The right of access, commonly referred to as a Subject Access Request, or SAR, gives individuals the right to request a copy of their personal data from organisations.
Last month the Information Commissioner’s Office (ICO) published new guidance for employers on responding to SARs.
The new guidance is published in question and answer format, referring to relevant parts of the ICO’s detailed guidance on the topic, and providing useful examples under each question to help organisations apply the guidance to their own contexts.
Bearing in mind the complexities around SARs and the penalties for non-compliance by data controllers, we welcome the additional guidance from the ICO, and encourage data protection compliance managers to familiarise themselves with it.
We have previously published a guide to responding to SARs, which you can read here.
Banner photo by Towfiqu barbhuiya on Unsplash