A data subject access request (SAR) is a legal right for individuals to access the information that an organisation holds about them.

Recent data protection legislation has had a significant impact on how organisations manage and respond to data subject access requests (SARs). The abolition of the £10 administration fee, reduced timescale for responding to a SAR, and higher fees for not complying; all pose significant challenges to how organisations manage SARs.

This Complying with Data Subject Access Requests course has been specifically designed to help you to identify and manage SARs. Through a series of interactive workshops, gain hands on experience at understanding the latest legislation on SARs; identifying and managing SARs, and applying the exemptions.

Attend this training course to take back a SARs handling toolkit to ensure that you and your organisation successfully comply and respond to a SAR.

About the Chair: Paul Gibbons
Paul Gibbons is a leading expert in information rights and management with many years experience in the field. With a background in the pharmaceutical industry, Paul then became the first Parliamentary Records Manager, and later prepared the Mayor of London for the implementation of the Freedom of Information Act. His experience also covers working for a London Healthcare Trust and a college of the University of London.

Paul has subsequently worked as an information governance manager, managing compliance with the Data Protection Act and other legislation in the NHS and in higher education. Since 2010 he has been writing the respected FOI Man blog and now provides training and consultancy in information rights and management to the public sector and beyond. He has become well known in the UK public sector and beyond and is regularly asked to speak and write about information rights.

09:15 - 09:45

Registration

09:45 - 10:00

Trainer’s Welcome and Introductions

10:00 - 10:45

Workshop I: Understanding the Latest Legislation on SARs

Gain a brief overview of Data Subjects Access Requests, under GDPR and Data Protection Act 2018.

  •  Ascertain what the GDPR and DPA Act 2018 state about SARs
  • Learn what has changed from DPA 1998
  • Understand the difference between SARs and FOI requests
  • Understand what is covered by SARs – what is personal data?
10:45 - 11:00

Morning Break

11:00 - 12:00

Workshop II: Identifying and Managing SARs

  • Ensure the subject access request is valid
  • Train your staff to identify a SAR
  • Prepare your staff to take a SAR through different mediums: phone, email, letter or form
  • Gain senior buy-in to ensure your organisation has effective procedures in place to manage SARs
  • Develop strategies to manage the increase of SARs
  • Learn the tools to verify the data subjects identify
  • Establish proof of authority
12:00 - 13:00

Workshop III: Applying the Exemptions

  • Understand the exemptions in the Data Protection Act 2018
  • Know when exemptions apply to SARs
  •  Learn what should be included in responses when refusing requests
13:00 - 14:00

Lunch

14:00 - 14:45

Workshop IV: Requests for Third Party Personal Data

How to deal with requests for personal data relating to third parties without harming individuals’ privacy.

  • The Third party data exemption
  • Obtaining consent from third parties
  • Deciding whether it is reasonable to disclose data
  • Data about children and families
14:45 - 15:00

Afternoon Break

15:00 - 16:00

Workshop V: Design a SARs Handling Toolkit

  • The role of a Data Protection Officer in managing a SAR
  • Examine bad and best practice examples
  • Learn what information to include when responding to a SAR
  • Avoid data breaches by removing other individual’s data
  • Develop recording procedures to monitor the process of the SAR request
16:00 - 16:15

Feedback, Evaluation and Close

De Vere West One

9-10 Portland Pl
Marylebone
London
W1B 1PR

020 7222 7777