Blog

How to deal with a subject access request

We've recently seen an increase in the number of advice firm requests we're getting on how to deal with subject access requests (SARs).

Graeme Stewart

Graeme Stewart

27 January 2021
So how should you go about dealing with a request when you receive one, and just what are your firm’s obligations?

First things first, what is an SAR?

An SAR is a request from an individual to obtain a copy of their personal data and other supplementary information from you. This right of access is a fundamental right for individuals.

Briefly:

  • Individuals can make SARs verbally or in writing, including via social media
  • A third party can make an SAR on behalf of another person
  • You cannot generally charge a fee to deal with a request
  • Responses should be sent without delay and within one month of receiving the request
  • The time limit can be extended by a further two months if the request is complex, or if you receive a number of requests from the individual
  • You should perform a reasonable search for the requested information
  • You should provide the information in an accessible, concise and intelligible format
  • The information should be disclosed securely.
  • You must provide the information unless an exemption or restriction applies, or if the request is ‘manifestly unfounded’ or ‘excessive’
(For more information on unfounded and excessive requests, the Information Commissioner's Office has put together this useful article: When can we refuse to comply with a request?)

What's expected of firms

The Information Commissioner's Office (ICO) expects firms to be prepared and to take a proactive approach so they can respond to requests in an effective and timely manner.

This means all staff in a client-facing role should be able to respond to an SAR when one is made. The ICO says by doing so this will help firms to:

  • comply with legal obligations under the General Data Protection Regulation (GDPR) and the Data Protection Act 2018 and show how they have done so
  • streamline their processes for dealing with SARs, saving both time and effort
  • increase levels of trust and confidence in their organisation by being open with individuals about the personal data held about them
  • enable customers, employees and others to verify that the information the firm holds about them is accurate, and to tell them if it's not
  • improve confidence in their information handling practices; and
  • increase the transparency of what they do with individuals’ data.
If firms do want to take a proactive approach and get to a stage where they're ready to deal with an SAR, it may be worth role-playing a scenario where a client has made a request and testing your approach to dealing with this.

Some firms may also choose to appoint an SAR 'tzar' or 'champion', so that any client queries from any source may be channelled and dealt with efficiently.

The ICO has recently published detailed SARs guidance to help firms meet their legal requirements, and the guide offers comprehensive support as well as answers to common questions. 

Overall, the key things to consider when dealing with a request are:
  • Verify the identity and/or the permission or authority provided by the person making the request
  • Agree how the firm is going to present the data for a client; this could be sent securely via the post or online
  • Does the client have any special requirements, for example, providing the data in larger print, braille or through an audio format?
  • How long might the firm need to collect the data, and how easy is this to obtain?
Firms who have trained staff to recognise an SAR, and who have tested their response to such a request, will be in a better position to deal with a request when one is made.

Not only will this meet with ICO expectations, but it makes sense from a business perspective as well.
Start the discussion

Reading this blog counts towards your CPD!

Click here to add this session to your Paradigm CPD log.


19 December 2024

Housing Market: 2025 Outlook


28 November 2024

Suppressing landlord activity won’t automatically improve first-time buyer prospects


25 November 2024

The Co-operative Bank for Intermediaries, streamlining processes and expanding product ranges


21 November 2024

Better off dead? The need for critical illness cover


18 November 2024

What the OBR’s five year forecasts mean for the market


11 November 2024

Exploring the latest in Defaqto Engage: A comprehensive roundup of new features and enhancements.


25 October 2024

Advisers should rethink their regulatory status to keep up with sector changes


16 October 2024

Your Business Matters


7 October 2024

What may impact BTL and Resi markets in 2025?


1 October 2024

Why Gen Z could be the perfect match for protection


30 September 2024

Self-employed mortgages can be easy, if you choose the right lender


26 September 2024

Lenders and regulators must be careful not to add to adviser disillusion


19 September 2024

There may be trouble ahead…


2 September 2024

Source Go: The Modern Answer to the GI Question


29 August 2024

Pre- and post-mini Budget remortgagors need guidance in transformed market


23 August 2024

Guardian's 2023 claims report: a milestone worth celebrating


14 August 2024

Rate cuts are a positive story for advisers


7 August 2024

Mind the gap (s)...


1 August 2024

The mortgage market is set for a teeming H2


29 July 2024

Aldermore are backing more of your clients to go for it


22 July 2024

YOU SAID, WE DID!


12 July 2024

A surge of optimism for the market


9 July 2024

Distribution of Wealth


3 July 2024

Consumer Duty one year on – what might happen next?


24 June 2024

How to increase your protection business


17 June 2024

Consumer Duty will mark new era of continuously changing advice


6 June 2024

Mental Health Matters: Workplace Wellbeing


21 May 2024

Advise or refer? Ensuring the best possible outcomes for your clients


15 May 2024

Darlington Criteria Updates


14 May 2024

And The Wait Goes On


10 May 2024

Cap on broker fees sparks industry debate


1 May 2024

Expect the unexpected


15 April 2024

Ready, set, remortgage!


12 April 2024

How the mortgage market is failing new arrivals to the UK


11 April 2024

A compliance refresh will lighten unavoidable market stress


4 April 2024

What is driving the Specialist Residential and Buy-to-Let markets this year?


4 April 2024

A Government that prioritises owner occupiers at the expense of the PRS


28 March 2024

What is your website for?


19 March 2024

Exploring the value of value added benefits


4 March 2024

Artificial intelligence – friend or foe to advisers?


21 February 2024

RESTRICTIONS LIFTED?


9 February 2024

Trust your own gut when listening to market predictions


7 February 2024

Strategic thinking - Is this time for a new look at how we work as a business?


8 January 2024

The Name's Bond...


Paradigm

THIS SITE IS FOR PROFESSIONAL INTERMEDIARY USE ONLY AND NOT FOR USE BY THE GENERAL PUBLIC.

APCC MemberConsumer Duty Alliance

Paradigm Consulting is a Member of the Association of Professional Compliance Consultants and also the Consumer Duty Alliance.

Paradigm Consulting is a trading name of Paradigm Partners Ltd
Office address: Paradigm Partners Ltd, Paradigm House, Brooke Court, Wilmslow, Cheshire, SK9 3ND
Paradigm Partners Ltd is registered in England and Wales. No.09902499. Registered Office: As above

Paradigm Mortgage Services LLP
Office address: 1310 Solihull Parkway, Birmingham Business Park, Birmingham B37 7YB
Registered in England and Wales. Company No: OC323403. Registered Office: Paradigm House, Brooke Court, Lower Meadow Road, Wilmslow, SK9 3ND
Paradigm Mortgage Services LLP is a Limited Liability Partnership.

Paradigm Protect is a trading name of Paradigm Mortgage Services LLP
Office address: 1310 Solihull Parkway, Birmingham Business Park, Birmingham B37 7YB
Paradigm Mortgage Services LLP is registered in England and Wales. Company No: OC323403. Registered Office: Paradigm House, Brooke Court, Lower Meadow Road, Wilmslow, SK9 3ND
Paradigm Mortgage Services LLP is a Limited Liability Partnership.