How to respond to subject access requests from employees under the General Data Protection Regulation (GDPR)
Author: Jo Broadbent
Summary
Click on any of the hyperlinks to go to more detailed guidance below.
- Be aware that employees have the right under the UK GDPR to ask employers for copies of personal data relating to them.
- Ensure that policies and procedures for dealing with subject access requests reflect the requirements of the UK GDPR.
- Be able to identify a subject access request.
- Understand your obligations to identify who has made the subject access request.
- Take steps to clarify the scope of the subject access request.
- Carry out the searches required to assemble the relevant personal data.
- Respond to the data subject access request appropriately.
- Maintain records of subject access requests.