Subject access policy and template response letters

Similar documents
GDPR SUBJECT ACCESS REQUESTS PROCEDURE

SOUTHFIELD SCHOOL PROCEDURE FOR RECEIVING AND RESPONDING TO SUBJECT ACCESS REQUESTS

1.7 The Policy sets out the manner by which the University will respond to Subject Access Requests.

Subject Access Request Policy

Privacy and Data Protection Policy

SUBJECT ACCESS REQUEST PROCEDURE. Date: 08/10/2018

Part B of this Policy sets out the rights that all individuals have in relation to the collection and use of your personal information

Guidance Request for Record Deletion, Rectification, Restriction and Processing

Wesley House data protection statement and privacy notice (short-course delegates)

Subject Access Request Form

HOW TO EXERCISE YOUR DATA SUBJECT RIGHTS

Nexus Education Schools Trust. Subject Access Request Procedures

Data Subject Access Request Form (GDPR)

Data Protection Policy

Privacy Notice For Ghana International Bank Plc customers

Data Subject Access Request Form

Access Rights and Responsibilities. A guide for Individuals and Organisations

Rights of Individuals under the General Data Protection Regulation

Nexus Education Schools Trust. Subject Access Request Procedures

Confirming your identity

Index Introduction... 3

Contract Services Europe

Subject Access Request (SAR) Procedure

Data Protection Policy

Data Subject Access Request (SAR) Policy, Guidance and Template

Element Finance Solutions Ltd Data Protection Policy

How to Request Information from Cardiff Metropolitan University

Exercising Your Data Access Rights under the Personal Data (Privacy) Ordinance (Frequently Asked Questions and Answers)

Our Commitment to Personal Privacy

Application for access to your personal data held by the Aster Group as data controllers

PRIVACY POLICY BACKGROUND:

Privacy Notice. Lonsdale & Marsh Privacy Notice Version July

Creative Funding Solutions Limited Data Protection Policy

Data Processing Policy

Data Subject Access Request Form (GDPR)

Proving your identity and ownership of a property

HRP GDPR Subject Access Request procedure for website , version: v1

BOROUGH MARKET (SOUTHWARK) TRUST DATA SUBJECT REQUEST FORM

PS Mailing Services Ltd Data Protection Policy May 2018

Applicant Manager Guidance Notes

Privacy Notice. General Information Protection Regulation ( GDPR )

Privacy Notice - General Data Protection Regulation ( GDPR )

Subject: Kier Group plc Data Protection Policy

ICO Information Request Handling Procedures

Cova Security Gates Ltd Privacy Notice. Unit C1, Sussex Manor Business Park, Crawley, West Sussex, RH10 9NH, United Kingdom

Privacy Notice Alumni

HBW LAW LTD T/A HESELTINE BRAY & WELSH

TRUSTIS FPS. Enrolment Requirements: Acceptable Evidence in Support of an Application for a Digital Certificate

Data Subject Access Request Procedure. Page 1 KubeNet Data Subject Access Request Procedure KN-SOP

Haaga-Helia University of Applied Sciences Privacy Notice for the Laura Recruitment Service

Data Subject Access Request Form

GDPR Compliance. Clauses

PRIVACY POLICY PRIVACY POLICY

AccessNI Guidance Notes

PRIVACY POLICY. 1. Definitions and Interpretation In this Policy the following terms shall have the following meanings:

INFORMATION NOTE ON DATA PROCESSING

M T BUCKLEY & Co Chartered Accountants

Privacy Notices under #GDPR: Have you noticed my notice?

Data Protection Policy

JASON GOUGH COMPUTING SERVICES LTD WEB SITE PRIVACY POLICY 15/5/18

REAL RENTS PROPERTY MANAGEMENT LTD PRIVACY NOTICE

Islam21c.com Data Protection and Privacy Policy

Haaga-Helia University of Applied Sciences Privacy Notice for Student Administration

INNOVENT LEASING LIMITED. Privacy Notice

PRIVACY POLICY. 1. Definitions and Interpretation In this Policy the following terms shall have the following meanings:

A Homeopath Registered Homeopath

Data Subject Access Request

MBNL Landlord Privacy Notice. This notice sets out how we handle landlord personal data as part of our General Data Protection policies (GDPR).

Cognizant Careers Portal Privacy Policy ( Policy )

TouchPoint, Inc. Subject Access Request Form

PRIVACY POLICY OF THE WEB SITE

Haaga-Helia University of Applied Sciences Privacy Notice for Urkund Plagiarism Detection Software

This Privacy Policy governs our processing of all personal data provided to us at Environmental Essentials in relation to our E-learning services.

Pathways CIC Privacy Policy. Date Issued: May Date to be Reviewed: May Issued by Yvonne Clarke

CHECKER GUIDE TO THE ONLINE DBS APPLICATION SYSTEM

PRIVACY NOTICE INTRODUCTION

About Us. Privacy Policy v1.3 Released 11/08/2017

NCAS SUBJECT ACCESS REQUEST FORM (DATA PROTECTION ACT 1998)

British Handball Association: Privacy Policy

WEBSITE PRIVACY POLICY

Website Privacy Policy

Privacy Policy Hafliger Films SpA

VISTRA (CYPRUS) LTD. PRIVACY NOTICE

Data Protection Policy

PRIVACY NOTICE (TIER 4)

Privacy Notice For Our Customers And Contacts

Beam Suntory Privacy Policy WEBSITE PRIVACY NOTICE

General Data Protection Regulation (GDPR) Policy

DATA SECURITY - DATA PROTECTION ACT

CEM Benchmarking Privacy Policy

Extension Architecture Privacy Notice

Subject Access Request Form

DCU Guide to Subject Access Requests. Under Irish Data Protection Legislation

Within the meanings of applicable data protection law (in particular EU Regulation 2016/679, the GDPR ):

Total Tax Group Privacy Notice

EIT Health UK-Ireland Privacy Policy

Data Protection. Policy

Privacy Policy of

Vistra International Expansion Limited PRIVACY NOTICE

PRIVACY NOTICE BACKGROUND:

Transcription:

Barham Parish Council. Subject Access Requests ( SAR ) Checklist Inform data subjects of their right to access data and provide an easily accessible mechanism through which such a request can be submitted (e.g. a dedicated email address). Make sure a SAR policy is in place within the council and that internal procedures on handling of SARs are accurate and complied with. Include, among other elements, provisions on: (1) Responsibilities (who, what) (2) Timing (3) Changes to data (4) Handling requests for rectification, erasure or restriction of processing. Ensure personal data is easily accessible at all times in order to ensure a timely response to SARs and that personal data on specific data subjects can be easily filtered. Where possible, implement standards to respond to SARs, including a standard response. Upon receipt of a SAR Verify whether you are controller of the data subject s personal data. If you are not a controller, but merely a processor, inform the data subject and refer them to the actual controller. Verify the identity of the data subject; if needed, request any further evidence on the identity of the data subject. Verity the access request; is it sufficiently substantiated? Is it clear to the data controller what personal data is requested? If not: request additional information. Verify whether requests are unfounded or excessive (in particular because of their repetitive character); if so, you may refuse to act on the request or charge a reasonable fee. Promptly acknowledge receipt of the SAR and inform the data subject of any costs involved in the processing of the SAR. Verify whether you process the data requested. If you do not process any data, inform the data subject accordingly. At all times make sure the internal SAR policy is followed and progress can be monitored. Ensure data will not be changed as a result of the SAR. Routine changes as part of the processing activities concerned are permitted. Verify whether the data requested also involves data on other data subjects and make sure this data is filtered before the requested data is supplied to the data subject; if data cannot be filtered, ensure that other data subjects have consented to the supply of their data as part of the SAR.

Responding to a SAR Respond to a SAR within one month after receipt of the request: (i) (ii) If more time is needed to respond to complex requests, an extension of another two months is permissible, provided this is communicated to the data subject in a timely manner within the first month; if the council cannot provide the information requested, it should inform the data subject on this decision without delay and at the latest within one month of receipt of the request. If a SAR is submitted in electronic form, any personal data should preferably be provided by electronic means as well. If data on the data subject is processed, make sure to include as a minimum the following information in the SAR response: (i) (ii) (iii) (iv) (v) (vi) (vii) (viii) the purposes of the processing; the categories of personal data concerned; the recipients or categories of recipients to whom personal data has been or will be disclosed, in particular in third countries or international organisations, including any appropriate safeguards for transfer of data, such as Binding Corporate Rules 1 or EU model clauses 2 ; where possible, the envisaged period for which personal data will be stored, or, if not possible, the criteria used to determine that period; the existence of the right to request rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing; the right to lodge a complaint with the Information Commissioners Office ( ICO ); if the data has not been collected from the data subject: the source of such data; the existence of any automated decision-making, including profiling and any meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject. Provide a copy of the personal data undergoing processing. Sample Subject Access Requests Policy What must I do? 1. MUST: On receipt of a subject access request you must forward it immediately to the Parish Clerk, 23 Old Rectory Close, Barham, IP6 0PY 2. MUST: We must correctly identify whether a request has been made under the Data Protection legislation 3. MUST: A member of staff, and as appropriate, councillor, who receives a request to locate and supply personal data relating to a SAR must make a full exhaustive search of the records to which they have access. 1 Binding Corporate Rules is a global data protection policy covering the international transfer pf personal data out of the European Union. It requires approval of a data protection regulator in the European Union. In most cases this will be the relevant regulator where an organisation s headquarters is located. In the UK, the relevant regulator is the Information Commissioner s Office. 2 EU model clauses are clauses approved by the European Union which govern the international transfer of personal data. The clauses can be between two data controllers or a data controller and a data processor.

4. MUST: All the personal data that has been requested must be provided unless an exemption can be applied. 5. MUST: We must respond within one calendar month after accepting the request as valid. 6. MUST: Subject Access Requests must be undertaken free of charge to the requestor unless the legislation permits reasonable fees to be charged. 7. MUST: Councillors and managers must ensure that the staff they manage are aware of and follow this guidance. 8. MUST: Where a requestor is not satisfied with a response to a SAR, the council must manage this as a complaint. How must I do it? 1. Notify the Parish Clerk upon receipt of a request. 2. We must ensure a request has been received in writing where a data subject is asking for sufficiently well-defined personal data held by the council relating to the data subject. You should clarify with the requestor what personal data they need. They must supply their address and valid evidence to prove their identity. The council accepts the following forms of identification (* These documents must be dated in the past 12 months, +These documents must be dated in the past 3 months): Current UK/EEA Passport UK Photocard Driving Licence (Full or Provisional) Firearms Licence / Shotgun Certificate EEA National Identity Card Full UK Paper Driving Licence State Benefits Entitlement Document* State Pension Entitlement Document* HMRC Tax Credit Document* Local Authority Benefit Document* State/Local Authority Educational Grant Document* HMRC Tax Notification Document Disabled Driver s Pass Financial Statement issued by bank, building society or credit card company+ Judiciary Document such as a Notice of Hearing, Summons or Court Order Utility bill for supply of gas, electric, water or telephone landline+ Most recent Mortgage Statement Most recent council Tax Bill/Demand or Statement Tenancy Agreement Building Society Passbook which shows a transaction in the last 3 months and your address 3. Depending on the degree to which personal data is organised and structured, you will need to search emails (including archived emails and those that have been deleted but are still recoverable), Word documents, spreadsheets, databases, systems, removable media (for example, memory sticks, floppy disks, CDs), tape recordings, paper records in relevant filing systems etc. which your area is responsible for or owns. 4. You must not withhold personal data because you believe it will be misunderstood; instead, you should provide an explanation with the personal data. You must provide the personal data in an intelligible form, which includes giving an explanation of any codes, acronyms and complex terms. The personal data must be supplied in a permanent form except where the person agrees or where it is impossible or would involve undue effort. You may be able to agree with the requester that they will view the personal data on screen or inspect files on our premises. You must redact any exempt personal data from the released documents and explain why that personal data is being withheld. 5. Make this clear on forms and on the council website

6. You should do this through the use of induction, my performance and training, as well as through establishing and maintaining appropriate day to day working practices. 7. A database is maintained allowing the council to report on the volume of requests and compliance against the statutory timescale. 8. When responding to a complaint, we must advise the requestor that they may complain to the Information Commissioners Office ( ICO ) if they remain unhappy with the outcome. Sample letters All letters must include the following information: the purposes of the processing; the categories of personal data concerned; the recipients or categories of recipients to whom personal data has been or will be disclosed, in particular in third countries or international organisations, including any appropriate safeguards for transfer of data, such as Binding Corporate Rules 3 or EU model clauses 4 ; where possible, the envisaged period for which personal data will be stored, or, if not possible, the criteria used to determine that period; the existence of the right to request rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing; the right to lodge a complaint with the Information Commissioners Office ( ICO ); if the data has not been collected from the data subject: the source of such data; the existence of any automated decision-making, including profiling and any meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject. Replying to a subject access request providing the requested personal data Thank you for your letter of [date] making a data subject access request for [subject]. We are pleased to enclose the personal data you requested. Include 1(a) to (h) above. Copyright in the personal data you have been given belongs to the council or to another party. Copyright material must not be copied, distributed, modified, reproduced, transmitted, published or otherwise made available in whole or in part without the prior written consent of the copyright holder. 3 Binding Corporate Rules is a global data protection policy covering the international transfer of personal data out of the European Union. It requires approval of a data protection regulator in the European Union. In most cases this will be the relevant regulator where an organisation s headquarters is located. In the UK, the relevant regulator is the Information Commissioner s Office. 4 EU model clauses are clauses approved by the European Union which govern the international transfer of personal data. The clauses can be between two data controllers or a data controller and a data processor.

Release of part of the personal data, when the remainder is covered by an exemption Thank you for your letter of [date] making a data subject access request for [subject]. To answer your request, we asked the following areas to search their records for personal data relating to you: [List the areas] I am pleased to enclose [some/most] of the personal data you requested. [If any personal data has been removed] We have removed any obvious duplicate personal data that we noticed as we processed your request, as well as any personal data that is not about you. You will notice that [if there are gaps in the document] parts of the document(s) have been blacked out. [OR if there are fewer documents enclose] I have not enclosed all of the personal data you requested. This is because [explain why it is exempt]. Include 1(a) to (h) above. Copyright in the personal data you have been given belongs to the council or to another party. Copyright material must not be copied, distributed, modified, reproduced, transmitted, published, or otherwise made available in whole or in part without the prior written consent of the copyright holder. Replying to a subject access request explaining why you cannot provide any of the requested personal data Thank you for your letter of [date] making a data subject access request for [subject]. I regret that we cannot provide the personal data you requested. This is because [explanation where appropriate]. [Examples include where one of the exemptions under the data protection legislation applies. For example, the personal data might include personal data is legally privileged because it is contained within legal advice provided to the council or relevant to on-going or preparation for litigation. Other exemptions include where the personal data identifies another living individual or relates to negotiations with the data subject. Your data protection officer will be able to advise if a relevant exemption applies and if the council is going to rely on the exemption to withhold or redact the data disclosed to the individual, then in this section of the letter the council should set out the reason why some of the data has been excluded.]