Seven organisations, including the Home Office, have been formally criticised by the Information Commissioners’ Office (ICO) for their failure to meet their legal obligations in responding to Data Subject Access Requests (DSARs). The ICO’s response highlights the continued requirement for an organisation to exercise diligence in dealing with such requests.
By law, individuals can make a subject access request to ascertain whether their personal data is being processed by an organisation and to obtain a copy.
The organisation concerned must issue a response within a month of receiving the request, providing a detailed explanation as to why the data is being processed, who it is being shared with and how long it will be retained. Where necessary, depending on the complexity and number of requests, this deadline can be extended by a further two months.
Among the issues addressed by the ICO across the seven organisations that were reprimanded were significant backlogs of DSARs causing significant distress to members of the public making the requests. In some cases, as many as 60% of DSARs were not dealt with in a timely manner with delays exceeding the statutory timeframe.
The ICO has granted the organisations between three and six months to deliver improvements or potentially face further enforcement action, setting recommended steps for improving compliance and requiring regular updates on progress.
The enforcement powers available to the ICO, in the event that an organisation fails to comply, include imposing fines of up to £17.5 million or 4% of the total annual worldwide turnover in the preceding financial year, whichever is higher.
What can organisations do to process DSARs more effectively?
The ICO has identified that delay, unsatisfactory responses, a lack of trust in responses received, and a lack of understanding of information provided are the key issues relating to the handling of DSARs.
As regards the issue of delay, in circumstances where the one-month time limit cannot be met, the organisation must inform the individual making the request.
If a request takes longer than anticipated to process due to its complexity, or the request is particularly wide and needs to be narrower to enable focus, this must also be communicated to the individual. Such communication will also serve to address the lack of trust which the ICO has identified in relation DSARs.
Where a lack of understanding of data is being processed, or how a request is being handled arises, it’s vital that organisations demonstrate transparency with regard to their data policies and notices so that potential data subjects have greater clarity as to how their information is being used and stored.
It is important to communicate clearly to an individual making a DSAR any exemptions that may apply and why.
Depending on the size of the organisation and how data is processed, employing a Data Protection Officer may be necessary or, at the very least, designating an employee within the organisation to handle DSARs and other privacy requests. However, as most, if not all, employees will handle personal data in some way, providing adequate training so that they understand their statutory obligations is advisable.
Often, DSARs will be general and unspecific in their nature. Therefore, it’s important to seek clarification from the data subject in order to focus the response to their request.
Establishing an audit trail to aid compliance and deal with complaints as and when they arise will also be beneficial to the organisation.
In summary, this latest flexing of the ICO’s muscle in monitoring the data protection practices of organisations should serve to reassure data subjects that their requests will be dealt with efficiently and effectively whilst also making clear to organisations the importance of handling DSARs with due care and attention.