to the requested
information free of charge.
o However, excessive or manifestly unfounded requests may be subject to a
reasonable fee.
Format: The information must be provided in a commonly used and machine-
readable format, such as CSV or JSON, where technically feasible.
Accuracy: The information provided must be accurate and up-to-date.
Scope: The scope of a DSAR can be broad, covering various aspects of data
processing, including:
o The purposes of the processing
o The categories of data being processed
o The recipients of the data
o The data retention periods
3. The DSAR Process:
Receive and Acknowledge: Upon receiving a DSAR, acknowledge receipt promptly
and inform the individual of the intended course of action.
Verify the Request: Verify the identity of the data subject to prevent unauthorized
access to personal data.
Consider notifying professional indemnity insurers: often a request for data is a
pre-cursor to a complaint
Locate and Retrieve Data: Locate and retrieve all relevant personal data from
various sources (e.g., databases, files, emails).
Prepare and Provide Information: Prepare the information in the requested format
and provide it to the individual within the specified timeframe.
Document and Record: Maintain clear records of all DSARs received, the actions
taken, and the information provided.
4. Common Challenges and Best Practices:
Meeting Deadlines: Implement robust internal processes to ensure timely responses
to DSARs.
Data Location and Retrieval: Establish clear data mapping and storage procedures
to facilitate efficient data retrieval.
Data Security: Ensure the security and confidentiality of personal data throughout
the DSAR process.
Training and Awareness: Train relevant staff on the requirements of the UK GDPR
implementation legislation and the procedures for handling DSARs.
Staying Updated: Keep abreast of any changes to data protection legislation.
5. Conclusion:
Handling DSARs effectively is crucial for compliance with the UK GDPR and maintaining
data subject trust. By following the guidance outlined in this blog post, organizations can
streamline their DSAR processes, minimize risks, and ensure they are meeting their data
protection obligations.
Disclaimer: This blog post provides general information and should not be considered legal
advice. Organizations are encouraged to seek professional legal counsel for specific
guidance on handling DSARs under the DPA 2018.
Note: This information is for general guidance only and may not be entirely up-to-date. It is
essential to consult the official UK GDPR implementation legislation and relevant guidance
documents for the most accurate and current information.
I hope this blog post is helpful!
The author, Vince Harvey, has worked in financial services for many years and has been running his
compliance consultancy for more than a decade. His specialist areas within the Compliance Alliance
are investment advice and management.
You can contact him on 07890311875 or at vince@compliancecubed.co.uk
