Why businesses shouldn’t ignore data requests

by | May 10, 2019

The data protection laws allow individuals certain rights in relation to their personal data. One such right is to access their personal information – this is also known as a subject access request (SAR).
In a recent case a housing developer has been prosecution for a failure to respond to a subject access request as required by the legislation. This is after they ignored an enforcement notice from the data watchdog in the UK, the Information Commissioner Office (ICO), which ordered them to comply with the law.
The company pleaded guilty and to a charge of failing to comply with an enforcement notice. It was fined £300, with a £30 victim surcharge, and was ordered to pay £1,133.75 towards prosecution costs.
As you may be aware, the GDPR and the Data Protection Act 2018 came into force on 25 May 2018. The new law changed some of the rules around SAR’s. 
Main points include:
  • A SAR does not require a specific format, it can be in a letter, email or verbal;
  • Organisations must act on the request without undue delay and at the latest within one month of receipt;
  • In most cases organisations cannot charge a fee to deal with a request;
  • Organisations must provide specified information to the person making the request;
  • There are clear rules around calculating the one month time limit.

For further information, or if you have a SAR enquiry, please contact me.

The 12 Days of Christmas

On the first day of Christmas my true love gave to me - A bonus with a bottle of brandy Christmas Bonus With the cost of living, it may not be possible to give your employees a Christmas bonus this year. If the Christmas bonus is contractual then you will need to pay...