This practical workshop, facilitated by Barry Moult, a former Head of Information Governance for an NHS Trust, will look at managing Subject Access Requests and what you need to consider to comply with legislation and upholding individuals rights to access personal and sensitive information held about them. This will enable delegates to look at case studies and have the confidence to respond to requests.
“The right of individuals to access information that organisations hold on them is one that is vital for transparency, and is enshrined in law. What we’re seeing now is that many employers are misunderstanding the nature of subject access requests, or underestimating the importance of responding to requests. For example, employers may be unaware that requests can be submitted informally, such as over social media, or do not have to contain the words ‘subject access request’ in order to qualify as a legally binding request. Similarly, employers may not realise that there is a strict time frame for responding to requests, and this must be kept to.”
Elanor McCombe, Policy Group Manager at the Information Commissioner’s Office
In 2018 both the General Data Protection Regulation and a new Data Protection Act were introduced in the UK, requiring health and social care bodies, by the nature of their work, to respond to Subject Access requests. There is, to a certain extent, relatively clear guidance in the legislation as to what this requires organisations to do. This course, however, facilitated by an experienced Information Governance & Health Records Manager, undertakes to highlight how to practically implement the requirements, introducing a practical approach to Subject Access Requests.
Within Health and Social Care (inc. third sector); Data Protection Officers, Deputy Data Protection Officers, Information Governance Professionals and Line Managers of any of the above should attend this masterclass.
In May 2023, the ICO published a new guide on responding to subject access requests Read in full here
Key Learning Objectives include understanding:
Background and Legal Basis
Definitions
Working with others in the organisation: Information Asset Owners, Health Records Manager, Data Protection Officer, Caldicott Guardian, Senior Information Risk Owner
How to Manage a Subject Access Request: Identifying a valid request, Excessive & Unfounded request, Locating the information requested, Collating, Redacting & Disclosure, Exemptions
Requests from 3rd Parties: Solicitors, Insurance Companies, Police, Others, Requests from Staff
Complaints
Complex requests - Case studies
Information Commissioners Office - Audits and Enforcement